Open-source atomic malware analysis

Analyze another

20220213_05.php

PHP
Verdict: HOSTILE
Mal-ecule
O₃(XeAs₂C)H(Po)Md(Pa)Th
Size 99.7 KB download
First seen 118 days ago
Analyzed 117 days ago
Ecosystem webshell

Objectives

suspicious severity, 90% confident.
execution/interpreter/eval Error-suppressed eval (@eval)
notable severity, 90% confident.
anti-static/obfuscation Single very long line (webshell
baseline severity, 90% confident.
anti-static/obfuscation/code-metrics Minified/compressed code (multiple indicators)
component severity, 70% confident.
command-and-control/backdoor Error suppression operator usage (@)

Micro-behaviors

notable severity, 75% confident.
process/interpreter PHP eval() token present

Metadata

component severity, 80% confident.
package Very short file (under 12 lines)

Third-party

hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Dynamic PHP webshell using $a($code) for kind of eval with encoded blob to decode, e.g. b374k
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Encoded PHP webshell using some kind of eval with encoded blob to decode, which is checked with YARAs math.entropy module

Identity

SHA-256 cf94677ad1107a2551285ccde8795445034dfa2f8ca316574fd1b9cb028f4faa
Filename 20220213_05.php

Origin

Source harvest
Feed datasets
Ecosystem webshell

Timeline

First seen 24 Apr 2026 16:15 UTC
Last analyzed 26 Apr 2026 04:19 UTC
Last updated 26 Apr 2026 04:19 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d