如果你想获得更好的查杀体验,建议下载我们的客户端
Online Webshell Detector
SHELLPUB focuses on Detecting WEBSHELL, a free and easy-to-use online WEBSHELL detector
Please drag the zip file into the area, the maximum supported is 10MB
safe
Result for test_samples.zip
SHA1
0170d048f2c507cd9c21ddf1aaf45ad6d66106dc
MD5
8e34cf399eb72007e4e81d7b27fc3a63
Size
65241 Byte
Version
1.0.0 alpha
Analyze results
60/22/100(backdoor/suspected/Total number of files)
Result list
download
resultdetailsfile name
SUSP疑似反射型JSP WEBSHELL/test_samples/plain/jsp_control_flow.jsp
BLACKaspx执行后门/test_samples/plain/ashx_unicode.ashx
BLACKJSP小马/test_samples/plain/jsp_cdata.jsp
BLACKaspx执行后门/test_samples/plain/aspx_url_unicode.aspx
BLACKasp执行后门 - 一句话/test_samples/plain/asp_excute_splice.asp
SUSP疑似反射型JSP WEBSHELL/test_samples/plain/jsp_funcrecon.jsp
SUSP疑似自定义类加载器WEBSHELL/test_samples/plain/jsp_gzip.jsp
BLACKJSP小马/test_samples/plain/jsp_cdata_split.jsp
BLACKJSP小马/test_samples/plain/jsp_html_entity.jsp
SUSP疑似反射型JSP WEBSHELL/test_samples/plain/jsp_long_array.jsp
BLACKJSP小马/test_samples/plain/jsp_nullbyte.jsp
SUSP疑似自定义类加载器WEBSHELL/test_samples/plain/jsp_portal_xmldecoder.jsp
BLACKJSP小马/test_samples/plain/jsp_maintenance.jsp
BLACKJSP小马/test_samples/plain/jsp_reflective.jsp
SUSP疑似自定义类加载器WEBSHELL/test_samples/plain/jsp_threadutil.jsp
SUSP疑似自定义类加载器WEBSHELL/test_samples/plain/jsp_stringutil.jsp
BLACKJSP小马/test_samples/plain/jsp_unicode_escape.jsp
SUSP疑似自定义类加载器WEBSHELL/test_samples/plain/jsp_unicode_varuu.jsp
BLACK命令执行JSP WEBSHELL/test_samples/plain/jspx_cdata.jspx
SUSP疑似自定义类加载器WEBSHELL/test_samples/plain/jsp_long_array_bytecode.jsp
SUSP疑似自定义类加载器WEBSHELL/test_samples/plain/jsp_mock_class_try_catch.jsp
BLACKJSP小马/test_samples/plain/jsp_mock_trycatch.jsp
BLACK命令执行JSP WEBSHELL/test_samples/plain/jsp_inazuma_puzzle_full.jsp
BLACKPHP加密混淆类木马/test_samples/plain/php_chr_encoder.php
BLACKPHP命令执行类木马/test_samples/plain/php_callback_array.php
BLACKPHP加密混淆类木马/test_samples/plain/php_branch_lock.php
BLACKPHP代码执行类木马/test_samples/plain/php_aes_gcm.php
BLACKPHP命令执行类木马/test_samples/plain/php_array_syntax.php
BLACKPHP加密混淆类木马/test_samples/plain/php_class_exists.php
BLACKPHP加密混淆类木马/test_samples/plain/php_create_function.php
BLACKPHP加密混淆类木马/test_samples/plain/php_dead_condition.php
BLACKPHP命令执行类木马/test_samples/plain/php_destruct_call.php
BLACKPHP加密混淆类木马/test_samples/plain/php_garbage.php
BLACKPHP命令执行类木马/test_samples/plain/php_fake_functions.php
BLACKPHP加密混淆类木马/test_samples/plain/php_funcrecon.php
BLACKPHP加密混淆类木马/test_samples/plain/php_fake_function.php
BLACKPHP代码执行类木马/test_samples/plain/php_hex.php
BLACKPHP加密混淆类木马/test_samples/plain/php_hmac.php
BLACKPHP命令执行类木马/test_samples/plain/php_invoke_call_user_func.php
BLACKPHP加密混淆类木马/test_samples/plain/php_maintenance.php
BLACKPHP加密混淆类木马/test_samples/plain/php_md5_gate.php
BLACKPHP加密混淆类木马/test_samples/plain/php_multi_layer.php
BLACKPHP加密混淆类木马/test_samples/plain/php_mock_trycatch.php
BLACKPHP已知后门/test_samples/plain/php_null_byte_comments.php
BLACKPHP加密混淆类木马/test_samples/plain/php_nullbyte.php
BLACKPHP加密混淆类木马/test_samples/plain/php_random_comments.php
BLACKPHP加密混淆类木马/test_samples/plain/php_perlin_noise.php
BLACKPHP加密混淆类木马/test_samples/plain/php_reflective.php
BLACK冰蝎3.0 ASP-webshell/test_samples/protocol/asp_behinder_baseline.asp
SUSP疑似自定义类加载器WEBSHELL/test_samples/protocol/jsp_antsword_baseline.jsp
SUSP疑似反射型JSP WEBSHELL/test_samples/protocol/jsp_antsword_longarray.jsp
SUSP疑似自定义类加载器WEBSHELL/test_samples/protocol/jsp_antsword_nullbyte.jsp
BLACK冰蝎JSP WEBSHELL/test_samples/protocol/jsp_behinder_baseline.jsp
BLACK冰蝎JSP WEBSHELL/test_samples/protocol/jsp_behinder_mock_trycatch.jsp
SUSP疑似自定义类加载器WEBSHELL/test_samples/protocol/jsp_godzilla_gzip.jsp
SUSP疑似自定义类加载器WEBSHELL/test_samples/protocol/jsp_godzilla_longarray.jsp
SUSP疑似自定义类加载器WEBSHELL/test_samples/protocol/jsp_godzilla_baseline.jsp
SUSP疑似自定义类加载器WEBSHELL/test_samples/protocol/jsp_godzilla_nullbyte.jsp
SUSP疑似反射型JSP WEBSHELL/test_samples/protocol/jsp_godzilla_xmldecoder.jsp
BLACKPHP命令执行类木马/test_samples/plain/php_var_override.php
BLACKPHP加密混淆类木马/test_samples/protocol/php_antsword_baseline.php
BLACKPHP加密混淆类木马/test_samples/protocol/php_antsword_funcrecon.php
BLACKPHP加密混淆类木马/test_samples/protocol/php_antsword_multi-layer.php
BLACKPHP加密混淆类木马/test_samples/protocol/php_antsword_nullbyte.php
BLACKPHP命令执行类木马/test_samples/protocol/php_antsword_varoverride.php
BLACKPHP哥斯拉木马/test_samples/protocol/php_behinder_baseline.php
BLACKPHP命令执行webshell/test_samples/plain/php_class_decode.php
SUSP疑似PHP命令执行类木马/test_samples/plain/php_base32.php
SUSP疑似PHP加密混淆型木马/test_samples/plain/php_combined.php
BLACKPHP命令执行webshell/test_samples/protocol/php_behinder_baseline_xor.php
BLACKPHP命令执行webshell/test_samples/protocol/php_behinder_hmac.php
SUSP疑似PHP命令执行webshell/test_samples/protocol/php_behinder_branchlock.php
BLACKPHP命令执行webshell/test_samples/protocol/php_behinder_nullbyte.php
BLACKPHP命令执行webshell/test_samples/protocol/php_behinder_funcrecon.php
BLACKPHP代码执行类木马/test_samples/xor_fallback/xor_behinder_baseline.php
BLACKPHP反弹Shell/test_samples/xor_fallback/xor_behinder_nullbyte.php
BLACKPHP命令执行webshell/test_samples/protocol/php_behinder_nullbyte_xor.php
BLACKPHP命令执行webshell/test_samples/protocol/php_godzilla_baseline.php
SUSP疑似PHP命令执行webshell/test_samples/protocol/php_godzilla_branchlock.php
BLACKPHP命令执行webshell/test_samples/protocol/php_godzilla_create_function.php
BLACKPHP命令执行webshell/test_samples/protocol/php_godzilla_nullbyte.php
BLACKPHP命令执行webshell/test_samples/protocol/php_godzilla_inazuma_puzzle.php
What to do if a malicious file is detected
1
Remove malicious files from website
2
After removal, repackage and upload to detect the presence of malicious files
3
Modify your password (such as ftp, website server, database, os, etc.)
4
Regularly check the website for backdoors and security issues to ensure website security
Q&A
Why does the upload fail?

The upload failed. There may be four reasons:

1. The size of the uploaded file exceeds 10MB. Please wait patiently while scanning multiple files.

2. The uploaded file format is incorrect and is not a standard zip package file.

3. The network is unstable and the file upload is incomplete, please refresh and re-upload your Browser

4. The browser version is too low, it is recommended to use chrome or a third-party browser containing chrome kernel

Inaccurate results?

If you find any false positives or false negatives, you can compress the Sample with zip and send to feedback@shellpub.com. Indicate [False Negatives] or [False Positives] in the email title and any other For any questions about webshell analyzing and detecting, you can contact us

Is this service free?

There is currently no charge, and there is no limit on the number of multiple uploads. Downloading the client will provide a better experience.

How does Shellpub detect webshell?

Shellpub Online Scan is the online version of the Shellpub Scan service. The latest detection capabilities will be integrated into the online version first. The webshell detection engine independently developed by Shellpub has complete intellectual property rights and uses static analysis, dynamic analysis, and features-Matching, machine learning and multiple technologies to detect webshell