PHP Malware Analysis

msh.php

md5: b164a20aa6d67d2782215426c12c1c4b

Jump to:

Screenshot


Attributes

Execution


Deobfuscated PHP code

<?php

$cmd = "ls";
shell_exec($cmd);
?>



Execution traces

data/traces/b164a20aa6d67d2782215426c12c1c4b_trace-1676240787.9583.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 20:26:53.856132]
1	0	1	0.000222	393512
1	3	0	0.000272	393496	{main}	1		/var/www/html/uploads/msh.php	0	0
1		A						/var/www/html/uploads/msh.php	2	$cmd = 'ls'
2	4	0	0.000306	393496	shell_exec	0		/var/www/html/uploads/msh.php	3	1	'ls'
2	4	1	0.001916	393584
2	4	R			'data\nmsh.php\nprepend.php\n'
1	3	1	0.001949	393496
			0.001983	314288
TRACE END   [2023-02-12 20:26:53.857935]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<?php
$cmd = "ls";
shell_exec($cmd);

?>