What this solution does
Antivirus: Virus and Trojan Search is a professional module for enhancing website security on the 1C-Bitrix platform. The tool is designed to detect malicious code, web shells, trojans, hidden backdoors, suspicious file modifications, and other signs of site compromise. The solution extends the platform's built-in protection mechanisms by providing advanced capabilities for file system analysis, 1C-Bitrix object inspection, and site integrity control.
The module performs comprehensive file scanning for malicious code. It supports analysis of PHP, JavaScript, HTML, .htaccess, and other file types. The system searches for web shells, trojans, backdoors, and malicious loaders. It identifies suspicious constructs, obfuscation methods, and hidden code execution. Analysis of high-entropy (encoded) payloads is performed. Suspicious external URLs, iframes, script injections, and remote code loaders are detected. Files are verified against a database of known malicious SHA-256 hashes. Heuristic detection of web shells based on characteristic behavioral patterns is implemented.
The module supports connecting custom signature files and user databases. It performs static analysis of PHP code using PHPAST without executing scripts. Taint analysis is implemented to track chains of user data transmission to potentially dangerous functions. It detects dangerous calls such as eval, assert, system, shell_exec, include, require, and others. The module analyzes dynamic function calls and loaders. Specialized checks for 1C-Bitrix platforms are included: analysis of Bitrix agents, verification of registered event handlers, analysis of website template connection conditions, verification of database SQL triggers, and rules for detecting suspicious changes in 1C-Bitrix projects. The integrity control function allows creating a baseline snapshot of the file system, identifying new, modified, and deleted files, and monitoring changes in critical directories. Integrity of the 1C-Bitrix core and standard modules is checked separately via checksums when update system data is available. Scanning is available step-by-step through the administrative panel without risking execution time limits. Running checks from the command line (CLI) is also supported for automation and scheduling.
The module provides detailed analysis of file objects with the generation of reports containing threat categories, risk level assessment, and recommendations for further actions. Scan results are tagged for easy filtering and can be exported in JSON format. Suspicious files are handled securely through quarantine isolation, restoration from quarantine, and protection against accidental deletion. A Dry Run mode is implemented to analyze the system without making changes to the file structure. The functionality includes management of file and rule whitelists, as well as a Finding Suppressor tool to hide individual false positives.
The solution is designed for administrators of 1C-Bitrix websites, web studios, technical support companies, system administrators, information security specialists, and owners of online stores and corporate portals.
The module is built on a modern modular architecture that ensures scalability and full integration with the 1C-Bitrix administrative panel. It employs multiple independent analysis methods supplemented by specialized checks tailored to the platform's specifics. The system performs integrity control of the file system and the CMS core.
The module supports automation via CLI and scheduled execution. It generates detailed reports with information about each detection. Suspicious files are safely isolated in quarantine. Scan profiles and sensitivity levels can be configured flexibly. The system supports custom signatures and user-defined databases. Files are not modified automatically without administrator confirmation, ensuring full control over all operations.
During scanning, the module analyzes the website file system, 1C-Bitrix platform objects, and project configuration to identify common signs of compromise. It detects PHP viruses and trojans, web shells, backdoors and hidden access points, malicious loaders, hidden scripts, obfuscated and encrypted code, and suspicious constructs typical of malware.
Special attention is paid to dangerous PHP functions and constructs, including the use of eval(), assert(), create_function(), calls to system(), exec(), shell_exec(), passthru(), proc_open(), dynamic function calls, unsafe include and require statements, and attempts to write or modify files via PHP.
The module performs comprehensive security analysis by detecting suspicious data flow chains from user inputs to dangerous functions using Taint Analysis. It identifies obfuscated and hidden code, including Base64, Gzip/Gzinflate, Hex, and ROT13 encoding, as well as high-entropy strings typical of malicious payloads. The system analyzes multi-stage code hiding methods and suspicious external calls, such as URLs in PHP, JavaScript, and HTML, remote script inclusion, suspicious iframes, remote code loaders, and redirects in .htaccess files. It also checks for matches against databases of known malicious domains.
Threat database verification includes file validation against a database of known malware SHA-256 hashes, detection of known web shell families based on specific signatures, and support for custom signature databases. The module provides specialized checking for 1C-Bitrix platform objects, including Bitrix Agents, Event Handlers, template connection conditions, and database SQL triggers, while also identifying suspicious changes in platform system objects.
Integrity control features enable the detection of new, modified, and deleted files, along with monitoring changes in critical site directories.
The module verifies the integrity of the 1C-Bitrix core and standard modules when checksums are available. It analyzes site configuration, including .htaccess files and the detection of dangerous request processing rules. Executable files in the /upload directory are checked, and system directories along with service files are analyzed. Detected threats are categorized by risk level, and each event is tagged. The system identifies potential false positives and generates detailed reports specifying detection reasons and recommended next steps.
General iT can connect “Antivirus: Virus and Trojan Detection”, configure it and verify the integration with the existing website.