Found something on a server?
If you have pulled a suspicious PHP file off a host — a webshell, an injected loader, an uploader that should not be there — send it to us.
The ones that get through are the ones worth having. The panel’s malware scanner is only as good as what it has been shown, and a sample that a scanner missed teaches it more than a hundred that everything already catches. If you know it slipped past something, say which.
You do not need to be a customer, and there is nothing to sign up for.
What happens to it
The sample is stored on our server as a text file, outside anything the web
serves, readable only by root, and run against the scanner’s rules. It is never
executed, and it is never given a .php name.
We do not want the site it came from, the customer’s name, or anything else identifying — please strip that out before sending. If you leave an email address we may write back about what it turned out to be; if you do not, that is fine and the sample is just as useful.
Paste it as text. There is no file upload, deliberately: it is one fewer way for this form to be something other than a text box.
Wanted to send a feature request instead? That form is here.