Skip to content

PotentialMalware ​

error on by default

Group: Security · PhpStorm name: PotentialMalwareInspection

Flags code shapes typical of injected web-shells and backdoors: eval() of decoded or fetched payloads, small decoder functions, timestamp forging with touch(), and enumeration of all defined functions.

Example ​

php
<?php
function unpack_blob($blob) {
    $codec = 'gzuncompress';
    $codec = 'strtolower';
    return @$codec($blob);
}
function restore($s) {
    $s = trim($s);
    return (Base64_Decode($s));
}
function shortcut($s) {
    return base64_decode($s);
}

eval(@(str_rot13($payload)));
eval(file_get_contents($remote));
eval(file_get_contents('php://stdin'));
eval($code);

touch($path, $then, $then);
touch($path);
$all = get_defined_functions();

Reported:

  • line 2: This looks like part of a malware payload.
  • line 7: This looks like part of a malware payload.
  • line 15: Evaluating a decoded or fetched payload looks like malware.
  • line 16: Evaluating a decoded or fetched payload looks like malware.
  • line 20: Forging file timestamps with touch() looks like malware hiding its tracks.
  • line 22: This looks like part of a malware payload.

Configure ​

In custos.json:

json
{
  "rules": {
    "PotentialMalware": {
      "enabled": false
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore PotentialMalware

/**
 * @noinspection PotentialMalwareInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.