PHP fsockopen() Reverse Shell on Compromised Roundcube Host

Detects PHP process execution invoking fsockopen() to establish an outbound reverse shell connection, consistent with SpyPress backdoor persistence mechanisms deployed by TA458 on compromised Roundcube webmail servers.