WebShell malware family
WebShell is a malware family tracked by MalwareAnalyzer by Cyble across 12 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-25. Observed ATT&CK techniques include T1105, T1059.004.
Corpus statistics
- Publicly analyzed samples: 12
- First seen: 2026-07-28
- Last seen: 2026-08-25
- Verdicts: malicious 12
- File types: shell 11, script 1
ATT&CK techniques used by WebShell
Extracted command-and-control infrastructure
- 160.119.69.4 - 11 samples
- http://data.esumsoft.com/download/POPPeeperPro.zip - 1 sample
- http://www.vulnerability-lab.com/get_content.php?id=1657 - 1 sample
- http://www.vulnerability-lab.com/keys/admin@vulnerability-lab.com%280x198E9928%29.txt - 1 sample
- http://www.vulnerability-lab.com/show.php?user=ZwX - 1 sample
- http://zwx.fr - 1 sample
- http://zwx.fr/videos/POPPeeper.html - 1 sample
Recent WebShell samples
- 71c7cbb42289fe16b17e4ad550f00bd11875ed823d0e7b1abc5453fddecc6013 - malicious (2026-08-25)
- 0f66313a5be3dea7436060ae606b0ef9bf11abf85b60a2bc9cac828dfb161538.sh - malicious (2026-08-02)
- 30a18c85fbf3beb4f8cd1940e9cc1dcd78f92f4e9e531f9f3cc615f67b53f582.sh - malicious (2026-07-29)
- 1bd26a5f04837e6b58262c5cef3a2de052928414bc5bcc1106861c3792ab595c.sh - malicious (2026-07-28)
- 977399df67a510fdb6fb6f9eb7a63a5bc8a178e0dd6cd6321c02b68c94681cef.sh - malicious (2026-07-28)
- 94e381ba36dcbf27e4907f9049eff1a8694dfafd4af899be0bed6b781f13b5ac.sh - malicious (2026-07-28)
- 79c7de724b8d91a50fd7cf1d4bb572fedba37d33f9e705ce37957af43c0e8b9c.sh - malicious (2026-07-28)
- 63559cb87098de64cbe5f1d981bf782283a8e24e3d81926a3ddb80cae5b5d856.sh - malicious (2026-07-28)
- 42daf9a89197d5e4e4e7781ec492877b699b8207ee1f92cd86506bd08224df4c.sh - malicious (2026-07-28)
- 34b3a7f20f952b72de26db5cb0b5bd21c25d9eacc112ea4b0dac62e213d6f04c.sh - malicious (2026-07-28)
- 0c54132cab0103d71f7442af592cf31ad9b3a88d51bf6159f8adcd0186852366.sh - malicious (2026-07-28)
- 0b1191aec5ad6ae2398f577f0b45de66c41edda4ce7216781f3a40ae010935b4.sh - malicious (2026-07-28)
Frequently asked about WebShell
- What is WebShell?
- WebShell is a malware family tracked by MalwareAnalyzer by Cyble across 12 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-25. Observed ATT&CK techniques include T1105, T1059.004.
- How many WebShell samples have been analyzed?
- MalwareAnalyzer by Cyble holds 12 publicly analyzed samples attributed to WebShell, first seen 2026-07-28 and most recently 2026-08-25. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does WebShell use?
- Across our WebShell samples the most frequently observed techniques are T1105 (11), T1059.004 (10). Counts are the number of analyzed samples in which each technique was observed.
- What file types does WebShell use?
- WebShell samples in this corpus are distributed as shell (11), script (1).
- Does WebShell use command-and-control infrastructure?
- Yes. 7 distinct command-and-control indicators have been extracted from WebShell samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is WebShell malicious?
- 12 of 12 analyzed WebShell samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends