Open-source atomic malware analysis

Analyze another

yaps.php

PHP
Verdict: HOSTILE
Mal-ecule
KO₉(CaEr₃Xe₂As₃C₈Eu₂P₃ILa)H₅(Cm₃Db₂F₄Os₅Po₄)Md₂(Pa)Th
Size 34.2 KB download
First seen 117 days ago
Analyzed 116 days ago
Ecosystem webshell

Objectives

suspicious severity, 85% confident.
credential-access/phishing PHP script writing POST data to local file
suspicious severity, 85% confident.
evasion Target /etc/crontab system crontab
suspicious severity, 95% confident.
execution/interpreter/eval eval of file_get_contents result
notable severity, 85% confident.
command-and-control/backdoor/webshell Ignores client abort (webshell indicator)
notable severity, 80% confident.
evasion/masquerade base64-encode HTTP POST request body
notable severity, 80% confident.
exfiltration curl -X POST flag

Micro-behaviors

notable severity, 85% confident.
communications/http/request HTTP REQUEST parameter access ($_REQUEST)
notable severity, 90% confident.
communications/socket nc command invocation
notable severity, 100% confident.
data/encode Long continuous hexadecimal string (>64 chars)
notable severity, 85% confident.
fs/write Move uploaded file to destination
notable severity, 95% confident.
os Disables error reporting (error_reporting(0))
notable severity, 90% confident.
os/network ifconfig command
notable severity, 90% confident.
os/privilege /etc/shadow password file access
notable severity, 95% confident.
process/create/shell Shell command execution via exec()

Metadata

notable severity, 90% confident.
encoded-payload Encoded payload detected: base64

Third-party

hostile severity, 90% confident.
SigBase/EXT/WEBSHELL/PHP php webshell having some kind of input and some kind of payload. restricted to small files or big ones including suspicious strings
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP PHP webshell which directly eval()s obfuscated string
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Base64/Encoded php webshell containing base64 encoded payload
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Dynamic PHP webshell using $a($code) for kind of eval with encoded blob to decode, e.g. b374k
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Generic php webshell having some kind of input and using a callback to execute the payload. restricted to small files or would give lots of false positives

20 of 47 traits shown

Identity

SHA-256 2fb7e5a2706d99e11b402fdc3970c4ad4e7b863e0f970471c3b3242973d5fc8b
Filename yaps.php

Origin

Source harvest
Feed datasets
Ecosystem webshell

Timeline

First seen 24 Apr 2026 16:15 UTC
Last analyzed 25 Apr 2026 22:48 UTC
Last updated 25 Apr 2026 22:48 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d