TF-MAL-php.p0wnyshell
📛 Threat Title
Malware family: p0wnyshell
Description
ThreatFox malware family `php.p0wnyshell`. Printable name: p0wnyshell. Aliases: Pownyshell,Ponyshell.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:apt.etda.or.th
Threat Group Cards: A Threat Actor Encyclopedia Tool: P0wnyshell ... Last change to this tool card: 13 October 2023 Download this tool card in JSON format All groups using tool P0wnyshell ... 1 group listed (1 APT, 0 other, 0 unknown) ↑
-
web:github.com
Single-file PHP shell. Contribute to flozz/p0wny-shell development by creating an account on GitHub.
-
web:learn.microsoft.com
Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the p0wnyshell malware family including references, samples and yara signatures.
-
web:threatfox.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with php. p0wnyshell .
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.itpro.com
The US Justice Department and FBI have revealed a joint operation with international partners was able to delete malware injected by Chinese threat actors to thousands of devices around the world.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.wordfence.com
The Wordfence Threat Intelligence Team recently identified an interesting malware family on May 16, 2025 during a site clean. This malware family shared a codebase but varied in features across different versions, including credit card skimming and WordPress credential theft. Most surprisingly, one variant incorporated a live backend system hosted directly on infected websites for attacker use ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.