Open-source atomic malware analysis

Analyze another

asw.php

PHP
Verdict: HOSTILE
Mal-ecule
KO₁₀(As₅C₈CaEr₃I₄Xe₂CoDy₂LaS₃)H₅(Cm₁₀Db₃F₉Os₃Po₅)Md(Pa₂)Th
Size 128.8 KB download
First seen 117 days ago
Analyzed 116 days ago
Ecosystem webshell

Objectives

suspicious severity, 93% confident.
anti-static/obfuscation/encoding chr(hexdec(...)) custom hex decoder (obfuscation)
suspicious severity, 92% confident.
command-and-control/channel/tunnel GOST proxy tunneling tool
suspicious severity, 85% confident.
credential-access/phishing PHP script writing POST data to local file
suspicious severity, 100% confident.
evasion/self-delete Recursive directory deletion in PHP (self-delete)
suspicious severity, 90% confident.
execution/interpreter/eval Error-suppressed eval (@eval)
suspicious severity, 92% confident.
impact/infect Detects delete-and-recreate file pattern
notable severity, 90% confident.
anti-static/obfuscation Single very long line (webshell
notable severity, 100% confident.
evasion Checks if exec functions exist

Micro-behaviors

suspicious severity, 93% confident.
communications/email MIME email with executable attachment
suspicious severity, 90% confident.
communications/http SSL certificate verification disabled (security
notable severity, 93% confident.
data/db/conn PHP MySQLi administration surface
notable severity, 100% confident.
fs/delete PHP rmdir function symbol
notable severity, 100% confident.
fs/enumerate PHP scandir function symbol
notable severity, 95% confident.
os Disables error reporting (error_reporting(0))
notable severity, 100% confident.
process/create PHP mail() function call
notable severity, 95% confident.
process/create/shell Shell command execution via exec()

Third-party

hostile severity, 90% confident.
SigBase/EXT/WEBSHELL/PHP php webshell having some kind of input and some kind of payload. restricted to small files or big ones including suspicious strings
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Dynamic PHP webshell using $a($code) for kind of eval with encoded blob to decode, e.g. b374k
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Generic php webshell having some kind of input and using a callback to execute the payload. restricted to small files or would give lots of false positives
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/OBFUSC/Encoded/Mixed/Dec/And PHP webshell obfuscated by encoding of mixed hex and dec

20 of 57 traits shown

Identity

SHA-256 88f4bed46b4e8ba8237edb2374a1bef7a252a01a54836ead82b5c7e989c12411
Filename asw.php

Origin

Source harvest
Feed datasets
Ecosystem webshell

Timeline

First seen 24 Apr 2026 16:15 UTC
Last analyzed 26 Apr 2026 04:56 UTC
Last updated 26 Apr 2026 04:56 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d