PHP Malware Analysis

1.php, t.txt, test.htm, test2.php

md5: 098f6bcd4621d373cade4e832627b4f6

Jump to:

Screenshot


Attributes


Deobfuscated PHP code

test

Execution traces

data/traces/098f6bcd4621d373cade4e832627b4f6_trace-1676250078.4545.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 23:01:44.352344]
1	0	1	0.000179	393464
1	3	0	0.000229	393016	{main}	1		/var/www/html/uploads/1.php	0	0
1	3	1	0.000249	393016
			0.000280	314200
TRACE END   [2023-02-12 23:01:44.352481]

data/traces/098f6bcd4621d373cade4e832627b4f6_trace-1676256992.3239.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-13 00:56:58.221739]
1	0	1	0.000156	393512
1	3	0	0.000196	393064	{main}	1		/var/www/html/uploads/test2.php	0	0
1	3	1	0.000213	393064
			0.000239	314224
TRACE END   [2023-02-13 00:56:58.221852]


Generated HTML code

<html><head></head><body>test</body></html>

Original PHP code

test