Open-source atomic malware analysis

Analyze another

cli_code.txt

PHP
Verdict: HOSTILE
Mal-ecule
O₇(C₄Er₃IXeAs₅DyP)H₅(Po₄Cm₃F₅OsDb)Md₃(Pa)Th
Size 67.8 KB download
First seen 117 days ago
Analyzed 115 days ago
Ecosystem malcontent-samples

Objectives

hostile severity, 95% confident.
command-and-control/backdoor PHP RAT with process masquerading
suspicious severity, 100% confident.
evasion/self-delete Recursive directory deletion in PHP (self-delete)
suspicious severity, 90% confident.
execution/interpreter/eval Error-suppressed eval (@eval)
suspicious severity, 92% confident.
impact/infect Detects delete-and-recreate file pattern
notable severity, 90% confident.
anti-static/obfuscation Single very long line (webshell
notable severity, 70% confident.
discovery/system Accesses PHP_OS constant (OS detection)
notable severity, 100% confident.
evasion Checks if exec functions exist

Micro-behaviors

suspicious severity, 90% confident.
process/control PHP daemonization pattern
notable severity, 80% confident.
communications/http HTTP request via file_get_contents
notable severity, 100% confident.
fs/delete PHP rmdir function symbol
notable severity, 100% confident.
fs/enumerate PHP scandir function symbol
notable severity, 80% confident.
fs/write File write via fwrite
notable severity, 95% confident.
os Disables error reporting (error_reporting(0))
notable severity, 95% confident.
process/create/shell Shell command execution via passthru()
notable severity, 75% confident.
process/interpreter PHP eval() token present

Metadata

suspicious severity, 100% confident.
file-extension-mismatch File extension claims Text but content is Php
notable severity, 90% confident.
encoded-payload Encoded payload detected: base64

Third-party

hostile severity, 90% confident.
SigBase/WEBSHELL/PHP PHP webshell which directly eval()s obfuscated string
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Base64/Encoded php webshell containing base64 encoded payload
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Dynamic PHP webshell using $a($code) for kind of eval with encoded blob to decode, e.g. b374k

20 of 31 traits shown

Identity

SHA-256 60c71dc626fbf248b85f9cacbd3768fa6e163017621bac31acc49ca1dd2cd436
Filename cli_code.txt

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 26 Apr 2026 13:01 UTC
Last updated 26 Apr 2026 13:01 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d