TF-1932519
medium
📛 Threat Title
php.shin_webshell: Domain that is used for botnet Command&control (C&C) zavuluka.workers.dev
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: php.shin_webshell. Confidence: 50. First seen: 2026-09-25 00:38:34 UTC. Reporter: xscon. Tags: Cloudflare, gif, PHP, webshell, WordPress, workers.dev, wp-admin.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
zavuluka.workers.dev
UrlVoid 2 / 36
IOC database
- Type
- domain
- Value
zavuluka.workers.dev- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: php.shin_webshell. Confidence: 50. First seen: 2026-09-25 00:38:34 UTC. Reporter: xscon. Tags: Cloudflare, gif, PHP, webshell, WordPress, workers.dev, wp-admin.
Remediations (10)
-
web:blog.pulsedive.com
Dive into a technical primer on the modern botnet landscape - including the evolution of Mirai-based botnets , capabilities, and recent enforcement actions.
-
web:help.bitsighttech.com
The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navigation Options SPM App: Finding...
-
web:networkthreatdetection.com
Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.
-
web:www.acunetix.com
Zombie Another use of web shells is to make servers part of a botnet . A botnet is a network of compromised systems that an attacker would control, either to use themselves or to lease to other criminals. The web shell or backdoor is connected to a command and control (C&C) server from which it can take commands on what instructions to execute.
-
web:www.geeksforgeeks.org
At this point, the infected devices are connected and controlled remotely through a central command-and-control (C&C) server. The attacker can command these devices, to perform tasks like sending spam, participating in distributed denial-of-service (DDoS) attacks, or stealing data. How to Prevent Botnet Attacks?
-
web:www.imperva.com
Web shells can also participate in a command-and-control infrastructure—for example, a web shell can be used to compromise a host and enlist it into a botnet . Attackers can infect other systems on the network with the web shell, in order to compromise additional resources.
-
web:www.malwarebytes.com
Botnets are networks of computers infected by a botnet agent that are under hidden control of a third party. They are used to execute various commands ordered by the attacker. Most common uses of botnets are criminal operations that require distributed resources, such as DDoS attacks on selected targets, spam campaigns, and performing click fraud.
-
web:www.spamhaus.com
Explore the Spamhaus Live Botnet Threat Map. Track global botnet activity in real time and see where malware and infected devices are operating worldwide.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
-
web:www.threatclaw.ai
QakBot + Shin WebShell on Cloudflare Workers: The Malware-as-a-Service Infrastructure Shift The fresh ThreatFox telemetry surfaces a distinct convergence signal that deserves closer scrutiny than the raw IOC list suggests. Three php.shin_webshell domains — jyjuregu.workers.dev, gotiri.workers.dev, and bohapu.workers.dev (all conf:50, tagged Cloudflare/gif/PHP) — appearing concurrently with ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.