PHP Malware Analysis

AcuTest3292.svg

md5: cc775826fa00996937f7d66ea0bdd087

Jump to:

Screenshot


Attributes

URLs


Deobfuscated PHP code

<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink">
<use xlink:href="data:application/xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hsaW5rIj4NCjxkZWZzPg0KPGNpcmNsZSBpZD0idGVzdCIgcj0iNTAiIGN4PSIxMDAiIGN5PSIxMDAiIHN0eWxlPSJmaWxsOiAjRjAwIj4NCjxzZXQgYXR0cmlidXRlTmFtZT0iZmlsbCIgYXR0cmlidXRlVHlwZT0iQ1NTIiBvbmJlZ2luPSdhbGVydCgxKScgb25lbmQ9J2FsZXJ0KDIpJyB0bz0iIzAwRiIgYmVnaW49IjFzIiBkdXI9IjVzIiAvPg0KPC9jaXJjbGU+DQo8L2RlZnM+DQo8dXNlIHhsaW5rOmhyZWY9IiN0ZXN0Ii8+DQo8L3N2Zz4g#test"/>
</svg>   

Execution traces


Generated HTML code

<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink">
<use xlink:href="data:application/xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hsaW5rIj4NCjxkZWZzPg0KPGNpcmNsZSBpZD0idGVzdCIgcj0iNTAiIGN4PSIxMDAiIGN5PSIxMDAiIHN0eWxlPSJmaWxsOiAjRjAwIj4NCjxzZXQgYXR0cmlidXRlTmFtZT0iZmlsbCIgYXR0cmlidXRlVHlwZT0iQ1NTIiBvbmJlZ2luPSdhbGVydCgxKScgb25lbmQ9J2FsZXJ0KDIpJyB0bz0iIzAwRiIgYmVnaW49IjFzIiBkdXI9IjVzIiAvPg0KPC9jaXJjbGU+DQo8L2RlZnM+DQo8dXNlIHhsaW5rOmhyZWY9IiN0ZXN0Ii8+DQo8L3N2Zz4g#test"/>
</svg>

Original PHP code

<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink">
<use xlink:href="data:application/xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hsaW5rIj4NCjxkZWZzPg0KPGNpcmNsZSBpZD0idGVzdCIgcj0iNTAiIGN4PSIxMDAiIGN5PSIxMDAiIHN0eWxlPSJmaWxsOiAjRjAwIj4NCjxzZXQgYXR0cmlidXRlTmFtZT0iZmlsbCIgYXR0cmlidXRlVHlwZT0iQ1NTIiBvbmJlZ2luPSdhbGVydCgxKScgb25lbmQ9J2FsZXJ0KDIpJyB0bz0iIzAwRiIgYmVnaW49IjFzIiBkdXI9IjVzIiAvPg0KPC9jaXJjbGU+DQo8L2RlZnM+DQo8dXNlIHhsaW5rOmhyZWY9IiN0ZXN0Ii8+DQo8L3N2Zz4g#test"/>
</svg>