Known webshell families
Signature strings of well-known PHP webshells (c99, r57, b374k, WSO, FilesMan, p0wny), spam mailers and back-connect helpers. Every rule requires PHP
Signature strings of well-known PHP webshells (c99, r57, b374k, WSO, FilesMan, p0wny), spam mailers and back-connect helpers. Every rule requires PHP context and at least two independent indicators.
Source file: panomity_known_shells.yar (license MIT, author Panomity GmbH). Scores range from 0 to 100; 85 and above marks a finding as malicious on its own, 40 to 84 as suspicious.
| Rule | Score | What it detects |
|---|---|---|
Panomity_Shell_C99 | 92 | c99 PHP webshell family markers |
Panomity_Shell_R57 | 92 | r57 PHP webshell family markers |
Panomity_Shell_B374k | 92 | b374k PHP webshell family markers |
Panomity_Shell_WSO | 90 | WSO (Web Shell by oRb) family markers |
Panomity_Shell_FilesMan | 88 | FilesMan file-manager webshell module marker |
Panomity_Shell_P0wny | 92 | p0wny-shell single-file PHP shell markers |
Panomity_Shell_Generic_Mailer_Spam | 86 | Bulk mailer spam kit markers (leaf/inbox mailer style), distinct from legitimate mail libraries |
Panomity_Shell_Generic_Uname_Backconnect | 87 | Generic PHP shell exposing a back-connect helper driven by request input |
Reporting a false positive
Send the finding ID, the rule name and, if possible, the file (or its SHA-256) to hallo@panomity.de or open a ticket in the client area . Confirmed false positives are fixed in the next signed generation; clients receive it automatically.