PHP Malware Analysis

rsHosts

md5: e8d12227d8c119632ee1ffb1927f344b

Jump to:

Screenshot


Attributes


Deobfuscated PHP code

[Linux:vars]
ansible_user=chkusr
ansible_ssh_pass=sha1XlBg
ansible_become=true
ansible_become_method=su
ansible_become_user=dsroot
ansible_become_pass=rsa3XlBg
[Linux]
rs ansible_ssh_port= ansible_ssh_host=rs.vanrui.com
rs5000 ansible_ssh_port=5000 ansible_ssh_host=rs.vanrui.com
rs5002 ansible_ssh_port=5002 ansible_ssh_host=rs.vanrui.com
rs5004 ansible_ssh_port=5004 ansible_ssh_host=rs.vanrui.com
rs5005 ansible_ssh_port=5005 ansible_ssh_host=rs.vanrui.com
rs5006 ansible_ssh_port=5006 ansible_ssh_host=rs.vanrui.com
rs5009 ansible_ssh_port=5009 ansible_ssh_host=rs.vanrui.com
rs5010 ansible_ssh_port=5010 ansible_ssh_host=rs.vanrui.com
rs5011 ansible_ssh_port=5011 ansible_ssh_host=rs.vanrui.com
rs6001 ansible_ssh_port=6001 ansible_ssh_host=rs.vanrui.com
rs6002 ansible_ssh_port=6002 ansible_ssh_host=rs.vanrui.com
rs6003 ansible_ssh_port=6003 ansible_ssh_host=rs.vanrui.com
rs6004 ansible_ssh_port=6004 ansible_ssh_host=rs.vanrui.com
rs6006 ansible_ssh_port=6006 ansible_ssh_host=rs.vanrui.com
rs6008 ansible_ssh_port=6008 ansible_ssh_host=rs.vanrui.com
rs6016 ansible_ssh_port=6016 ansible_ssh_host=rs.vanrui.com
rs6017 ansible_ssh_port=6017 ansible_ssh_host=rs.vanrui.com
rs6018 ansible_ssh_port=6018 ansible_ssh_host=rs.vanrui.com
rs6019 ansible_ssh_port=6019 ansible_ssh_host=rs.vanrui.com
rs6020 ansible_ssh_port=6020 ansible_ssh_host=rs.vanrui.com
rs6021 ansible_ssh_port=6021 ansible_ssh_host=rs.vanrui.com
rs6023 ansible_ssh_port=6023 ansible_ssh_host=rs.vanrui.com
rs6024 ansible_ssh_port=6024 ansible_ssh_host=rs.vanrui.com
rs6026 ansible_ssh_port=6026 ansible_ssh_host=rs.vanrui.com
rs6027 ansible_ssh_port=6027 ansible_ssh_host=rs.vanrui.com
rs6029 ansible_ssh_port=6029 ansible_ssh_host=rs.vanrui.com
rs6030 ansible_ssh_port=6030 ansible_ssh_host=rs.vanrui.com
rs6031 ansible_ssh_port=6031 ansible_ssh_host=rs.vanrui.com
rs6033 ansible_ssh_port=6033 ansible_ssh_host=rs.vanrui.com
rs6035 ansible_ssh_port=6035 ansible_ssh_host=rs.vanrui.com
rs6037 ansible_ssh_port=6037 ansible_ssh_host=rs.vanrui.com
rs6038 ansible_ssh_port=6038 ansible_ssh_host=rs.vanrui.com
rs6039 ansible_ssh_port=6039 ansible_ssh_host=rs.vanrui.com
rs6040 ansible_ssh_port=6040 ansible_ssh_host=rs.vanrui.com
rs7004 ansible_ssh_port=7004 ansible_ssh_host=rs.vanrui.com
rs7020 ansible_ssh_port=7020 ansible_ssh_host=rs.vanrui.com
rs7023 ansible_ssh_port=7023 ansible_ssh_host=rs.vanrui.com
rs8003 ansible_ssh_port=8003 ansible_ssh_host=rs.vanrui.com
rs8071 ansible_ssh_port=8071 ansible_ssh_host=rs.vanrui.com

Execution traces


Generated HTML code

<html><head><meta name="color-scheme" content="light dark"></head><body><pre style="word-wrap: break-word; white-space: pre-wrap;">[Linux:vars]
ansible_user=chkusr
ansible_ssh_pass=sha1XlBg
ansible_become=true
ansible_become_method=su
ansible_become_user=dsroot
ansible_become_pass=rsa3XlBg
[Linux]
rs ansible_ssh_port= ansible_ssh_host=rs.vanrui.com
rs5000 ansible_ssh_port=5000 ansible_ssh_host=rs.vanrui.com
rs5002 ansible_ssh_port=5002 ansible_ssh_host=rs.vanrui.com
rs5004 ansible_ssh_port=5004 ansible_ssh_host=rs.vanrui.com
rs5005 ansible_ssh_port=5005 ansible_ssh_host=rs.vanrui.com
rs5006 ansible_ssh_port=5006 ansible_ssh_host=rs.vanrui.com
rs5009 ansible_ssh_port=5009 ansible_ssh_host=rs.vanrui.com
rs5010 ansible_ssh_port=5010 ansible_ssh_host=rs.vanrui.com
rs5011 ansible_ssh_port=5011 ansible_ssh_host=rs.vanrui.com
rs6001 ansible_ssh_port=6001 ansible_ssh_host=rs.vanrui.com
rs6002 ansible_ssh_port=6002 ansible_ssh_host=rs.vanrui.com
rs6003 ansible_ssh_port=6003 ansible_ssh_host=rs.vanrui.com
rs6004 ansible_ssh_port=6004 ansible_ssh_host=rs.vanrui.com
rs6006 ansible_ssh_port=6006 ansible_ssh_host=rs.vanrui.com
rs6008 ansible_ssh_port=6008 ansible_ssh_host=rs.vanrui.com
rs6016 ansible_ssh_port=6016 ansible_ssh_host=rs.vanrui.com
rs6017 ansible_ssh_port=6017 ansible_ssh_host=rs.vanrui.com
rs6018 ansible_ssh_port=6018 ansible_ssh_host=rs.vanrui.com
rs6019 ansible_ssh_port=6019 ansible_ssh_host=rs.vanrui.com
rs6020 ansible_ssh_port=6020 ansible_ssh_host=rs.vanrui.com
rs6021 ansible_ssh_port=6021 ansible_ssh_host=rs.vanrui.com
rs6023 ansible_ssh_port=6023 ansible_ssh_host=rs.vanrui.com
rs6024 ansible_ssh_port=6024 ansible_ssh_host=rs.vanrui.com
rs6026 ansible_ssh_port=6026 ansible_ssh_host=rs.vanrui.com
rs6027 ansible_ssh_port=6027 ansible_ssh_host=rs.vanrui.com
rs6029 ansible_ssh_port=6029 ansible_ssh_host=rs.vanrui.com
rs6030 ansible_ssh_port=6030 ansible_ssh_host=rs.vanrui.com
rs6031 ansible_ssh_port=6031 ansible_ssh_host=rs.vanrui.com
rs6033 ansible_ssh_port=6033 ansible_ssh_host=rs.vanrui.com
rs6035 ansible_ssh_port=6035 ansible_ssh_host=rs.vanrui.com
rs6037 ansible_ssh_port=6037 ansible_ssh_host=rs.vanrui.com
rs6038 ansible_ssh_port=6038 ansible_ssh_host=rs.vanrui.com
rs6039 ansible_ssh_port=6039 ansible_ssh_host=rs.vanrui.com
rs6040 ansible_ssh_port=6040 ansible_ssh_host=rs.vanrui.com
rs7004 ansible_ssh_port=7004 ansible_ssh_host=rs.vanrui.com
rs7020 ansible_ssh_port=7020 ansible_ssh_host=rs.vanrui.com
rs7023 ansible_ssh_port=7023 ansible_ssh_host=rs.vanrui.com
rs8003 ansible_ssh_port=8003 ansible_ssh_host=rs.vanrui.com
rs8071 ansible_ssh_port=8071 ansible_ssh_host=rs.vanrui.com
</pre></body></html>

Original PHP code

[Linux:vars]
ansible_user=chkusr
ansible_ssh_pass=sha1XlBg
ansible_become=true
ansible_become_method=su
ansible_become_user=dsroot
ansible_become_pass=rsa3XlBg
[Linux]
rs ansible_ssh_port= ansible_ssh_host=rs.vanrui.com
rs5000 ansible_ssh_port=5000 ansible_ssh_host=rs.vanrui.com
rs5002 ansible_ssh_port=5002 ansible_ssh_host=rs.vanrui.com
rs5004 ansible_ssh_port=5004 ansible_ssh_host=rs.vanrui.com
rs5005 ansible_ssh_port=5005 ansible_ssh_host=rs.vanrui.com
rs5006 ansible_ssh_port=5006 ansible_ssh_host=rs.vanrui.com
rs5009 ansible_ssh_port=5009 ansible_ssh_host=rs.vanrui.com
rs5010 ansible_ssh_port=5010 ansible_ssh_host=rs.vanrui.com
rs5011 ansible_ssh_port=5011 ansible_ssh_host=rs.vanrui.com
rs6001 ansible_ssh_port=6001 ansible_ssh_host=rs.vanrui.com
rs6002 ansible_ssh_port=6002 ansible_ssh_host=rs.vanrui.com
rs6003 ansible_ssh_port=6003 ansible_ssh_host=rs.vanrui.com
rs6004 ansible_ssh_port=6004 ansible_ssh_host=rs.vanrui.com
rs6006 ansible_ssh_port=6006 ansible_ssh_host=rs.vanrui.com
rs6008 ansible_ssh_port=6008 ansible_ssh_host=rs.vanrui.com
rs6016 ansible_ssh_port=6016 ansible_ssh_host=rs.vanrui.com
rs6017 ansible_ssh_port=6017 ansible_ssh_host=rs.vanrui.com
rs6018 ansible_ssh_port=6018 ansible_ssh_host=rs.vanrui.com
rs6019 ansible_ssh_port=6019 ansible_ssh_host=rs.vanrui.com
rs6020 ansible_ssh_port=6020 ansible_ssh_host=rs.vanrui.com
rs6021 ansible_ssh_port=6021 ansible_ssh_host=rs.vanrui.com
rs6023 ansible_ssh_port=6023 ansible_ssh_host=rs.vanrui.com
rs6024 ansible_ssh_port=6024 ansible_ssh_host=rs.vanrui.com
rs6026 ansible_ssh_port=6026 ansible_ssh_host=rs.vanrui.com
rs6027 ansible_ssh_port=6027 ansible_ssh_host=rs.vanrui.com
rs6029 ansible_ssh_port=6029 ansible_ssh_host=rs.vanrui.com
rs6030 ansible_ssh_port=6030 ansible_ssh_host=rs.vanrui.com
rs6031 ansible_ssh_port=6031 ansible_ssh_host=rs.vanrui.com
rs6033 ansible_ssh_port=6033 ansible_ssh_host=rs.vanrui.com
rs6035 ansible_ssh_port=6035 ansible_ssh_host=rs.vanrui.com
rs6037 ansible_ssh_port=6037 ansible_ssh_host=rs.vanrui.com
rs6038 ansible_ssh_port=6038 ansible_ssh_host=rs.vanrui.com
rs6039 ansible_ssh_port=6039 ansible_ssh_host=rs.vanrui.com
rs6040 ansible_ssh_port=6040 ansible_ssh_host=rs.vanrui.com
rs7004 ansible_ssh_port=7004 ansible_ssh_host=rs.vanrui.com
rs7020 ansible_ssh_port=7020 ansible_ssh_host=rs.vanrui.com
rs7023 ansible_ssh_port=7023 ansible_ssh_host=rs.vanrui.com
rs8003 ansible_ssh_port=8003 ansible_ssh_host=rs.vanrui.com
rs8071 ansible_ssh_port=8071 ansible_ssh_host=rs.vanrui.com