Scroll to top

Hacking Tools: Detection Indicators and Behaviors of the Godzilla Webshell

  • Home
  • Blog
  • Hacking Tools: Detection Indicators and Behaviors of the Godzilla Webshell

Publicly available security tools have long been favored by penetration testers: they are easy to obtain, feature-rich, and impose no maintenance cost on the operator. We likewise believe that many APT actors and opportunistic attackers use them frequently, and that the malicious techniques involved are fairly generic. Analyzing these tools is worthwhile work, and we plan to start with a webshell framework named Godzilla and, as far as possible, expose the key technical details of popular hacking tools. This should help defenders strengthen network defense and threat hunting. We also hope to derive specific rules that help the security community quickly spot advanced attackers who rely on these techniques.

About Godzilla

Godzilla is a cross-platform webshell management tool written in Java. It supports webshells in ASP, ASP.NET, Java, and PHP, ships with plugins for specific capabilities, and provides relatively strong traffic encryption.

It is currently hosted on both GitHub and Gitee; the Gitee mirror is likely intended for users who cannot reach GitHub. The original project does not provide an open-source edition, and the author is BeichenDream. The tool was updated frequently in 2020 and 2021 across 10 versions. The latest version on GitHub is currently v4.01. During our research we also found two additional builds, v4.15 (a "特战版" edition) and ekp1.2, which we will analyze in a follow-up article.

Taking v4.01 as an example, Godzilla's main UI looks like this:

godzilla-v4-01-main-interface

The main UI exposes several key features. Under the Target menu, Add lets you register a webshell and configure it in detail. Under the Manage menu, Generate produces a webshell with a chosen configuration. Once a reachable webshell path is available, the tool presents a control panel for that webshell type with a rich set of capabilities. An ASP.NET example is shown below:

aspnet-webshell-control-panel

Technical Design

Based on parameters configured in the UI, Godzilla reads the matching template resources and assembles a webshell. The following shows Java webshell generation details in v4.01:

java-aes-webshell-generation

Once the generated webshell is deployed on the target site, the attacker can use the tool for encrypted communication with that site. Depending on the scripting language, Godzilla reads the corresponding main payload, encrypts it, and sends it to the webshell:

encrypted-payload-transmission

The webshell decrypts and loads the main payload, keeping the core capability code resident in memory:

payload-memory-resident-loading

When the attacker uses basic features in the webshell control panel, the tool assembles parameters from the UI, sends them to the webshell, and invokes the matching function in the in-memory main payload. Taking basic information retrieval as an example:

getbasicsinfo-function-call

This is the overall technical design and is not limited to Java. We focus on indicators and behaviors that can actually be detected, and the following sections analyze them in detail.

Main Payload

Godzilla implements a main payload for ASP, ASP.NET, Java, and PHP respectively. Using v4.01 as an example:

TypeFull name
ASPshells.payloads.asp.assets.payload.asp
ASP.NETshells.payloads.csharp.assets.payload.dll
Javashells.payloads.java.assets.payload.classs
PHPshells.payloads.php.assets.payload.php

The main payload resides and runs in memory on the target server and provides Godzilla's common baseline capabilities:

FunctionDescriptionNotes
bigFileDownloadReads file content by offset and byte length for chunked large-file downloadSince v3.00
bigFileUploadWrites file content by offset and byte length for chunked large-file uploadSince v3.00
closeCloses the current webshell sessionSince v3.00
copyFileCopies a file
deleteFileDeletes a file
downloadFileReads an entire file for download
execCommandExecutes a system command
execSqlConnects to a database and executes SQL
fileRemoteDownDownloads a given URLSince v3.00
getBasicsInfoCollects basic runtime environment information
getFileLists subdirectory and file information under a directory
getFileSizeGets file sizeSince v3.00
includeWrites an extension module's content and name into memory
runExecutes a specified method or extension module
moveFileMoves a file
newDirCreates a directory
newFileCreates an empty file
setFileAttrSets basic file attributes or modification timeSince v3.00
testVerifies that the main payload is functioning
uploadFileWrites an entire file for upload

Different webshell types load their main payload differently.

For ASP, the main payload is stored under the Session key payload, then later loaded via Execute to run specific functions:

asp-payload-session-execute

For PHP, the main payload (a PHP code string) is XOR-encrypted and stored under the Session key payload. Later it is retrieved from Session, decrypted, and executed directly with eval, which calls the defined run function to process request data:

php-xor-session-payload-eval

For ASP.NET, the main payload is loaded into memory via reflective Assembly.Load and stored under the Session key payload. Later the loaded assembly is retrieved from Session, an instance of class LY is created, and commands are executed by calling that instance's Equals and ToString methods:

aspnet-assembly-load-session

In the ASP.NET main payload, Equals and ToString are overridden. Equals acts as a parameter receiver; ToString triggers command execution and returns the encoded result:

aspnet-equals-tostring-override

For Java, the main payload is loaded into memory via a custom class loader's defineClass method and stored under the Session key payload. Later the loaded Class object is retrieved from Session, an instance is created, and commands are executed by calling that instance's equals and toString methods. The design mirrors ASP.NET; the difference is in the overridden methods. Java places command data in the request attribute in advance, and equals only receives PageContext and triggers parameter parsing:

java-defineclass-equals-tostring

The main payload itself offers little that is distinctive: its functions are mostly primitives. Detection opportunities appear mainly when callers abuse those primitives. Aside from execCommand, when any main-payload type executes commands on Windows, a middleware process typically spawns cmd; on Linux it usually spawns sh or bash.

Overall it is specific to Godzilla and runs entirely in memory, but that does not mean there are no detection opportunities. PHP webshells store the main payload in $_SESSION['payload']. Under default configuration this creates a Session file on disk containing the encrypted PHP main-payload code:

php-session-file-encrypted-payload

Although Godzilla has tried to evade detection from early versions, extracting keys on the network side and decrypting corresponding Session data to recover the main-payload code makes a precise PHP-focused detector comparatively practical. Java main payloads can be monitored and blocked in real time with mature Java Agent or RASP approaches. For ASP.NET, one can monitor .NET runtime (CLR) load behavior and scan process memory for suspicious assemblies with no on-disk counterpart. How to build such detectors is outside the scope of this article.

Feature Modules

Godzilla uses the main payload's include capability to add extra feature modules into memory. ASP and PHP store feature modules directly in Session; ASP.NET loads them via Assembly.Load; Java loads them via a custom class loader's defineClass. Feature-module loading matches main-payload loading.

Module full nameTypeDescriptionNotes
shells.plugins.asp.assets.PortScan.aspASPPort scannerSince v4.0
shells.plugins.asp.assets.evalCode.aspASPExecute custom ASP codeSince v4.0
shells.plugins.cshap.assets.AsmLoader.dllASP.NETShellcode loaderSince v4.0
shells.plugins.cshap.assets.BadPotato.dllASP.NETWindows privilege-escalation exploit
shells.plugins.cshap.assets.CProtScan.dllASP.NETPort scannerSince v4.0
shells.plugins.cshap.assets.CZip.dllASP.NETZIP compress / decompressSince v4.0
shells.plugins.cshap.assets.EfsPotato.dllASP.NETWindows privilege-escalation exploitSince v4.0
shells.plugins.cshap.assets.HttpRequest.dllASP.NETHTTP request utilitySince v4.0
shells.plugins.cshap.assets.RealCmd.dllASP.NETRemote interactive process controlSince v4.0
shells.plugins.cshap.assets.SharpWeb.dllASP.NETBrowser credential stealer
shells.plugins.cshap.assets.SweetPotato.dllASP.NETWindows privilege-escalation exploit
shells.plugins.cshap.assets.lemon.dllASP.NETOps-software credential stealer
shells.plugins.cshap.assets.memoryShell.dllASP.NETIn-memory ASP.NET Godzilla webshellSince v4.0
shells.plugins.java.assets.Behinder.classsJavaIn-memory Behinder Java webshellNot present in v3.x
shells.plugins.java.assets.Cknife.classsJavaIn-memory Cknife Java webshell
shells.plugins.java.assets.FilterManage.classsJavaJava Filter managerSince v4.0
shells.plugins.java.assets.HttpRequest.classsJavaHTTP request utilitySince v4.0
shells.plugins.java.assets.JPortScan.classsJavaPort scannerSince v4.0
shells.plugins.java.assets.JZip.classsJavaZIP compress / decompress
shells.plugins.java.assets.JarLoader.classsJavaIn-memory JAR loader
shells.plugins.java.assets.Meterpreter.classsJavaMeterpreter backdoor
shells.plugins.java.assets.ReGeorg.classsJavaIn-memory reGeorg HTTP tunnel
shells.plugins.java.assets.RealCmd.classsJavaRemote interactive process control
shells.plugins.java.assets.ServletManage.classsJavaJava Servlet manager
shells.plugins.java.assets.ShellDriver.classsJavaDatabase connection credential stealerSince v2.96
shells.plugins.java.assets.AttachShellcodeLoader.classsJavaShellcode loaderv3.01 to v3.03
shells.plugins.java.assets.ShellcodeLoader.classsJavaShellcode loaderSince v4.0
shells.plugins.php.assets.Apache_mod_cgi.phpPHPCommand execution bypassing disable_functionsSince v4.0
shells.plugins.php.assets.AttackFPM.phpPHPPHP-FPM FastCGI attack utilitySince v4.0
shells.plugins.php.assets.ByPassOpenBasedir.phpPHPopen_basedir bypass marker
shells.plugins.php.assets.FPM.phpPHPCommand execution bypassing disable_functionsSince v4.0
shells.plugins.php.assets.HttpRequest.phpPHPHTTP request utilitySince v4.0
shells.plugins.php.assets.LD_PRELOAD.phpPHPCommand execution bypassing disable_functionsSince v4.0
shells.plugins.php.assets.PHP74-FFI-Serializable.phpPHPCommand execution bypassing disable_functionsSince v4.0
shells.plugins.php.assets.PZip.phpPHPZIP compress / decompress
shells.plugins.php.assets.PortScan.phpPHPPort scannerSince v4.0
shells.plugins.php.assets.Ps.phpPHPProcess listingSince v4.0
shells.plugins.php.assets.WebShellScan.phpPHPPHP webshell scannerSince v4.0
shells.plugins.php.assets.disfunpoc.phpPHPdisable_functions bypass
shells.plugins.php.assets.eval.phpPHPPHP code-execution backdoorSince v4.0
shells.plugins.php.assets.evalCode.phpPHPExecute custom PHP code
shells.plugins.php.assets.meterpreter.phpPHPMeterpreter backdoor
shells.plugins.php.assets.ntunnel_mysql.phpPHPMySQL connection tunnelLegitimate Navicat tool, since v4.0
shells.plugins.php.assets.ntunnel_pgsql.phpPHPPostgreSQL connection tunnelLegitimate Navicat tool, since v4.0
shells.plugins.php.assets.ntunnel_sqlite.phpPHPSQLite connection tunnelLegitimate Navicat tool, since v4.0
shells.plugins.php.assets.php-com.phpPHPExecute arbitrary commands via COMSince v4.0
shells.plugins.php.assets.php-filter-bypass.phpPHPCommand execution bypassing disable_functionsSince v4.0
shells.plugins.php.assets.php-json-bypass.phpPHPCommand execution bypassing disable_functions
shells.plugins.php.assets.php5-imap_open.phpPHPCVE-2018-19518Since v4.0
shells.plugins.php.assets.php7-FFI.phpPHPCommand execution bypassing disable_functionsSince v4.0
shells.plugins.php.assets.php7-SplDoublyLinkedList-uaf.phpPHPCommand execution bypassing disable_functionsSince v4.0
shells.plugins.php.assets.php7-backtrace-bypass.phpPHPCommand execution bypassing disable_functions
shells.plugins.php.assets.php7-gc-bypass.phpPHPCommand execution bypassing disable_functions
shells.plugins.php.assets.php74-FFI-BUG.phpPHPCommand execution bypassing disable_functionsSince v4.0
shells.plugins.php.assets.procfs_bypass.phpPHPCommand execution bypassing disable_functions
shells.plugins.php.assets.realCmd.phpPHPRemote interactive process controlSince v4.0

We only analyze modules that are realistic candidates for generic detection. Modules built from open-source projects are described only briefly.

PortScan

All language editions include a port-scan module. In real environments one may observe w3wp, java middleware, or php middleware accessing uncommon network ports.

The ASP edition is unusual. It uses ASP's ADODB.Connection object and the SQLOLEDB.1 provider, builds a SQL Server connection string Data Source=ip,port;User ID=a;Password=a; from the target IP and port, sets a 1-second connect timeout, then calls Open. Through the OLEDB driver it opens a TCP connection to the target port and attempts to send TDS pre-login/login data. Port status is inferred from the failure stage: if the connect stage fails and the error description contains (Connect())., the port is treated as closed or unreachable and 0 is returned; if the TCP connection succeeds but login fails, a service is considered present on that port and 1 is returned. Results are aggregated as ip\tport\t状态.

asp-portscan-adodb-connection

This scan is clearly anomalous in traffic. Typical port scans send only TCP SYN or perform a minimal handshake. This method completes a full TCP three-way handshake and sends full TDS pre-login/login data, so probing non-SQL Server ports such as 445 can produce TDS on an SMB port. The figure below shows Pre-Login:

portscan-tds-prelogin-traffic

Login packets may also contain plaintext such as hostname, connection string, and client information. The figure below shows Login7:

portscan-tds-login7-traffic

AsmLoader.dll

This module executes shellcode based on parameters. If excuteFile is empty, it allocates executable memory in the current process, creates a thread to run the shellcode, and returns ok. If the shellcode is empty it returns shellcode is Null, and on exceptions it returns the exception message, as shown below:

asmloader-inprocess-shellcode

If shellcode is non-empty and excuteFile has a value, it calls AsmLoader.loadAsmBin to inject into the specified process and returns the output:

asmloader-process-injection

This code always runs inside w3wp.exe. With excuteFile set, it creates a suspended child process, allocates RWX memory in that process, writes random padding and shellcode, then uses CreateRemoteThread to execute from offset 1024 and read pipe output. A normal IIS worker process does not create child processes and remotely inject them. Without excuteFile, w3wp itself uses VirtualAlloc for RWX memory, Marshal.Copy to write shellcode, and CreateThread to execute it, producing anonymous executable memory and non-module threads inside the worker.

By default excuteFile is C:\Windows\System32\rundll32.exe. In practice one may observe w3wp creating rundll32.

BadPotato.dll

This module is based on an open-source project. It creates a fake spoolss named-pipe server and induces the Print Spooler service running as SYSTEM to connect. Once connected, BadPotato calls ImpersonateNamedPipeClient to impersonate that high-privilege client token and elevate to NT AUTHORITY\SYSTEM. Some implementations first create a random-GUID sub-pipe, but the final pipe name that lures the privileged process always contains the key string spoolss.

badpotato-spoolss-named-pipe

Under default UI settings, running this module yields w3wp creating cmd.

RealCmd

Equivalent implementations exist for ASP.NET, Java, and PHP. The core idea is to maintain an interactive channel to a child process on the target (such as cmd.exe or /bin/bash) over web requests. On start, the module creates the process from parameters and redirects stdin, stdout, and stderr. ASP.NET and Java use a background thread to continuously read process output and cache it in a memory object bound to the current HTTP session. PHP cannot retain process resources across requests, so it simulates interactivity with a blocking loop plus a Session buffer. The frontend controls the session via the action parameter (start, processWriteData, getResult, stop). All returned data is prefixed with a 0x05 protocol marker byte. On Windows the module can also invoke winpty to obtain a pseudo-terminal for interactive CLI programs.

Under default UI settings, running this module yields w3wp (or java / php-fpm) creating cmd.exe (or /bin/bash).

SharpWeb.dll

This module is based on an open-source project. It recovers saved account passwords from common browser and system credential stores on the target Windows host. It walks browser data directories under the current user and loaded user profiles, locates Chrome/Chromium/Edge Login Data SQLite databases, Firefox logins.json and key4.db, and IE / Windows Vault credential files, then uses Windows DPAPI (CryptUnprotectData) to decrypt protected keys and AES-GCM (and related algorithms) to recover plaintext browser credentials. Godzilla loads the .NET assembly in memory, so no executable is dropped to disk, but at runtime one may observe w3wp reading browser databases, accessing Local State, and calling crypt32.dll.

SweetPotato.dll

This module is based on an open-source project. The base version was developed by EthicalChaos; uknowsec adapted it to run commands in a webshell environment. It combines multiple local Windows privilege-escalation techniques and supports DCOM, WinRM, EfsRpc, and PrintSpoofer, defaulting to PrintSpoofer. In PrintSpoofer mode, w3wp calls CreatePipe to create a named pipe, induces the Print Spooler service (spoolsv.exe) running as SYSTEM to connect, then calls ImpersonateNamedPipeClient to impersonate the SYSTEM token and elevate to NT AUTHORITY\SYSTEM. In EfsRpc mode, w3wp triggers a SYSTEM connection via MS-EFSR and likewise relies on named-pipe token impersonation. In DCOM or WinRM mode, w3wp listens on a local port (default 6666) and induces a SYSTEM component to initiate NTLM authentication, then relays to activate objects, and this path does not depend on named pipes.

Observed behavior varies by exploit mode.

On the PrintSpoofer path, w3wp creates a named pipe whose name contains spoolss, after which a SYSTEM-privileged process connects. After impersonating the client token, w3wp creates a child cmd.exe running as NT AUTHORITY\SYSTEM.

sweetpotato-printspoofer-behavior

On the DCOM path, w3wp listens on local port 6666 and establishes a local network connection with a SYSTEM component. On the WinRM path, w3wp listens on local port 5985 and likewise connects with a SYSTEM component. On both paths, w3wp loads ole32.dll, rpcrt4.dll, combase.dll, clr.dll, and mscoree.dll, then creates a SYSTEM-privileged child process. Throughout, the w3wp thread token and process token become NT AUTHORITY\SYSTEM.

Because the module runs via in-memory loading, there is no corresponding executable on disk.

lemon.dll

This module collects credentials saved by FileZilla, Navicat, SqlYog, WinSCP, and Xshell on the target Windows host. The run method invokes five collector classes (FileZilla, Navicat, SqlYog, WinSCP, and Xmangager) in turn, reading each product's config files and registry keys and decrypting stored credentials.

lemon-credential-collectors

w3wp reads the following locations: FileZilla's %APPDATA%\FileZilla\recentservers.xml; SQLyog walks all user directories under %SystemDrive%\Users\ and reads AppData\Roaming\SQLyog\sqlyog.ini; Xshell reads %SystemDrive%\Users\%USERNAME%\Documents\NetSarang Computer\6\Xshell\Sessions\; Navicat reads registry HKCU\SOFTWARE\PremiumSoft\*\Servers\*; WinSCP walks HKEY_USERS SIDs beginning with S-1-5-21-* and reads Software\Martin Prikryl\WinSCP 2\Sessions\*.

memoryShell.dll

This module is an ASP.NET VirtualPathProvider-style in-memory webshell. It registers malicious logic into the ASP.NET runtime of the w3wp process and lives for the lifetime of the application pool.

The core mechanism is registering a custom VirtualPathProvider. Run.addShell reflectively calls HostingEnvironment.RegisterVirtualPathProviderInternal and attaches a GodzillaVirtualPathProvider instance to the ASP.NET virtual-path system.

memoryshell-virtualpathprovider-register

After registration, ASP.NET request handling invokes that provider's malicious GetCacheKey method. The trigger conditions are specific: the request must be POST, Content-Type must contain www-form, and a request parameter named password must exist. When matched, w3wp takes Base64 ciphertext from that parameter, decrypts it with Rijndael using key, and obtains a .NET assembly byte array.

memoryshell-getcachekey-trigger

To work in more environments, the module also provides two bypasses. bypassFriendlyUrlRoute reflectively locates Microsoft.AspNet.FriendlyUrls.FriendlyUrlRoute and sets AutoRedirectMode to 2. bypassPrecompiledApp reflectively sets BuildManager's _isPrecompiledAppComputed to true and _isPrecompiledApp to false, forcing precompiled apps onto the dynamic compilation path.

The module runs entirely in w3wp memory, with no corresponding DLL or ASPX on disk, and the implant disappears when the application pool recycles.

Behinder.classs

This module dynamically registers a Servlet in Tomcat to implant an in-memory Behinder Java webshell. Behinder is a Chinese webshell manager (project page).

After execution, the Tomcat process dynamically creates a Wrapper and registers a Servlet at the path given by the path parameter. Requests to that path enter _jspService, load AES-decrypted bytecode, modify MapperListener's exactWrappers, and modify Valve's condition. Memory contains Behinder classes, x.Behinder, and a random key.

Cknife.classs

This module dynamically registers a Servlet in Tomcat to implant an in-memory Cknife Java webshell with file management, command execution, and database operations. Cknife is likewise a Chinese webshell manager (project page).

The entry class Cknife extends HttpServlet, reflectively obtains StandardContext, creates a Wrapper, registers a servlet mapping, then modifies MapperListener's exactWrappers so requests route to that Servlet, while also modifying Valve's condition to bypass access logging. Requests are identified via the pwd parameter and dispatched by funccode, and results are wrapped with ->| and |<-.

After execution, Tomcat dynamically registers a Servlet, memory contains Cknife classes and x.Cknife, and MapperListener and Valve are modified.

JarLoader.classs

This module is an in-memory JAR loader for Java. Through a custom jarmembuff URL protocol and reflective injection, it loads a JAR byte array into the target JVM without writing a file.

Observable artifacts include class names JarLoader, MemoryBufferURLConnection, and MemoryBufferURLStreamHandler; protocol name jarmembuff; parameter keys methodName, loadJar, jarByteArray, hasClass, className, and result; fields parameterMap, exStr, and mconnClass; and two hex class constants beginning with cafebabe. Reflective calls include defineClass, Class.forName, and URLClassLoader.addURL, plus access to URL.handlers or URL.ph_cache.

Some Godzilla features are extended by loading GodzillaJna.jar through this module.

jarloader-godzillajna-extension

ReGeorg.classs

This module dynamically registers a Servlet in Tomcat to implant an in-memory ReGeorg Java webshell. ReGeorg is a classic HTTP tunneling tool (project page). Its role is to establish a TCP channel between the target server and internal hosts over web requests.

Like Behinder.classs and Cknife.classs, ReGeorg.classs uses reflection against Tomcat internals for Servlet injection. ReGeorg itself is a "forward proxy / tunnel" style memory webshell: its core logic is not command execution or file management, but controlling CONNECT, READ, FORWARD, and DISCONNECT via the X-CMD request header, using SocketChannel to connect to internal targets and retaining the socket channel in the HTTP session.

After execution, Tomcat dynamically registers a Servlet, memory contains ReGeorg classes and x.ReGeorg, and MapperListener and Valve are modified. Unlike Behinder/Cknife, ReGeorg also stores a SocketChannel in the HTTP Session and, on later READ/FORWARD requests, retrieves that socket from session for data forwarding. Because it mainly tunnels traffic, one may likewise observe java middleware accessing uncommon network ports, as with port scanning.

AttachShellcodeLoader.classs

This module is a native shellcode injector for Java. It abuses the JDK Attach API to inject shellcode into an arbitrary Windows process and execute it.

At runtime it reads executableFile and shellcodeHex from parameterMap. executableFile names the host process to launch (default C:/Windows/System32/userinit.exe), which need not be a JVM and can be any Windows executable. shellcodeHex is the shellcode byte array encoded as hex.

attachshellcode-loader-parameters

The init method reflectively calls defineClass through the system class loader. It dynamically defines sun.tools.attach.WindowsVirtualMachine and sun.tools.attach.VirtualMachineImpl from bytecode hardcoded in WindowsVirtualMachineHex and VirtualMachineImplHex. Those classes' static initializers execute System.loadLibrary("attach"), loading the JDK's attach.dll.

The run method uses ProcessBuilder to start the process named by executableFile, then reflectively reads the Process object's handle field to obtain the target process handle.

attachshellcode-process-handle

It then reflectively calls WindowsVirtualMachine.enqueue with the process handle and shellcode byte array. enqueue is normally the legitimate JNI function Java_sun_tools_attach_WindowsVirtualMachine_enqueue in attach.dll, designed to send management commands to a JVM. Here the stub argument is replaced with attacker-supplied shellcode, so attach.dll uses VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, and related APIs to write and run the shellcode in the target process.

attachshellcode-enqueue-injection

If WindowsVirtualMachine.enqueue throws UnsatisfiedLinkError, it falls back to VirtualMachineImpl.enqueue. The result is written to the result key in parameterMap. Success returns "ok", and failure returns the exception stack.

After execution, the Java process loads the attach native library. Memory contains AttachShellcodeLoader, WindowsVirtualMachine, and VirtualMachineImpl, plus two class bytecode constants beginning with cafebabe. The process also creates the child named by executableFile and calls the enqueue native method, and the target process memory shows remotely threaded shellcode. With default parameters one may also observe the uncommon behavior of java creating userinit.

ShellcodeLoader.classs

This module's core capability is extended by loading GodzillaJna.jar via JarLoader.classs. Although it and AttachShellcodeLoader both load shellcode, the mechanisms differ: it uses JNA to load jna.sun.jna.platform.godzilla.AsmcodeLoad from GodzillaJna.jar and directly calls kernel32 APIs such as VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread for injection.

When the excuteFile parameter is empty, the module loads shellcode directly into the current process, an additional capability relative to AttachShellcodeLoader.

shellcodeloader-jna-injection

Bypassing disable_functions

This section covers all PHP feature modules related to bypassing disable_functions.

Some modules are dispatched by shells.plugins.php.BypassDisableFunctions. On Linux webshells it supports: php-filter-bypass, disfunpoc, php-json-bypass, php7-backtrace-bypass, php7-gc-bypass, php7-SplDoublyLinkedList-uaf, procfs_bypass, php74-FFI-BUG, php5-imap_open, php7-FFI, and PHP74-FFI-Serializable. On Windows it only supports php-filter-bypass and php-com.

These PHP modules are grouped by technique into four types: MemBypass, EnvBypass, FPMBypass, and AMCBypass.

bypass-disable-functions-types

When running MemBypass with the php-filter-bypass module loaded, Godzilla has that module redirect execution output to a file whose extension is an MD5 hash string:

membypass-md5-result-file

When running EnvBypass and FPMBypass, the corresponding PHP module code first accepts parameters, then writes an so file, a cmd file, and a result file to the specified path:

envbypass-fpmbypass-file-drop

All of these files use an MD5 hash string as the extension. The so file is assembled from the template ant_x64.so or ant_x86.so plus the real command line.

ant-so-template-assembly

Almost all PHP feature modules related to bypassing disable_functions cause the php middleware process to create cmd, bash, or sh.

Common Modules

SuperTerminal

This module is Godzilla's interactive terminal plugin and provides pseudo-terminal capability on Windows and Linux. It is an abstract class and depends on the RealCmd module to run commands and maintain an interactive session on the target.

On Windows it supports winpty and winShellhost. winpty uploads winpty_x64.dll or winpty_x32.dll plus winpty-agent.exe to a temporary directory:

superterminal-winpty-upload

winShellhost uploads shellhost-agent.exe:

superterminal-winshellhost-upload

Before upload it checks whether the file already exists and skips if so.

On Linux it first tries python, python3, and python2. If Python is found it runs python -c 'import pty; pty.spawn("bash")'. If not, it uploads the built-in assets/linuxpty to a temporary directory as pty- plus a random UUID, then runs chmod +x and executes it.

superterminal-linuxpty-upload

When this module runs, one may observe winpty_x64.dll, winpty_x32.dll, winpty-agent.exe, shellhost-agent.exe, or random files beginning with pty- being created by the web middleware process, or on Linux the middleware spawning a python interpreter.

Mimikatz

This module uses the ShellcodeLoader feature module to convert mimikatz into shellcode and load it into a remote process.

mimikatz-shellcode-loader

With default parameters, one should observe a child process created by middleware improperly accessing lsass memory.

mimikatz-lsass-memory-access

IOCs

Although some modules are derived from open-source projects, every .NET DLL includes overridden Equals and ToString methods adapted for Godzilla. There is reason to treat these modules as Godzilla-unique, at least initially.

NameSHA256Notes
payload.dllCD310C1827D7F9686C56B7CA259E8782A17964C23E93C932AE201F78AB046B20
payload.dllF4967773F525CD392BC79B2252F48B5819AA99A0643DAE1A28BF5AE998A87AB4Since v3.00
payload.dllCFCBB3014ECC560BA36103213B36FC62D6B0EF22C49067FF0D860FD7253A7C94Since v4.0
BadPotato.dllBCAF32B547CE962291C3E905B9FE6DD2DF389B19DA01DEDFF9BD7B2BB5B71039
BadPotato.dllF0E64281D017D1E09ECD8853E326874A8E94795A95235A2D8D64BCBA1A47954ESince v4.0
CZip.dll9EE46729A9109BF6A5E802EA0F3698DCD38EB5DC1BC5529954D1121B089DD717
CZip.dll1B8322A9E47F3662EE46E49C19F03BB469D28870B96E6E0A4C8A70DF3F15622CSince v4.0
lemon.dllEC9204B818A8BF3893428EB9C869E8AA2D53EAAC52D9CB249EDE288DBF042FEA
lemon.dll693352CF8536AFB270962CEE3DF84EE8121B9AC45D2CF496039745AEAD48752ASince v4.0
RevlCmd.dll8AB8E1D302F81AF6F3C240642489B297C549DE98A7E46C8436CBA750BF288B51
SafetyKatz.dllB42F9571D486A8AEF5B36D72C1C8FFF83F29CAC2F9C61AECE3AD70537D49B222
SharpWeb.dll89A0C5BFA07F8C0114208173EB77B9A49A43CEE5694C5111DD178EA0B51C51F0
SharpWeb.dll76F2B8F074145F649F4B828F874AEC4AC4D85CEEF654537005EFD263F0780185Since v4.0
ShellcodeLoader.dllE12832E1232D955258AAE108C0BDD667AEBE2A11D1C49EBBA5F4FC2449AFDAA2
SweetPotato.dll734C3A8EC0D442A49C7909702012C50AB2DB32CFED02E82B5C19A5AFDA5A87D3
SweetPotato.dllA9FEF22AC2ECD5DE42B1A46543E7791620BD9217D35D17C33813439CF293486CSince v4.0
AsmLoader.dllC7A981D8C99040A7E3BA09A786249185C7B47C5C2DC9D03D8491BB69FA966017Since v4.0
CProtScan.dll21D41E466F8162D132F993FCF59E5EA6A59CCCDDC3386DD27FB1C1D4815E5D71Since v4.0
EfsPotato.dllD8EFF00E73FF007504786EB4E2308460DE1E0F2C66C176F23A76630F00752209Since v4.0
HttpRequest.dllE802DE292F231A8D9DBA640261080DBB5AA56BB6C7ED8CA71092A089209C87D6Since v4.0
memoryShell.dll3C35403BF25E3900871E873B38796ABFDCF3A78CF3C1123E13BA1097E606E397Since v4.0
RealCmd.dll5B8EC91B3366E3D37F68DE4B20B7F29D183D2C13B2429A48308E225DDCBC0E1FSince v4.0
efsPotato-32.exe13372771A7C2DF00E248E963B11B974D9EA2A3A0CAB7F77D4DF2AFA59DB4B04BSince v4.0
efsPotato-64.exe2D1B66619AFE4D0819004F0ECD2B429921596D1AF1F6A0EB88817F02E47C8C00Since v4.0
mimikatz-32.exeE81A8F8AD804C4D83869D7806A303FF04F31CCE376C5DF8AADA2E9DB2C1EEB98Since v4.0
mimikatz-64.exe912018AB3C6B16B39EE84F17745FF0C80A33CEE241013EC35D0281E40C0658D9Since v4.0
linuxptyA71965F2248F1E8FB7B7A4610ED4F4F1ECD2D9769BB1561838071C940013569ASince v4.0
ant_x64.dll27EF30B04B734A8DD61A049D755A141D8871854F9D988CF6FDB1196159F58B63Since v4.0
ant_x64.soF23690E52D2A2842CA82F082BA78F0DFA5B651ED8C8DE411266C64BB025800F0Since v4.0
ant_x86.dll6D89BBDF7847630B827DD5B059645CEEF0E8C6636A10DB8B34FCC4097EC40EC5Since v4.0
ant_x86.so2AAA036A885C9FCAEDDFF757E18F97C7CF48D89C69BE58E5DA9DE6DDDE717C79Since v4.0

We also published a Yara rule to detect Godzilla webshell scripts across major versions. The rule set will continue to be updated to cover Godzilla webshells and their latest variants.

Organizations with hash matches to the unique module IOCs above include:

Activity identified as using Godzilla via webshell scripts or behavioral characteristics includes:

There is currently no indication that technical reports related to Godzilla IOCs describe activity occurring before the corresponding Godzilla version was released.