P.A.S. Webshell

MITRE ATT&CK: S0598 View on attack.mitre.org

Aliases: Fobushell, P.A.S. Webshell

First seen
2016-01-01 00:00:00
Malware type
webshell
Family
Malware family
Operating systems
linux, windows
Profile updated
2026-07-07 14:24:46

Context

P.A.S. Webshell is a publicly available multifunctional PHP webshell in use since at least 2016 that provides remote access and execution on target web servers.

Detection coverage

  • 2 YARA rules
  • 388 Sigma rules

Malware & tools used

  • Deobfuscate/Decode Files or Information (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Web Shell (attack-pattern)
  • Data from Local System (attack-pattern)
  • Linux and Mac Permissions (attack-pattern)
  • Web Protocols (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Software Discovery (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • File Deletion (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Databases (attack-pattern)
  • Password Guessing (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Local Account (attack-pattern)

Used by threat actors

Detection rules

  • SIGNATURE_BASE_WEBSHELL_PAS_Webshell_Perlnetworkscript (yara-rule)
  • SIGNATURE_BASE_WEBSHELL_PAS_Webshell_Sqldumpfile (yara-rule)

Reports & references

  • cert.ssi.gouv.fr — Certfr 2021 Cti 005 (report)
  • MITRE ATT&CK — S0598 (report)
  • CISA — Ar 17 20045 Enhanced Analysis Of Grizzly Steppe Activity (report)

External references