TF-1932736
medium
📛 Threat Title
php.shin_webshell: Domain that is used for botnet Command&control (C&C) zejaziri.workers.dev
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: php.shin_webshell. Confidence: 50. First seen: 2026-09-25 08:32:51 UTC. Reporter: xscon. Tags: Cloudflare, gif, PHP, webshell, WordPress, workers.dev, wp-admin.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
zejaziri.workers.dev
VT 2 / 91
IOC database
- Type
- domain
- Value
zejaziri.workers.dev- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 2 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Certego | suspicious | suspicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | CloudFlare, Inc. |
| TLD | workers.dev |
History
| Creation date | 2019-02-08 20:36 UTC |
| Last analysis | 2026-09-25 09:50 UTC |
| Last modified on VirusTotal | 2026-09-25 16:18 UTC |
| Last WHOIS update | 2025-03-10 15:45 UTC |
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: php.shin_webshell. Confidence: 50. First seen: 2026-09-25 08:32:51 UTC. Reporter: xscon. Tags: Cloudflare, gif, PHP, webshell, WordPress, workers.dev, wp-admin.
Remediations (8)
-
web:cybersecuritynews.com
A newly uncovered malware operation dubbed StopAndProtect is transforming thousands of hacked WordPress websites into a sprawling criminal command-and-control (C2) infrastructure.
-
web:en.wikipedia.org
Botnets can be used to perform distributed denial-of-service (DDoS) attacks, steal data, [1] send spam, and allow the attacker to access the device and its connection. The owner can control the botnet using command and control (C&C) software. [2] The word " botnet " is a portmanteau of the words "robot" and "network".
-
web:github.com
A PHP Botnet proof of concept. Web servers communicating in a centralized Command & Control environment. This is a proof of concept I wrote for a class project. I was supposed to write a simple PHP webserver. This was easily accomplished so I decided to write a proof of concept Botnet Command And Control. The simpleWebServ.php file serves as the C&C webserver, with the laravel_bot.php files ...
-
web:www.imperva.com
Web shells can also participate in a command-and-control infrastructure—for example, a web shell can be used to compromise a host and enlist it into a botnet . Attackers can infect other systems on the network with the web shell, in order to compromise additional resources.
-
web:www.revshells.com
Online Reverse Shell generator with Local Storage functionality, URI & Base64 Encoding, MSFVenom Generator, and Raw Mode. Great for CTFs.
-
web:www.securityweek.com
Authorities announced taking down 106 SocGholish botnet C&C servers and domains , and cleaning up 15,000 WordPress websites.
-
web:www.spamhaus.com
Explore the Spamhaus Live Botnet Threat Map. Track global botnet activity in real time and see where malware and infected devices are operating worldwide.
-
web:www.threatclaw.ai
QakBot + Shin WebShell on Cloudflare Workers: The Malware-as-a-Service Infrastructure Shift The fresh ThreatFox telemetry surfaces a distinct convergence signal that deserves closer scrutiny than the raw IOC list suggests. Three php.shin_webshell domains — jyjuregu.workers.dev, gotiri.workers.dev, and bohapu.workers.dev (all conf:50, tagged Cloudflare/gif/PHP) — appearing concurrently with ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.