Publicly available security tools have long been favored by penetration testers: they are easy to obtain, feature-rich, and impose no maintenance cost on the operator. We likewise believe that many APT actors and opportunistic attackers use them frequently, and that the malicious techniques involved are fairly generic. Analyzing these tools is worthwhile work, and we plan to start with a webshell framework named Godzilla and, as far as possible, expose the key technical details of popular hacking tools. This should help defenders strengthen network defense and threat hunting. We also hope to derive specific rules that help the security community quickly spot advanced attackers who rely on these techniques.
About Godzilla
Godzilla is a cross-platform webshell management tool written in Java. It supports webshells in ASP, ASP.NET, Java, and PHP, ships with plugins for specific capabilities, and provides relatively strong traffic encryption.
It is currently hosted on both GitHub and Gitee; the Gitee mirror is likely intended for users who cannot reach GitHub. The original project does not provide an open-source edition, and the author is BeichenDream. The tool was updated frequently in 2020 and 2021 across 10 versions. The latest version on GitHub is currently v4.01. During our research we also found two additional builds, v4.15 (a "特战版" edition) and ekp1.2, which we will analyze in a follow-up article.
Taking v4.01 as an example, Godzilla's main UI looks like this:

The main UI exposes several key features. Under the Target menu, Add lets you register a webshell and configure it in detail. Under the Manage menu, Generate produces a webshell with a chosen configuration. Once a reachable webshell path is available, the tool presents a control panel for that webshell type with a rich set of capabilities. An ASP.NET example is shown below:

Technical Design
Based on parameters configured in the UI, Godzilla reads the matching template resources and assembles a webshell. The following shows Java webshell generation details in v4.01:

Once the generated webshell is deployed on the target site, the attacker can use the tool for encrypted communication with that site. Depending on the scripting language, Godzilla reads the corresponding main payload, encrypts it, and sends it to the webshell:

The webshell decrypts and loads the main payload, keeping the core capability code resident in memory:

When the attacker uses basic features in the webshell control panel, the tool assembles parameters from the UI, sends them to the webshell, and invokes the matching function in the in-memory main payload. Taking basic information retrieval as an example:

This is the overall technical design and is not limited to Java. We focus on indicators and behaviors that can actually be detected, and the following sections analyze them in detail.
Main Payload
Godzilla implements a main payload for ASP, ASP.NET, Java, and PHP respectively. Using v4.01 as an example:
| Type | Full name |
|---|---|
| ASP | shells.payloads.asp.assets.payload.asp |
| ASP.NET | shells.payloads.csharp.assets.payload.dll |
| Java | shells.payloads.java.assets.payload.classs |
| PHP | shells.payloads.php.assets.payload.php |
The main payload resides and runs in memory on the target server and provides Godzilla's common baseline capabilities:
| Function | Description | Notes |
|---|---|---|
| bigFileDownload | Reads file content by offset and byte length for chunked large-file download | Since v3.00 |
| bigFileUpload | Writes file content by offset and byte length for chunked large-file upload | Since v3.00 |
| close | Closes the current webshell session | Since v3.00 |
| copyFile | Copies a file | |
| deleteFile | Deletes a file | |
| downloadFile | Reads an entire file for download | |
| execCommand | Executes a system command | |
| execSql | Connects to a database and executes SQL | |
| fileRemoteDown | Downloads a given URL | Since v3.00 |
| getBasicsInfo | Collects basic runtime environment information | |
| getFile | Lists subdirectory and file information under a directory | |
| getFileSize | Gets file size | Since v3.00 |
| include | Writes an extension module's content and name into memory | |
| run | Executes a specified method or extension module | |
| moveFile | Moves a file | |
| newDir | Creates a directory | |
| newFile | Creates an empty file | |
| setFileAttr | Sets basic file attributes or modification time | Since v3.00 |
| test | Verifies that the main payload is functioning | |
| uploadFile | Writes an entire file for upload |
Different webshell types load their main payload differently.
For ASP, the main payload is stored under the Session key payload, then later loaded via Execute to run specific functions:

For PHP, the main payload (a PHP code string) is XOR-encrypted and stored under the Session key payload. Later it is retrieved from Session, decrypted, and executed directly with eval, which calls the defined run function to process request data:

For ASP.NET, the main payload is loaded into memory via reflective Assembly.Load and stored under the Session key payload. Later the loaded assembly is retrieved from Session, an instance of class LY is created, and commands are executed by calling that instance's Equals and ToString methods:

In the ASP.NET main payload, Equals and ToString are overridden. Equals acts as a parameter receiver; ToString triggers command execution and returns the encoded result:

For Java, the main payload is loaded into memory via a custom class loader's defineClass method and stored under the Session key payload. Later the loaded Class object is retrieved from Session, an instance is created, and commands are executed by calling that instance's equals and toString methods. The design mirrors ASP.NET; the difference is in the overridden methods. Java places command data in the request attribute in advance, and equals only receives PageContext and triggers parameter parsing:

The main payload itself offers little that is distinctive: its functions are mostly primitives. Detection opportunities appear mainly when callers abuse those primitives. Aside from execCommand, when any main-payload type executes commands on Windows, a middleware process typically spawns cmd; on Linux it usually spawns sh or bash.
Overall it is specific to Godzilla and runs entirely in memory, but that does not mean there are no detection opportunities. PHP webshells store the main payload in $_SESSION['payload']. Under default configuration this creates a Session file on disk containing the encrypted PHP main-payload code:

Although Godzilla has tried to evade detection from early versions, extracting keys on the network side and decrypting corresponding Session data to recover the main-payload code makes a precise PHP-focused detector comparatively practical. Java main payloads can be monitored and blocked in real time with mature Java Agent or RASP approaches. For ASP.NET, one can monitor .NET runtime (CLR) load behavior and scan process memory for suspicious assemblies with no on-disk counterpart. How to build such detectors is outside the scope of this article.
Feature Modules
Godzilla uses the main payload's include capability to add extra feature modules into memory. ASP and PHP store feature modules directly in Session; ASP.NET loads them via Assembly.Load; Java loads them via a custom class loader's defineClass. Feature-module loading matches main-payload loading.
| Module full name | Type | Description | Notes |
|---|---|---|---|
| shells.plugins.asp.assets.PortScan.asp | ASP | Port scanner | Since v4.0 |
| shells.plugins.asp.assets.evalCode.asp | ASP | Execute custom ASP code | Since v4.0 |
| shells.plugins.cshap.assets.AsmLoader.dll | ASP.NET | Shellcode loader | Since v4.0 |
| shells.plugins.cshap.assets.BadPotato.dll | ASP.NET | Windows privilege-escalation exploit | |
| shells.plugins.cshap.assets.CProtScan.dll | ASP.NET | Port scanner | Since v4.0 |
| shells.plugins.cshap.assets.CZip.dll | ASP.NET | ZIP compress / decompress | Since v4.0 |
| shells.plugins.cshap.assets.EfsPotato.dll | ASP.NET | Windows privilege-escalation exploit | Since v4.0 |
| shells.plugins.cshap.assets.HttpRequest.dll | ASP.NET | HTTP request utility | Since v4.0 |
| shells.plugins.cshap.assets.RealCmd.dll | ASP.NET | Remote interactive process control | Since v4.0 |
| shells.plugins.cshap.assets.SharpWeb.dll | ASP.NET | Browser credential stealer | |
| shells.plugins.cshap.assets.SweetPotato.dll | ASP.NET | Windows privilege-escalation exploit | |
| shells.plugins.cshap.assets.lemon.dll | ASP.NET | Ops-software credential stealer | |
| shells.plugins.cshap.assets.memoryShell.dll | ASP.NET | In-memory ASP.NET Godzilla webshell | Since v4.0 |
| shells.plugins.java.assets.Behinder.classs | Java | In-memory Behinder Java webshell | Not present in v3.x |
| shells.plugins.java.assets.Cknife.classs | Java | In-memory Cknife Java webshell | |
| shells.plugins.java.assets.FilterManage.classs | Java | Java Filter manager | Since v4.0 |
| shells.plugins.java.assets.HttpRequest.classs | Java | HTTP request utility | Since v4.0 |
| shells.plugins.java.assets.JPortScan.classs | Java | Port scanner | Since v4.0 |
| shells.plugins.java.assets.JZip.classs | Java | ZIP compress / decompress | |
| shells.plugins.java.assets.JarLoader.classs | Java | In-memory JAR loader | |
| shells.plugins.java.assets.Meterpreter.classs | Java | Meterpreter backdoor | |
| shells.plugins.java.assets.ReGeorg.classs | Java | In-memory reGeorg HTTP tunnel | |
| shells.plugins.java.assets.RealCmd.classs | Java | Remote interactive process control | |
| shells.plugins.java.assets.ServletManage.classs | Java | Java Servlet manager | |
| shells.plugins.java.assets.ShellDriver.classs | Java | Database connection credential stealer | Since v2.96 |
| shells.plugins.java.assets.AttachShellcodeLoader.classs | Java | Shellcode loader | v3.01 to v3.03 |
| shells.plugins.java.assets.ShellcodeLoader.classs | Java | Shellcode loader | Since v4.0 |
| shells.plugins.php.assets.Apache_mod_cgi.php | PHP | Command execution bypassing disable_functions | Since v4.0 |
| shells.plugins.php.assets.AttackFPM.php | PHP | PHP-FPM FastCGI attack utility | Since v4.0 |
| shells.plugins.php.assets.ByPassOpenBasedir.php | PHP | open_basedir bypass marker | |
| shells.plugins.php.assets.FPM.php | PHP | Command execution bypassing disable_functions | Since v4.0 |
| shells.plugins.php.assets.HttpRequest.php | PHP | HTTP request utility | Since v4.0 |
| shells.plugins.php.assets.LD_PRELOAD.php | PHP | Command execution bypassing disable_functions | Since v4.0 |
| shells.plugins.php.assets.PHP74-FFI-Serializable.php | PHP | Command execution bypassing disable_functions | Since v4.0 |
| shells.plugins.php.assets.PZip.php | PHP | ZIP compress / decompress | |
| shells.plugins.php.assets.PortScan.php | PHP | Port scanner | Since v4.0 |
| shells.plugins.php.assets.Ps.php | PHP | Process listing | Since v4.0 |
| shells.plugins.php.assets.WebShellScan.php | PHP | PHP webshell scanner | Since v4.0 |
| shells.plugins.php.assets.disfunpoc.php | PHP | disable_functions bypass | |
| shells.plugins.php.assets.eval.php | PHP | PHP code-execution backdoor | Since v4.0 |
| shells.plugins.php.assets.evalCode.php | PHP | Execute custom PHP code | |
| shells.plugins.php.assets.meterpreter.php | PHP | Meterpreter backdoor | |
| shells.plugins.php.assets.ntunnel_mysql.php | PHP | MySQL connection tunnel | Legitimate Navicat tool, since v4.0 |
| shells.plugins.php.assets.ntunnel_pgsql.php | PHP | PostgreSQL connection tunnel | Legitimate Navicat tool, since v4.0 |
| shells.plugins.php.assets.ntunnel_sqlite.php | PHP | SQLite connection tunnel | Legitimate Navicat tool, since v4.0 |
| shells.plugins.php.assets.php-com.php | PHP | Execute arbitrary commands via COM | Since v4.0 |
| shells.plugins.php.assets.php-filter-bypass.php | PHP | Command execution bypassing disable_functions | Since v4.0 |
| shells.plugins.php.assets.php-json-bypass.php | PHP | Command execution bypassing disable_functions | |
| shells.plugins.php.assets.php5-imap_open.php | PHP | CVE-2018-19518 | Since v4.0 |
| shells.plugins.php.assets.php7-FFI.php | PHP | Command execution bypassing disable_functions | Since v4.0 |
| shells.plugins.php.assets.php7-SplDoublyLinkedList-uaf.php | PHP | Command execution bypassing disable_functions | Since v4.0 |
| shells.plugins.php.assets.php7-backtrace-bypass.php | PHP | Command execution bypassing disable_functions | |
| shells.plugins.php.assets.php7-gc-bypass.php | PHP | Command execution bypassing disable_functions | |
| shells.plugins.php.assets.php74-FFI-BUG.php | PHP | Command execution bypassing disable_functions | Since v4.0 |
| shells.plugins.php.assets.procfs_bypass.php | PHP | Command execution bypassing disable_functions | |
| shells.plugins.php.assets.realCmd.php | PHP | Remote interactive process control | Since v4.0 |
We only analyze modules that are realistic candidates for generic detection. Modules built from open-source projects are described only briefly.
PortScan
All language editions include a port-scan module. In real environments one may observe w3wp, java middleware, or php middleware accessing uncommon network ports.
The ASP edition is unusual. It uses ASP's ADODB.Connection object and the SQLOLEDB.1 provider, builds a SQL Server connection string Data Source=ip,port;User ID=a;Password=a; from the target IP and port, sets a 1-second connect timeout, then calls Open. Through the OLEDB driver it opens a TCP connection to the target port and attempts to send TDS pre-login/login data. Port status is inferred from the failure stage: if the connect stage fails and the error description contains (Connect())., the port is treated as closed or unreachable and 0 is returned; if the TCP connection succeeds but login fails, a service is considered present on that port and 1 is returned. Results are aggregated as ip\tport\t状态.

This scan is clearly anomalous in traffic. Typical port scans send only TCP SYN or perform a minimal handshake. This method completes a full TCP three-way handshake and sends full TDS pre-login/login data, so probing non-SQL Server ports such as 445 can produce TDS on an SMB port. The figure below shows Pre-Login:

Login packets may also contain plaintext such as hostname, connection string, and client information. The figure below shows Login7:

AsmLoader.dll
This module executes shellcode based on parameters. If excuteFile is empty, it allocates executable memory in the current process, creates a thread to run the shellcode, and returns ok. If the shellcode is empty it returns shellcode is Null, and on exceptions it returns the exception message, as shown below:

If shellcode is non-empty and excuteFile has a value, it calls AsmLoader.loadAsmBin to inject into the specified process and returns the output:

This code always runs inside w3wp.exe. With excuteFile set, it creates a suspended child process, allocates RWX memory in that process, writes random padding and shellcode, then uses CreateRemoteThread to execute from offset 1024 and read pipe output. A normal IIS worker process does not create child processes and remotely inject them. Without excuteFile, w3wp itself uses VirtualAlloc for RWX memory, Marshal.Copy to write shellcode, and CreateThread to execute it, producing anonymous executable memory and non-module threads inside the worker.
By default excuteFile is C:\Windows\System32\rundll32.exe. In practice one may observe w3wp creating rundll32.
BadPotato.dll
This module is based on an open-source project. It creates a fake spoolss named-pipe server and induces the Print Spooler service running as SYSTEM to connect. Once connected, BadPotato calls ImpersonateNamedPipeClient to impersonate that high-privilege client token and elevate to NT AUTHORITY\SYSTEM. Some implementations first create a random-GUID sub-pipe, but the final pipe name that lures the privileged process always contains the key string spoolss.

Under default UI settings, running this module yields w3wp creating cmd.
RealCmd
Equivalent implementations exist for ASP.NET, Java, and PHP. The core idea is to maintain an interactive channel to a child process on the target (such as cmd.exe or /bin/bash) over web requests. On start, the module creates the process from parameters and redirects stdin, stdout, and stderr. ASP.NET and Java use a background thread to continuously read process output and cache it in a memory object bound to the current HTTP session. PHP cannot retain process resources across requests, so it simulates interactivity with a blocking loop plus a Session buffer. The frontend controls the session via the action parameter (start, processWriteData, getResult, stop). All returned data is prefixed with a 0x05 protocol marker byte. On Windows the module can also invoke winpty to obtain a pseudo-terminal for interactive CLI programs.
Under default UI settings, running this module yields w3wp (or java / php-fpm) creating cmd.exe (or /bin/bash).
SharpWeb.dll
This module is based on an open-source project. It recovers saved account passwords from common browser and system credential stores on the target Windows host. It walks browser data directories under the current user and loaded user profiles, locates Chrome/Chromium/Edge Login Data SQLite databases, Firefox logins.json and key4.db, and IE / Windows Vault credential files, then uses Windows DPAPI (CryptUnprotectData) to decrypt protected keys and AES-GCM (and related algorithms) to recover plaintext browser credentials. Godzilla loads the .NET assembly in memory, so no executable is dropped to disk, but at runtime one may observe w3wp reading browser databases, accessing Local State, and calling crypt32.dll.
SweetPotato.dll
This module is based on an open-source project. The base version was developed by EthicalChaos; uknowsec adapted it to run commands in a webshell environment. It combines multiple local Windows privilege-escalation techniques and supports DCOM, WinRM, EfsRpc, and PrintSpoofer, defaulting to PrintSpoofer. In PrintSpoofer mode, w3wp calls CreatePipe to create a named pipe, induces the Print Spooler service (spoolsv.exe) running as SYSTEM to connect, then calls ImpersonateNamedPipeClient to impersonate the SYSTEM token and elevate to NT AUTHORITY\SYSTEM. In EfsRpc mode, w3wp triggers a SYSTEM connection via MS-EFSR and likewise relies on named-pipe token impersonation. In DCOM or WinRM mode, w3wp listens on a local port (default 6666) and induces a SYSTEM component to initiate NTLM authentication, then relays to activate objects, and this path does not depend on named pipes.
Observed behavior varies by exploit mode.
On the PrintSpoofer path, w3wp creates a named pipe whose name contains spoolss, after which a SYSTEM-privileged process connects. After impersonating the client token, w3wp creates a child cmd.exe running as NT AUTHORITY\SYSTEM.

On the DCOM path, w3wp listens on local port 6666 and establishes a local network connection with a SYSTEM component. On the WinRM path, w3wp listens on local port 5985 and likewise connects with a SYSTEM component. On both paths, w3wp loads ole32.dll, rpcrt4.dll, combase.dll, clr.dll, and mscoree.dll, then creates a SYSTEM-privileged child process. Throughout, the w3wp thread token and process token become NT AUTHORITY\SYSTEM.
Because the module runs via in-memory loading, there is no corresponding executable on disk.
lemon.dll
This module collects credentials saved by FileZilla, Navicat, SqlYog, WinSCP, and Xshell on the target Windows host. The run method invokes five collector classes (FileZilla, Navicat, SqlYog, WinSCP, and Xmangager) in turn, reading each product's config files and registry keys and decrypting stored credentials.

w3wp reads the following locations: FileZilla's %APPDATA%\FileZilla\recentservers.xml; SQLyog walks all user directories under %SystemDrive%\Users\ and reads AppData\Roaming\SQLyog\sqlyog.ini; Xshell reads %SystemDrive%\Users\%USERNAME%\Documents\NetSarang Computer\6\Xshell\Sessions\; Navicat reads registry HKCU\SOFTWARE\PremiumSoft\*\Servers\*; WinSCP walks HKEY_USERS SIDs beginning with S-1-5-21-* and reads Software\Martin Prikryl\WinSCP 2\Sessions\*.
memoryShell.dll
This module is an ASP.NET VirtualPathProvider-style in-memory webshell. It registers malicious logic into the ASP.NET runtime of the w3wp process and lives for the lifetime of the application pool.
The core mechanism is registering a custom VirtualPathProvider. Run.addShell reflectively calls HostingEnvironment.RegisterVirtualPathProviderInternal and attaches a GodzillaVirtualPathProvider instance to the ASP.NET virtual-path system.

After registration, ASP.NET request handling invokes that provider's malicious GetCacheKey method. The trigger conditions are specific: the request must be POST, Content-Type must contain www-form, and a request parameter named password must exist. When matched, w3wp takes Base64 ciphertext from that parameter, decrypts it with Rijndael using key, and obtains a .NET assembly byte array.

To work in more environments, the module also provides two bypasses. bypassFriendlyUrlRoute reflectively locates Microsoft.AspNet.FriendlyUrls.FriendlyUrlRoute and sets AutoRedirectMode to 2. bypassPrecompiledApp reflectively sets BuildManager's _isPrecompiledAppComputed to true and _isPrecompiledApp to false, forcing precompiled apps onto the dynamic compilation path.
The module runs entirely in w3wp memory, with no corresponding DLL or ASPX on disk, and the implant disappears when the application pool recycles.
Behinder.classs
This module dynamically registers a Servlet in Tomcat to implant an in-memory Behinder Java webshell. Behinder is a Chinese webshell manager (project page).
After execution, the Tomcat process dynamically creates a Wrapper and registers a Servlet at the path given by the path parameter. Requests to that path enter _jspService, load AES-decrypted bytecode, modify MapperListener's exactWrappers, and modify Valve's condition. Memory contains Behinder classes, x.Behinder, and a random key.
Cknife.classs
This module dynamically registers a Servlet in Tomcat to implant an in-memory Cknife Java webshell with file management, command execution, and database operations. Cknife is likewise a Chinese webshell manager (project page).
The entry class Cknife extends HttpServlet, reflectively obtains StandardContext, creates a Wrapper, registers a servlet mapping, then modifies MapperListener's exactWrappers so requests route to that Servlet, while also modifying Valve's condition to bypass access logging. Requests are identified via the pwd parameter and dispatched by funccode, and results are wrapped with ->| and |<-.
After execution, Tomcat dynamically registers a Servlet, memory contains Cknife classes and x.Cknife, and MapperListener and Valve are modified.
JarLoader.classs
This module is an in-memory JAR loader for Java. Through a custom jarmembuff URL protocol and reflective injection, it loads a JAR byte array into the target JVM without writing a file.
Observable artifacts include class names JarLoader, MemoryBufferURLConnection, and MemoryBufferURLStreamHandler; protocol name jarmembuff; parameter keys methodName, loadJar, jarByteArray, hasClass, className, and result; fields parameterMap, exStr, and mconnClass; and two hex class constants beginning with cafebabe. Reflective calls include defineClass, Class.forName, and URLClassLoader.addURL, plus access to URL.handlers or URL.ph_cache.
Some Godzilla features are extended by loading GodzillaJna.jar through this module.

ReGeorg.classs
This module dynamically registers a Servlet in Tomcat to implant an in-memory ReGeorg Java webshell. ReGeorg is a classic HTTP tunneling tool (project page). Its role is to establish a TCP channel between the target server and internal hosts over web requests.
Like Behinder.classs and Cknife.classs, ReGeorg.classs uses reflection against Tomcat internals for Servlet injection. ReGeorg itself is a "forward proxy / tunnel" style memory webshell: its core logic is not command execution or file management, but controlling CONNECT, READ, FORWARD, and DISCONNECT via the X-CMD request header, using SocketChannel to connect to internal targets and retaining the socket channel in the HTTP session.
After execution, Tomcat dynamically registers a Servlet, memory contains ReGeorg classes and x.ReGeorg, and MapperListener and Valve are modified. Unlike Behinder/Cknife, ReGeorg also stores a SocketChannel in the HTTP Session and, on later READ/FORWARD requests, retrieves that socket from session for data forwarding. Because it mainly tunnels traffic, one may likewise observe java middleware accessing uncommon network ports, as with port scanning.
AttachShellcodeLoader.classs
This module is a native shellcode injector for Java. It abuses the JDK Attach API to inject shellcode into an arbitrary Windows process and execute it.
At runtime it reads executableFile and shellcodeHex from parameterMap. executableFile names the host process to launch (default C:/Windows/System32/userinit.exe), which need not be a JVM and can be any Windows executable. shellcodeHex is the shellcode byte array encoded as hex.

The init method reflectively calls defineClass through the system class loader. It dynamically defines sun.tools.attach.WindowsVirtualMachine and sun.tools.attach.VirtualMachineImpl from bytecode hardcoded in WindowsVirtualMachineHex and VirtualMachineImplHex. Those classes' static initializers execute System.loadLibrary("attach"), loading the JDK's attach.dll.
The run method uses ProcessBuilder to start the process named by executableFile, then reflectively reads the Process object's handle field to obtain the target process handle.

It then reflectively calls WindowsVirtualMachine.enqueue with the process handle and shellcode byte array. enqueue is normally the legitimate JNI function Java_sun_tools_attach_WindowsVirtualMachine_enqueue in attach.dll, designed to send management commands to a JVM. Here the stub argument is replaced with attacker-supplied shellcode, so attach.dll uses VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, and related APIs to write and run the shellcode in the target process.

If WindowsVirtualMachine.enqueue throws UnsatisfiedLinkError, it falls back to VirtualMachineImpl.enqueue. The result is written to the result key in parameterMap. Success returns "ok", and failure returns the exception stack.
After execution, the Java process loads the attach native library. Memory contains AttachShellcodeLoader, WindowsVirtualMachine, and VirtualMachineImpl, plus two class bytecode constants beginning with cafebabe. The process also creates the child named by executableFile and calls the enqueue native method, and the target process memory shows remotely threaded shellcode. With default parameters one may also observe the uncommon behavior of java creating userinit.
ShellcodeLoader.classs
This module's core capability is extended by loading GodzillaJna.jar via JarLoader.classs. Although it and AttachShellcodeLoader both load shellcode, the mechanisms differ: it uses JNA to load jna.sun.jna.platform.godzilla.AsmcodeLoad from GodzillaJna.jar and directly calls kernel32 APIs such as VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread for injection.
When the excuteFile parameter is empty, the module loads shellcode directly into the current process, an additional capability relative to AttachShellcodeLoader.

Bypassing disable_functions
This section covers all PHP feature modules related to bypassing disable_functions.
Some modules are dispatched by shells.plugins.php.BypassDisableFunctions. On Linux webshells it supports: php-filter-bypass, disfunpoc, php-json-bypass, php7-backtrace-bypass, php7-gc-bypass, php7-SplDoublyLinkedList-uaf, procfs_bypass, php74-FFI-BUG, php5-imap_open, php7-FFI, and PHP74-FFI-Serializable. On Windows it only supports php-filter-bypass and php-com.
These PHP modules are grouped by technique into four types: MemBypass, EnvBypass, FPMBypass, and AMCBypass.

When running MemBypass with the php-filter-bypass module loaded, Godzilla has that module redirect execution output to a file whose extension is an MD5 hash string:

When running EnvBypass and FPMBypass, the corresponding PHP module code first accepts parameters, then writes an so file, a cmd file, and a result file to the specified path:

All of these files use an MD5 hash string as the extension. The so file is assembled from the template ant_x64.so or ant_x86.so plus the real command line.

Almost all PHP feature modules related to bypassing disable_functions cause the php middleware process to create cmd, bash, or sh.
Common Modules
SuperTerminal
This module is Godzilla's interactive terminal plugin and provides pseudo-terminal capability on Windows and Linux. It is an abstract class and depends on the RealCmd module to run commands and maintain an interactive session on the target.
On Windows it supports winpty and winShellhost. winpty uploads winpty_x64.dll or winpty_x32.dll plus winpty-agent.exe to a temporary directory:

winShellhost uploads shellhost-agent.exe:

Before upload it checks whether the file already exists and skips if so.
On Linux it first tries python, python3, and python2. If Python is found it runs python -c 'import pty; pty.spawn("bash")'. If not, it uploads the built-in assets/linuxpty to a temporary directory as pty- plus a random UUID, then runs chmod +x and executes it.

When this module runs, one may observe winpty_x64.dll, winpty_x32.dll, winpty-agent.exe, shellhost-agent.exe, or random files beginning with pty- being created by the web middleware process, or on Linux the middleware spawning a python interpreter.
Mimikatz
This module uses the ShellcodeLoader feature module to convert mimikatz into shellcode and load it into a remote process.

With default parameters, one should observe a child process created by middleware improperly accessing lsass memory.

IOCs
Although some modules are derived from open-source projects, every .NET DLL includes overridden Equals and ToString methods adapted for Godzilla. There is reason to treat these modules as Godzilla-unique, at least initially.
| Name | SHA256 | Notes |
|---|---|---|
| payload.dll | CD310C1827D7F9686C56B7CA259E8782A17964C23E93C932AE201F78AB046B20 | |
| payload.dll | F4967773F525CD392BC79B2252F48B5819AA99A0643DAE1A28BF5AE998A87AB4 | Since v3.00 |
| payload.dll | CFCBB3014ECC560BA36103213B36FC62D6B0EF22C49067FF0D860FD7253A7C94 | Since v4.0 |
| BadPotato.dll | BCAF32B547CE962291C3E905B9FE6DD2DF389B19DA01DEDFF9BD7B2BB5B71039 | |
| BadPotato.dll | F0E64281D017D1E09ECD8853E326874A8E94795A95235A2D8D64BCBA1A47954E | Since v4.0 |
| CZip.dll | 9EE46729A9109BF6A5E802EA0F3698DCD38EB5DC1BC5529954D1121B089DD717 | |
| CZip.dll | 1B8322A9E47F3662EE46E49C19F03BB469D28870B96E6E0A4C8A70DF3F15622C | Since v4.0 |
| lemon.dll | EC9204B818A8BF3893428EB9C869E8AA2D53EAAC52D9CB249EDE288DBF042FEA | |
| lemon.dll | 693352CF8536AFB270962CEE3DF84EE8121B9AC45D2CF496039745AEAD48752A | Since v4.0 |
| RevlCmd.dll | 8AB8E1D302F81AF6F3C240642489B297C549DE98A7E46C8436CBA750BF288B51 | |
| SafetyKatz.dll | B42F9571D486A8AEF5B36D72C1C8FFF83F29CAC2F9C61AECE3AD70537D49B222 | |
| SharpWeb.dll | 89A0C5BFA07F8C0114208173EB77B9A49A43CEE5694C5111DD178EA0B51C51F0 | |
| SharpWeb.dll | 76F2B8F074145F649F4B828F874AEC4AC4D85CEEF654537005EFD263F0780185 | Since v4.0 |
| ShellcodeLoader.dll | E12832E1232D955258AAE108C0BDD667AEBE2A11D1C49EBBA5F4FC2449AFDAA2 | |
| SweetPotato.dll | 734C3A8EC0D442A49C7909702012C50AB2DB32CFED02E82B5C19A5AFDA5A87D3 | |
| SweetPotato.dll | A9FEF22AC2ECD5DE42B1A46543E7791620BD9217D35D17C33813439CF293486C | Since v4.0 |
| AsmLoader.dll | C7A981D8C99040A7E3BA09A786249185C7B47C5C2DC9D03D8491BB69FA966017 | Since v4.0 |
| CProtScan.dll | 21D41E466F8162D132F993FCF59E5EA6A59CCCDDC3386DD27FB1C1D4815E5D71 | Since v4.0 |
| EfsPotato.dll | D8EFF00E73FF007504786EB4E2308460DE1E0F2C66C176F23A76630F00752209 | Since v4.0 |
| HttpRequest.dll | E802DE292F231A8D9DBA640261080DBB5AA56BB6C7ED8CA71092A089209C87D6 | Since v4.0 |
| memoryShell.dll | 3C35403BF25E3900871E873B38796ABFDCF3A78CF3C1123E13BA1097E606E397 | Since v4.0 |
| RealCmd.dll | 5B8EC91B3366E3D37F68DE4B20B7F29D183D2C13B2429A48308E225DDCBC0E1F | Since v4.0 |
| efsPotato-32.exe | 13372771A7C2DF00E248E963B11B974D9EA2A3A0CAB7F77D4DF2AFA59DB4B04B | Since v4.0 |
| efsPotato-64.exe | 2D1B66619AFE4D0819004F0ECD2B429921596D1AF1F6A0EB88817F02E47C8C00 | Since v4.0 |
| mimikatz-32.exe | E81A8F8AD804C4D83869D7806A303FF04F31CCE376C5DF8AADA2E9DB2C1EEB98 | Since v4.0 |
| mimikatz-64.exe | 912018AB3C6B16B39EE84F17745FF0C80A33CEE241013EC35D0281E40C0658D9 | Since v4.0 |
| linuxpty | A71965F2248F1E8FB7B7A4610ED4F4F1ECD2D9769BB1561838071C940013569A | Since v4.0 |
| ant_x64.dll | 27EF30B04B734A8DD61A049D755A141D8871854F9D988CF6FDB1196159F58B63 | Since v4.0 |
| ant_x64.so | F23690E52D2A2842CA82F082BA78F0DFA5B651ED8C8DE411266C64BB025800F0 | Since v4.0 |
| ant_x86.dll | 6D89BBDF7847630B827DD5B059645CEEF0E8C6636A10DB8B34FCC4097EC40EC5 | Since v4.0 |
| ant_x86.so | 2AAA036A885C9FCAEDDFF757E18F97C7CF48D89C69BE58E5DA9DE6DDDE717C79 | Since v4.0 |
We also published a Yara rule to detect Godzilla webshell scripts across major versions. The rule set will continue to be updated to cover Godzilla webshells and their latest variants.
Organizations with hash matches to the unique module IOCs above include:
- CL-UNK-1068
https://unit42.paloaltonetworks.com/cl-unk-1068-targets-critical-sectors/ - APT15 / Flea
https://www.security.com/threat-intelligence/flea-backdoor-microsoft-graph-apt15
Activity identified as using Godzilla via webshell scripts or behavioral characteristics includes:
- DEV-0322
https://www.microsoft.com/en-us/security/blog/2021/11/08/threat-actor-dev-0322-exploiting-zoho-manageengine-adselfservice-plus/
https://unit42.paloaltonetworks.com/manageengine-godzilla-nglite-kdcsponge/
https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a - Dalbit / m00nlight
https://asec.ahnlab.com/en/47455/ - Earth Baku (aka APT41)
https://www.trendmicro.com/en_us/research/24/h/earth-baku-latest-campaign.html - Silent Skimmer
https://arcticwolf.com/resources/blog/silent-skimmer-online-payment-scraping-campaign-shifts-targets-from-apac-to-nala/
There is currently no indication that technical reports related to Godzilla IOCs describe activity occurring before the corresponding Godzilla version was released.