{"id":17384955,"url":"https://github.com/cvar1984/sussyfinder","last_synced_at":"2026-01-19T08:04:53.722Z","repository":{"id":171912251,"uuid":"648589994","full_name":"Cvar1984/sussyfinder","owner":"Cvar1984","description":"Single file php webshell scanner to detect potentially malicious backdoor based on token and hash with web interface and VirusTotal integration","archived":false,"fork":false,"pushed_at":"2024-10-22T07:54:52.000Z","size":764,"stargazers_count":61,"open_issues_count":0,"forks_count":11,"subscribers_count":2,"default_branch":"main","last_synced_at":"2024-10-23T11:21:50.424Z","etag":null,"topics":["antivirus","backdoor","forensics","hacktoberfest","malware","malware-analysis","php","webshells"],"latest_commit_sha":null,"homepage":"","language":"PHP","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Cvar1984.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2023-06-02T10:23:44.000Z","updated_at":"2024-10-22T07:54:56.000Z","dependencies_parsed_at":null,"dependency_job_id":"944bcbb7-2ddd-475f-ae59-98f2b4387765","html_url":"https://github.com/Cvar1984/sussyfinder","commit_stats":null,"previous_names":["cvar1984/sussyfinder"],"tags_count":8,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Cvar1984%2Fsussyfinder","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Cvar1984%2Fsussyfinder/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Cvar1984%2Fsussyfinder/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Cvar1984%2Fsussyfinder/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Cvar1984","download_url":"https://codeload.github.com/Cvar1984/sussyfinder/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248684812,"owners_count":21145146,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["antivirus","backdoor","forensics","hacktoberfest","malware","malware-analysis","php","webshells"],"created_at":"2024-10-16T07:47:05.220Z","updated_at":"2026-01-19T08:04:53.712Z","avatar_url":"https://github.com/Cvar1984.png","language":"PHP","funding_links":[],"categories":[],"sub_categories":[],"readme":"# SussyFinder\n[![CodeFactor](https://www.codefactor.io/repository/github/cvar1984/sussyfinder/badge)](https://www.codefactor.io/repository/github/cvar1984/sussyfinder)\n[![PRs Welcome](https://img.shields.io/badge/PRs-welcome-brightgreen.svg?style=flat-square)](https://makeapullrequest.com)\n\nPHP web application that scans a directory for files with specific extensions (e.g., PHP scripts) and checks for suspicious tokens or patterns within the files.\n\nThe application uses various PHP functions and techniques to achieve this, including recursive directory scanning, file token extraction, and token comparison.\n\nThis tool is designed to help identify potentially malicious PHP files in a web server environment, but it should be used with caution as it may produce false positives and has the capability to delete files.\n## Requirements\n- PHP4/PHP5/PHP7/PHP8\n- VirusTotal APIKey (Optional)\n## Features\n- token based comparison (ignore some obfuscation technique)\n- support \"\u003c?\" and \"\u003c%\" notations\n- md5 hash based comparison (whitelist \u0026 blacklist)\n- recent times sorted result\n- highlight result by color\n- copy paste result\n\n![ss](https://raw.githubusercontent.com/Cvar1984/sussyfinder/main/demo.jpg)\n![profile](https://raw.githubusercontent.com/Cvar1984/sussyfinder/main/profile.png)\n\u003eclone webshells submodule for testing\n\n## Whitelist \u0026 blacklist\nWhitelist system exist to skip the program from scanning whitelisted files to speed up the whole thing.\n\nWhitelist hash i provide is harvested from common frameworks and libraries, its up to you to trust it or no.\n\nBlacklist system exist also to speed up the scanning progress and make it easier to spot the malware.\n\nplease provide the source files if you want to make pr to add your own hash data.","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcvar1984%2Fsussyfinder","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcvar1984%2Fsussyfinder","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcvar1984%2Fsussyfinder/lists"}