PHP Malware Analysis

def.php

md5: f61aba97a2353f781c2b66b6c19b6f86

Jump to:

Screenshot


Attributes


Deobfuscated PHP code

GIF89a;


                                            BELAJAR HACK

                                            HACK BY MR44J

Execution traces

data/traces/f61aba97a2353f781c2b66b6c19b6f86_trace-1676258776.7324.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-13 01:26:42.630246]
1	0	1	0.000142	393512
1	3	0	0.000183	393192	{main}	1		/var/www/html/uploads/def.php	0	0
1	3	1	0.000200	393192
			0.000225	314224
TRACE END   [2023-02-13 01:26:42.630357]


Generated HTML code

<html><head></head><body>GIF89a;


                                            BELAJAR HACK

                                            HACK BY MR44J</body></html>

Original PHP code

GIF89a;


                                            BELAJAR HACK

                                            HACK BY MR44J