s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932729 medium

📛 Threat Title

php.shin_webshell: Domain that is used for botnet Command&control (C&C) 5yuj1m1rfv.workers.dev

Category: php.shin_webshell Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: php.shin_webshell. Confidence: 50. First seen: 2026-09-25 08:24:08 UTC. Reporter: xscon. Tags: Cloudflare, gif, PHP, webshell, WordPress, workers.dev, wp-admin.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain 5yuj1m1rfv.workers.dev VT 2 / 91 UrlVoid 2 / 36

IOC database

Type
domain
Value
5yuj1m1rfv.workers.dev
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 2 of 91 VirusTotal vendors

VendorVerdictDetection
alphaMountain.ai suspicious suspicious
Gridinsoft suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarCloudFlare, Inc.
TLDworkers.dev
History
Creation date2019-02-08 20:36 UTC
Last analysis2026-09-25 12:33 UTC
Last modified on VirusTotal2026-09-25 20:25 UTC
Last WHOIS update2025-03-10 15:45 UTC

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: php.shin_webshell. Confidence: 50. First seen: 2026-09-25 08:24:08 UTC. Reporter: xscon. Tags: Cloudflare, gif, PHP, webshell, WordPress, workers.dev, wp-admin.

Remediations (10)

  • web:cybelangel.com

    What web shells are, how attackers deploy them, and how defenders find them — including C99 shell analysis and a CISO detection checklist.

  • web:github.com

    Common PHP shells is a collection of PHP webshells that you may need for your penetration testing (PT) cases or in a CTF challenge. Do not host any of the files on a publicly-accessible webserver (unless you know what you are up-to).

  • web:safeguard.sh

    A PHP webshell gives attackers remote control of a server. Learn how they get planted, what the code looks like, and how to detect and remove one.

  • web:www.microsoft.com

    Cookie-gated PHP webshells use obfuscation, php-fpm execution, and cron-based persistence to evade detection in Linux hosting environments. This post examines how this tradecraft conceals execution behind specially crafted HTTP cookies.

  • web:www.threatclaw.ai

    Cloudflare Workers, being serverless functions rather than traditional hosting, don't natively execute PHP. When attackers deploy php.shin_webshell to a worker domain , they exploit a different path than the QakBot-style native-C2 model.

  • web:www.threatclaw.ai

    EDR / endpoint detections (the real kill-chain anchor): The webshell still needs a victim host to invoke. Monitor for outbound HTTP requests from web servers (IIS/Nginx/Apache workers) to workers.dev endpoints that POST or receive image-content responses. Correlate with the surrounding process (php-cgi, w3wp, httpd) command line and child process spawns.

  • web:www.threatclaw.ai

    The Cloudflare Workers Webshell Family ( php.shin_webshell ) Three domains — qhvdg6q2ob.workers.dev, 591jemmy.workers.dev, and the previously-flagged ck.erloro.com pattern — are hosting php.shin_webshell with conf:50-85 and tag Cloudflare,gif,PHP. This is not a coincidence of naming.

  • web:www.threatclaw.ai

    QakBot + Shin WebShell on Cloudflare Workers: The Malware-as-a-Service Infrastructure Shift The fresh ThreatFox telemetry surfaces a distinct convergence signal that deserves closer scrutiny than the raw IOC list suggests. Three php.shin_webshell domains — jyjuregu.workers.dev, gotiri.workers.dev, and bohapu.workers.dev (all conf:50, tagged Cloudflare/gif/PHP) — appearing concurrently with ...

  • web:www.threatclaw.ai

    The shin_webshell workers.dev cluster is a reminder that infrastructure capability is now a commodity — Cloudflare's free edge has become the attacker's rotating proxy tier, and domain -generation algorithms have migrated from .ru /.top to .workers.dev. Detection must shift from reputation-lookup to behavioral fingerprinting of the TLS edge ...

  • web:www.threatclaw.ai

    The shin_webshell Workers Fleet: A Network-Level Blind Spot Worth Closing Today Four domains in the last 24h from ThreatFox all share the same fingerprint: *.workers.dev hosting php.shin_webshell , tagging Cloudflare,gif,PHP. When a legitimate CDN provider is itself the delivery substrate, your traditional URL categorization, domain reputation scoring, and TLS-inspection egress filters all stop ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.