PHP Malware Analysis

Hats.html

md5: c7e2cc135da117f290ac4899e2998d42

Jump to:

Screenshot

No Image

Attributes

URLs


Deobfuscated PHP code

<html>
<DOCTYPE html>
<html xmlns="http://www.w3.org/1999/xhtml">
<meta name="viewport" content="width=device-width, initial-scale=1" /> 
<head>
	<title>Hacked By Hats7</title>
<meta property="og:description" content="Hii Bang "/>	
<meta property="og:image" content="https://k.top4top.io/p_2002m9i7y0.jpg"/>
<link rel="shortcut icon" href="../g.top4top.io/p_1952hya001.png"/>
<link href="https://fonts.googleapis.com/css?family=&display=swap" type="text/css" rel="stylesheet">
<link href="https://fonts.googleapis.com/css?family=Audiowide&display=swap" type="text/css" rel="stylesheet">
</head>
<body oncontextmenu="return false" onkeydown="return false" onmousedown="return false">
<script type="text/javascript">
var snowmax=35
var snowcolor=new Array("#AAAACC","#DDDDFF","#CCCCDD","#F3F3F3","#F0FFFF")
var snowtype=new Array("Arial Black","Arial Narrow","Times","Comic Sans MS")
var snowletter="*"
var sinkspeed=0.6
var snowmaxsize=22
var snowminsize=8
var snowingzone=1
// Do not edit below this line
var snow=new Array()
var marginbottom
var marginright
var timer
var i_snow=0
var x_mv=new Array();
var crds=new Array();
var lftrght=new Array();
var browserinfos=navigator.userAgent 
var ie5=document.all&&document.getElementById&&!browserinfos.match(/Opera/)
var ns6=document.getElementById&&!cument.all
var opera=browserinfos.match(/Opera/)  
var browserok=ie5||ns6||opera
function randommaker(range) {		
	rand=Math.floor(range*Math.random())
    return rand
}
function initsnow() {
	if (ie5 || opera) {
		marginbottom = document.body.clientHeight
		marginright = document.body.clientWidth
	}
	else if (ns6) {
		marginbottom = window.innerHeight
		marginright = window.innerWidth
	}
	var snowsizerange=snowmaxsize-snowminsize
	for (i=0;i<=snowmax;i  ) {
		crds[i] = 0;                      
    	lftrght[i] = Math.random()*15;         
    	x_mv[i] = 0.03   Math.random()/10;
		snow[i]=document.getElementById("s" i)
		snow[i].style.fontFamily=snowtype[randommaker(snowtype.length)]
		snow[i].size=randommaker(snowsizerange) snowminsize
		snow[i].style.fontSize=snow[i].size
		snow[i].style.color=snowcolor[randommaker(snowcolor.length)]
		snow[i].sink=sinkspeed*snow[i].size/5
		if (snowingzone==1) {snow[i].posx=randommaker(marginright-snow[i].size)}
		if (snowingzone==2) {snow[i].posx=randommaker(marginright/2-snow[i].size)}
		if (snowingzone==3) {snow[i].posx=randommaker(marginright/2-snow[i].size) marginright/4}
		if (snowingzone==4) {snow[i].posx=randommaker(marginright/2-snow[i].size) marginright/2}
		snow[i].posy=randommaker(2*marginbottom-marginbottom-2*snow[i].size)
		snow[i].style.left=snow[i].posx
		snow[i].style.top=snow[i].posy
	}
	movesnow()
}
function movesnow() {
	for (i=0;i<=snowmax;i  ) {
		crds[i]  = x_mv[i];
		snow[i].posy =snow[i].sink
		snow[i].style.left=snow[i].posx lftrght[i]*Math.sin(crds[i]);
		snow[i].style.top=snow[i].posy
		if (snow[i].posy>=marginbottom-2*snow[i].size || parseInt(snow[i].style.left)>(marginright-3*lftrght[i])){
			if (snowingzone==1) {snow[i].posx=randommaker(marginright-snow[i].size)}
			if (snowingzone==2) {snow[i].posx=randommaker(marginright/2-snow[i].size)}
			if (snowingzone==3) {snow[i].posx=randommaker(marginright/2-snow[i].size) marginright/4}
			if (snowingzone==4) {snow[i].posx=randommaker(marginright/2-snow[i].size) marginright/2}
			snow[i].posy=0
		}
	}
	var timer=setTimeout("movesnow()",50)
}
for (i=0;i<=snowmax;i  ) {
	document.write("<span id='s" i "' style='position:absolute;top:-" snowmaxsize "'>" snowletter "</span>")
}
if (browserok) {
	window.onload=initsnow
}
</script>
<head>
    <title>Hacked By Tn.Fidin404</title>
<style type="text/css">.lagu{background:transparent;border:1px solid red;font-family:Share\ Tech\ Mono;color:;font-size:10px;font-weight:normal;padding:2px 25px;text-decoration:none;text-shadow:0 0 0px #15cff4}</style>
<script>
    function play(){var audio=document.getElementById('lagu');audio.play();}function liat(){document.getElementById('galiat').style.visibility='visible';}</script>
<script src="../cdn.rawgit.com/bungfrangki/efeksalju/2a7805c7/efek-salju.js" type="text/javascript">
</script>
<style>img[alt="www.000webhost.com"]{display:none;}</style>
</style>
<style type='text/css'>
HTML,BODY{cursor: none;}
</style>
<body BGCOLOR="black">
<center>
<body background="index.html" height="" width="">
<center>
<style>
    h1 {
    text-align: center;
    color: #3335cf;
    font-size: 35px;
    font-family: Arial Narrow, sans-serif;
    font-style: garamond;
    text-shadow: 100vmax #f00505;>
    text-shadow: 0px 0px 0px #f00505;>
    </style>
    <center>
<br>
<script>alert("Welcome Admin.\n");</script>
<script>alert("Hecked By MR.N4N0");</script>
<script>alert("NOT FOUND 404");</script>
<br>
	<img src="https://c.top4top.io/p_24472jw6p0.jpeg" width="200" height="100"> 

<center>
<h3> <font color=white size=4 face="courier New">Mr.N4N0</font>

<center>
<h3> <font color=red size=4 face="courier New">Hallo Admin </font>
<br>
<font color="white" size="2" face="courier New">:v<br></br>WEBSITE DOWN</font>
<br>
<button class="lagu" onclick="play();liat();"><font face="courier new" size="2" color="white">CLICK TO PLAY MUSIC</font></button><audio id="lagu" src=" https://a.top4top.io/m_244708li90.mp3"></audio>
<br>
<br>
<b><font face="courier New" color="red" size="3">thank you friend</font></b><br>
<font color="red" face="courier new">Mr.T1T4N-Mr.DENVAS-Mr.M1KU <font color="red"><a href='https://banjarnegara-xploit.blogspot.com/'><b>
</font></center>
<br>
</body>
</htm>

Execution traces


Generated HTML code


Original PHP code

<html>
<DOCTYPE html>
<html xmlns="http://www.w3.org/1999/xhtml">
<meta name="viewport" content="width=device-width, initial-scale=1" /> 
<head>
	<title>Hacked By Hats7</title>
<meta property="og:description" content="Hii Bang "/>	
<meta property="og:image" content="https://k.top4top.io/p_2002m9i7y0.jpg"/>
<link rel="shortcut icon" href="../g.top4top.io/p_1952hya001.png"/>
<link href="https://fonts.googleapis.com/css?family=&display=swap" type="text/css" rel="stylesheet">
<link href="https://fonts.googleapis.com/css?family=Audiowide&display=swap" type="text/css" rel="stylesheet">
</head>
<body oncontextmenu="return false" onkeydown="return false" onmousedown="return false">
<script type="text/javascript">
var snowmax=35
var snowcolor=new Array("#AAAACC","#DDDDFF","#CCCCDD","#F3F3F3","#F0FFFF")
var snowtype=new Array("Arial Black","Arial Narrow","Times","Comic Sans MS")
var snowletter="*"
var sinkspeed=0.6
var snowmaxsize=22
var snowminsize=8
var snowingzone=1
// Do not edit below this line
var snow=new Array()
var marginbottom
var marginright
var timer
var i_snow=0
var x_mv=new Array();
var crds=new Array();
var lftrght=new Array();
var browserinfos=navigator.userAgent 
var ie5=document.all&&document.getElementById&&!browserinfos.match(/Opera/)
var ns6=document.getElementById&&!cument.all
var opera=browserinfos.match(/Opera/)  
var browserok=ie5||ns6||opera
function randommaker(range) {		
	rand=Math.floor(range*Math.random())
    return rand
}
function initsnow() {
	if (ie5 || opera) {
		marginbottom = document.body.clientHeight
		marginright = document.body.clientWidth
	}
	else if (ns6) {
		marginbottom = window.innerHeight
		marginright = window.innerWidth
	}
	var snowsizerange=snowmaxsize-snowminsize
	for (i=0;i<=snowmax;i  ) {
		crds[i] = 0;                      
    	lftrght[i] = Math.random()*15;         
    	x_mv[i] = 0.03   Math.random()/10;
		snow[i]=document.getElementById("s" i)
		snow[i].style.fontFamily=snowtype[randommaker(snowtype.length)]
		snow[i].size=randommaker(snowsizerange) snowminsize
		snow[i].style.fontSize=snow[i].size
		snow[i].style.color=snowcolor[randommaker(snowcolor.length)]
		snow[i].sink=sinkspeed*snow[i].size/5
		if (snowingzone==1) {snow[i].posx=randommaker(marginright-snow[i].size)}
		if (snowingzone==2) {snow[i].posx=randommaker(marginright/2-snow[i].size)}
		if (snowingzone==3) {snow[i].posx=randommaker(marginright/2-snow[i].size) marginright/4}
		if (snowingzone==4) {snow[i].posx=randommaker(marginright/2-snow[i].size) marginright/2}
		snow[i].posy=randommaker(2*marginbottom-marginbottom-2*snow[i].size)
		snow[i].style.left=snow[i].posx
		snow[i].style.top=snow[i].posy
	}
	movesnow()
}
function movesnow() {
	for (i=0;i<=snowmax;i  ) {
		crds[i]  = x_mv[i];
		snow[i].posy =snow[i].sink
		snow[i].style.left=snow[i].posx lftrght[i]*Math.sin(crds[i]);
		snow[i].style.top=snow[i].posy
		if (snow[i].posy>=marginbottom-2*snow[i].size || parseInt(snow[i].style.left)>(marginright-3*lftrght[i])){
			if (snowingzone==1) {snow[i].posx=randommaker(marginright-snow[i].size)}
			if (snowingzone==2) {snow[i].posx=randommaker(marginright/2-snow[i].size)}
			if (snowingzone==3) {snow[i].posx=randommaker(marginright/2-snow[i].size) marginright/4}
			if (snowingzone==4) {snow[i].posx=randommaker(marginright/2-snow[i].size) marginright/2}
			snow[i].posy=0
		}
	}
	var timer=setTimeout("movesnow()",50)
}
for (i=0;i<=snowmax;i  ) {
	document.write("<span id='s" i "' style='position:absolute;top:-" snowmaxsize "'>" snowletter "</span>")
}
if (browserok) {
	window.onload=initsnow
}
</script>
<head>
    <title>Hacked By Tn.Fidin404</title>
<style type="text/css">.lagu{background:transparent;border:1px solid red;font-family:Share\ Tech\ Mono;color:;font-size:10px;font-weight:normal;padding:2px 25px;text-decoration:none;text-shadow:0 0 0px #15cff4}</style>
<script>
    function play(){var audio=document.getElementById('lagu');audio.play();}function liat(){document.getElementById('galiat').style.visibility='visible';}</script>
<script src="../cdn.rawgit.com/bungfrangki/efeksalju/2a7805c7/efek-salju.js" type="text/javascript">
</script>
<style>img[alt="www.000webhost.com"]{display:none;}</style>
</style>
<style type='text/css'>
HTML,BODY{cursor: none;}
</style>
<body BGCOLOR="black">
<center>
<body background="index.html" height="" width="">
<center>
<style>
    h1 {
    text-align: center;
    color: #3335cf;
    font-size: 35px;
    font-family: Arial Narrow, sans-serif;
    font-style: garamond;
    text-shadow: 100vmax #f00505;>
    text-shadow: 0px 0px 0px #f00505;>
    </style>
    <center>
<br>
<script>alert("Welcome Admin.\n");</script>
<script>alert("Hecked By MR.N4N0");</script>
<script>alert("NOT FOUND 404");</script>
<br>
	<img src="https://c.top4top.io/p_24472jw6p0.jpeg" width="200" height="100"> 

<center>
<h3> <font color=white size=4 face="courier New">Mr.N4N0</font>

<center>
<h3> <font color=red size=4 face="courier New">Hallo Admin </font>
<br>
<font color="white" size="2" face="courier New">:v<br></br>WEBSITE DOWN</font>
<br>
<button class="lagu" onclick="play();liat();"><font face="courier new" size="2" color="white">CLICK TO PLAY MUSIC</font></button><audio id="lagu" src=" https://a.top4top.io/m_244708li90.mp3"></audio>
<br>
<br>
<b><font face="courier New" color="red" size="3">thank you friend</font></b><br>
<font color="red" face="courier new">Mr.T1T4N-Mr.DENVAS-Mr.M1KU <font color="red"><a href='https://banjarnegara-xploit.blogspot.com/'><b>
</font></center>
<br>
</body>
</htm>