PHP Malware Analysis

clear.php

md5: cffa2a8fa87074e8bca4d64372f40d39

Jump to:

Screenshot


Attributes


Deobfuscated PHP code

<?php

unlink('web.php');
unlink('clear.php');

Execution traces

data/traces/cffa2a8fa87074e8bca4d64372f40d39_trace-1676256342.732.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-13 00:46:08.629857]
1	0	1	0.000130	393512
1	3	0	0.000172	393576	{main}	1		/var/www/html/uploads/clear.php	0	0
2	4	0	0.000189	393576	unlink	0		/var/www/html/uploads/clear.php	2	1	'web.php'
2	4	1	0.000228	393728
2	4	R			FALSE
2	5	0	0.000243	393688	unlink	0		/var/www/html/uploads/clear.php	3	1	'clear.php'
2	5	1	0.000279	393728
2	5	R			TRUE
1	3	1	0.000293	393688
			0.000316	314224
TRACE END   [2023-02-13 00:46:08.630069]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<?php
unlink('web.php');
unlink('clear.php');
?>