Open-source atomic malware analysis

Analyze another

2022-08-26 06

PHP
Verdict: HOSTILE
Mal-ecule
O(C)H₂(CmDb)Md(Pa)Th
Size 69 B download
First seen 117 days ago
Analyzed 115 days ago
Ecosystem webshell

Objectives

suspicious severity, 98% confident.
command-and-control/backdoor User input used as function (GET/POST/REQUEST)

Micro-behaviors

notable severity, 85% confident.
communications/http/request HTTP GET parameter access ($_GET)

Metadata

component severity, 80% confident.
package Very short file (under 12 lines)

Third-party

hostile severity, 90% confident.
SigBase/WEBSHELL/PHP PHP webshell using function name from variable, e.g. $a='ev'.'al'; $a($code)
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Function/Via Webshell which sends eval/assert via GET

Identity

SHA-256 53b06c5e45b4972c539466dbbc71ef635cf3989c3fd39c84e54316db02cfbce9
Filename 2022-08-26-06.php
Package 2022-08-26
Version 06

Origin

Source harvest
Feed datasets
Ecosystem webshell

Timeline

First seen 24 Apr 2026 16:15 UTC
Last analyzed 26 Apr 2026 23:31 UTC
Last updated 26 Apr 2026 23:31 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d