PHP / JSP / ASPX Web-Shell Backdoor & Persistence IOC Scanner (2026)

Deobfuscate nested `eval(gzinflate(base64_decode(...)))` chains, calculate Shannon string entropy, flag dynamic variable execution (`$_POST[...]()`), and generate YARA / Linux `find` incident response hunts 100% client-side.

PHP / JSP / ASPX Web-Shell Backdoor & Persistence IOC Scanner — Interactive Console
Runs locally in your browser • Instant output
Load Sample Preset:
Detection Verdict
CRITICAL — ACTIVE WEBSHELL SIGNATURE DETECTED
Shannon Entropy
5.53 bits/byte
Matched RCE Sinks
4 signature(s)
assert() — Stealth PHP code evaluation sink
CRITICAL
OS Command Execution — Spawns system shell process from web worker
CRITICAL
Payload Deobfuscation Chain — Decodes compressed/encoded backdoor payload in memory
HIGH
Superglobal User Input Vector — Direct HTTP request parameter intake
HIGH
Linux Webroot Forensics & YARA Hunt Commands
# 1. Find PHP/JSP files modified in the last 7 days in webroot
find /var/www/html -type f \( -name "*.php" -o -name "*.jsp" \) -mtime -7 -ls

# 2. Grep for obfuscated eval/gzinflate/base64 webshell one-liners
grep -RnE "(eval|assert|passthru|shell_exec|system|gzinflate|base64_decode)\s*\(" /var/www/html/

# 3. Audit Nginx/Apache access logs for POST requests to uploads/ or cache/ directories
awk '$6 ~ /POST/ && $7 ~ /\.(php|jsp|aspx)/ {print $1, $4, $7, $9}' /var/log/nginx/access.log | sort | uniq -c | sort -nr | head -n 20
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![PHP / JSP / ASPX Web-Shell Backdoor & Persistence IOC Scanner](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/webshell-backdoor-ioc-signature-scanner/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/webshell-backdoor-ioc-signature-scanner/">PHP / JSP / ASPX Web-Shell Backdoor & Persistence IOC Scanner — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: PHP / JSP / ASPX Web-Shell Backdoor & Persistence IOC Scanner

Quick Answer & 2026 Technical Summary (webshell backdoor scanner php deobfuscator)Updated 2026 Standard

Attackers avoid literal `eval(` or `system(` strings by constructing function names dynamically at runtime—for example via string concatenation (`$f = 'as'.'sert'; $f($_POST['x']);`), bitwise XOR of two non-alphanumeric strings (`('^'^'|')`), `create_function()`, `array_map()`, or storing the function name inside an HTTP request header (`$_SERVER['HTTP_X_CMD']($_SERVER['HTTP_X_ARGS'])`). Use this interactive webshell backdoor scanner php deobfuscator above to test php eval base64 gzinflate deobfuscator, detect china chopper wso c99 webshell, and jsp aspx webshell yara rule generator locally in your browser with zero server uploads.

Target Keyword Spec: webshell backdoor scanner php deobfuscator | Modules: AST-Style Dangerous Sink & Superglobal Flow Detector • Multi-Layer Base64 / Hex / ROT13 / XOR Deobfuscator • Shannon Entropy & File-Header Polyglot Inspector
Primary Focus: webshell backdoor scanner php deobfuscator
Core Capability: php eval base64 gzinflate deobfuscator
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
AST-Style Dangerous Sink & Superglobal Flow Detectorphp eval base64 gzinflate deobfuscatorIdentify direct and indirect user input (`$_REQUEST`, `$_COOKIE`, `php://in...WordPress, Laravel & Legacy PHP Incident Response Triage
Multi-Layer Base64 / Hex / ROT13 / XOR Deobfuscatordetect china chopper wso c99 webshellUnpack obfuscated `base64_decode`, `str_rot13`, `chr()` concatenation, and ...Enterprise Tomcat / IIS (JSP & ASPX) Web-Shell Hunting
Shannon Entropy & File-Header Polyglot Inspectorjsp aspx webshell yara rule generatorCalculate per-line and file-wide Shannon bits-per-byte entropy (`H(X) > 5.4...Detecting Timestomped Persistence & `.htaccess` Handlers
Execution & Privacy Architecture100% Client-Side WebCrypto / JS Sandbox0 Bytes Sent to External ServersSafe for internal SOC & authorized lab artifacts
NIST SP 800-53 / OWASP AlignmentOWASP ASVS v4.0.3 / NIST CSF 2.0Deterministic Rule & Header VerificationMaps findings to actionable hardening controls
Cryptographic & Entropy StandardSHA-256 / AES-256-GCM / Argon2id≥ 128-bit Effective Security MarginMeets 2026 post-quantum & zero-trust baselines
In-Depth ZerosUniverse Tutorial

What is a Backdoor & How to Clean an Infected System

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use PHP / JSP / ASPX Web-Shell Backdoor & Persistence IOC Scanner

01

Paste Suspicious PHP / JSP / ASPX Code or Load a Web-Shell Sample

Paste raw source code from your web root or select a realistic preset (Obfuscated PHP One-Liner, GIF89a Polyglot Upload, or AES-Encrypted JSP Shell).

02

Inspect Flagged Execution Sinks, Superglobals & Evasion Tricks

Review the line-by-line threat breakdown highlighting variable functions (`$a($b)`), `preg_replace` `/e` modifiers, reflection calls, and silent `@` error suppression.

03

Unpack Decoded String Payloads & Entropy Spikes

Examine the extracted Base64/ROT13/Hex plaintext preview and verify whether high-entropy blobs indicate encrypted Behinder/Godzilla payloads.

04

Copy YARA Rules & Server-Wide Linux Forensic Hunt Commands

Run the generated `find` and `ripgrep` commands on your server to locate sibling backdoors, rogue cron jobs, and unauthorized `authorized_keys` entries.

Key Capabilities & Technical Architecture

AST-Style Dangerous Sink & Superglobal Flow Detector

Identify direct and indirect user input (`$_REQUEST`, `$_COOKIE`, `php://input`) flowing into execution sinks (`eval`, `assert`, `proc_open`, `Runtime.getRuntime().exec`).

Multi-Layer Base64 / Hex / ROT13 / XOR Deobfuscator

Unpack obfuscated `base64_decode`, `str_rot13`, `chr()` concatenation, and hex-escaped string literals to reveal hidden C2 endpoints and password gates.

Shannon Entropy & File-Header Polyglot Inspector

Calculate per-line and file-wide Shannon bits-per-byte entropy (`H(X) > 5.4`) and detect `GIF89a;` / `ÿØÿ` magic-byte polyglots hiding executable code.

YARA Rule & Linux Incident Response (`find` / `grep`) Generator

Export custom YARA detection signatures and non-destructive Linux filesystem commands to hunt timestomped (`ctime` vs `mtime`) backdoors across `/var/www`.

Practical Use Cases

WordPress, Laravel & Legacy PHP Incident Response Triage

Inspect suspicious files inside `/wp-content/uploads/` or modified `wp-config.php` includes to uncover hidden one-liner China Chopper or WSO/b374k shells.

Enterprise Tomcat / IIS (JSP & ASPX) Web-Shell Hunting

Detect Godzilla, Behinder, and AntSword encrypted AES/XOR web shells deployed after deserialization or file-upload vulnerabilities.

Detecting Timestomped Persistence & `.htaccess` Handlers

Generate forensic `stat` and `find -ctime` queries that spot attackers who ran `touch -r index.php shell.php` to fake modification timestamps.

Frequently Asked Questions (FAQs)

How do modern PHP web shells bypass simple `grep -R "eval("` scans?+

Attackers avoid literal `eval(` or `system(` strings by constructing function names dynamically at runtime—for example via string concatenation (`$f = 'as'.'sert'; $f($_POST['x']);`), bitwise XOR of two non-alphanumeric strings (`('^'^'|')`), `create_function()`, `array_map()`, or storing the function name inside an HTTP request header (`$_SERVER['HTTP_X_CMD']($_SERVER['HTTP_X_ARGS'])`).

What is a `GIF89a;` polyglot web shell?+

Many naive image upload validators only check the first few magic bytes of an uploaded file (`47 49 46 38 39 61` for `GIF89a`) via `getimagesize()` or `finfo_file()`. Attackers prepend `GIF89a;` followed by `<?php system($_GET['c']); ?>` and exploit either double extensions (`shell.php.gif` on misconfigured Apache `AddHandler`) or Local File Inclusion (LFI) to execute it.

How can I detect 'timestomped' web shells on a Linux server?+

Attackers frequently run `touch -r index.php backdoor.php` to copy the legitimate `mtime` (Modification Time) and `atime` (Access Time) of an old file so `ls -lt` blends in. However, unprivileged users cannot forge the inode `ctime` (Change Time) in the kernel filesystem metadata. Running `find /var/www -ctime -7 -type f` reliably exposes recently dropped or timestomped files.

Why does encrypted web-shell traffic (Behinder / Godzilla) trigger high Shannon entropy alerts?+

Normal human-written PHP, JSP, or HTML source code has a predictable character frequency distribution with Shannon entropy between 4.2 and 4.9 bits per byte. Encrypted payloads wrapped in Base64 or raw hex buffers push local entropy above 5.5 to 6.0 bits per byte with zero whitespace.

Is my pasted source code sent to any external server?+

Never. All signature matching, entropy calculation, Base64/ROT13 decoding, and YARA rule synthesis run 100% locally inside your browser's JavaScript engine.