s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-php.c99

📛 Threat Title

Malware family: c99shell

Category: c99shell First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `php.c99`. Printable name: c99shell. Aliases: c99.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:cybelangel.com

    What web shells are, how attackers deploy them, and how defenders find them — including C99 shell analysis and a CISO detection checklist.

  • web:github.com

    C99Shell -PHP7 PHP 7 and safe-build Update of the popular C99 variant of PHP Shell. c99shell .php v.2.0 (PHP 7) (25.02.2019) Updated by: KaizenLouie for PHP 7 About C99Shell An excellent example of a web shell is the c99 variant, which is a PHP shell (most of them calls it malware ) often uploaded to a vulnerable web application to give hackers an interface. The c99 shell lets the attacker take ...

  • web:learn.microsoft.com

    Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.

  • web:malpedia.caad.fkie.fraunhofer.de

    C99shell is a PHP backdoor that provides a lot of functionality, for example: * run shell commands; * download/upload files from and to the server (FTP functionality); * full access to all files on the hard disk; * self-delete functionality.

  • web:threats.kaspersky.com

    Class: Backdoor Backdoors are designed to give malicious users remote control over an infected computer. In terms of functionality, Backdoors are similar to many administration systems designed and distributed by software developers. These types of malicious programs make it possible to do anything the author wants on the infected computer: send and receive files, launch files or delete them ...

  • web:windowsforum.com

    High vendor confidence: Microsoft has publicly acknowledged CVE‑2025‑62454 and published updates in the Security Update Guide; that gives defenders a clean remediation path. Clear operational playbook: community reporting and past incidents provide a pragmatic set of detection, hunting, and mitigation steps that defenders can adopt quickly.

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.trendmicro.com

    This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.