Open-source atomic malware analysis

Analyze another

2022-08-26 07

PHP
Verdict: HOSTILE
Mal-ecule
O(C)H(Cm)Md(Pa)Th
Size 34 B download
First seen 117 days ago
Analyzed 117 days ago
Ecosystem webshell

Objectives

suspicious severity, 98% confident.
command-and-control/backdoor User input used as function (GET/POST/REQUEST)

Micro-behaviors

notable severity, 85% confident.
communications/http/request HTTP GET parameter access ($_GET)

Metadata

baseline severity, 82% confident.
file Sparse string pool in PHP
component severity, 80% confident.
package Very short file (under 12 lines)

Third-party

hostile severity, 90% confident.
SigBase/WEBSHELL/PHP PHP webshell using function name from variable, e.g. $a='ev'.'al'; $a($code)
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Function/Via Webshell which sends eval/assert via GET

Identity

SHA-256 3f5d83cb2231c81ca96ff05d316f163fb67d1d407906e9e51cd424601a6bab3a
Filename 2022-08-26-07.php
Package 2022-08-26
Version 07

Origin

Source harvest
Feed datasets
Ecosystem webshell

Timeline

First seen 24 Apr 2026 16:15 UTC
Last analyzed 24 Apr 2026 20:18 UTC
Last updated 24 Apr 2026 20:18 UTC

Labeling

Label bad
Label source harvest
Traits version 8bf61