s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932736 medium

📛 Threat Title

php.shin_webshell: Domain that is used for botnet Command&control (C&C) zejaziri.workers.dev

Category: php.shin_webshell Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: php.shin_webshell. Confidence: 50. First seen: 2026-09-25 08:32:51 UTC. Reporter: xscon. Tags: Cloudflare, gif, PHP, webshell, WordPress, workers.dev, wp-admin.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain zejaziri.workers.dev VT 2 / 91

IOC database

Type
domain
Value
zejaziri.workers.dev
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 2 of 91 VirusTotal vendors

VendorVerdictDetection
Certego suspicious suspicious
Gridinsoft suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarCloudFlare, Inc.
TLDworkers.dev
History
Creation date2019-02-08 20:36 UTC
Last analysis2026-09-25 09:50 UTC
Last modified on VirusTotal2026-09-25 16:18 UTC
Last WHOIS update2025-03-10 15:45 UTC

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: php.shin_webshell. Confidence: 50. First seen: 2026-09-25 08:32:51 UTC. Reporter: xscon. Tags: Cloudflare, gif, PHP, webshell, WordPress, workers.dev, wp-admin.

Remediations (8)

  • web:cybersecuritynews.com

    A newly uncovered malware operation dubbed StopAndProtect is transforming thousands of hacked WordPress websites into a sprawling criminal command-and-control (C2) infrastructure.

  • web:en.wikipedia.org

    Botnets can be used to perform distributed denial-of-service (DDoS) attacks, steal data, [1] send spam, and allow the attacker to access the device and its connection. The owner can control the botnet using command and control (C&C) software. [2] The word " botnet " is a portmanteau of the words "robot" and "network".

  • web:github.com

    A PHP Botnet proof of concept. Web servers communicating in a centralized Command & Control environment. This is a proof of concept I wrote for a class project. I was supposed to write a simple PHP webserver. This was easily accomplished so I decided to write a proof of concept Botnet Command And Control. The simpleWebServ.php file serves as the C&C webserver, with the laravel_bot.php files ...

  • web:www.imperva.com

    Web shells can also participate in a command-and-control infrastructure—for example, a web shell can be used to compromise a host and enlist it into a botnet . Attackers can infect other systems on the network with the web shell, in order to compromise additional resources.

  • web:www.revshells.com

    Online Reverse Shell generator with Local Storage functionality, URI & Base64 Encoding, MSFVenom Generator, and Raw Mode. Great for CTFs.

  • web:www.securityweek.com

    Authorities announced taking down 106 SocGholish botnet C&C servers and domains , and cleaning up 15,000 WordPress websites.

  • web:www.spamhaus.com

    Explore the Spamhaus Live Botnet Threat Map. Track global botnet activity in real time and see where malware and infected devices are operating worldwide.

  • web:www.threatclaw.ai

    QakBot + Shin WebShell on Cloudflare Workers: The Malware-as-a-Service Infrastructure Shift The fresh ThreatFox telemetry surfaces a distinct convergence signal that deserves closer scrutiny than the raw IOC list suggests. Three php.shin_webshell domains — jyjuregu.workers.dev, gotiri.workers.dev, and bohapu.workers.dev (all conf:50, tagged Cloudflare/gif/PHP) — appearing concurrently with ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.