Open-source atomic malware analysis

Analyze another

20220213_03.php

PHP
Verdict: HOSTILE
Mal-ecule
O₃(As₂CXe)H₄(CmOsPo₂Db)Md(Pa)Th
Size 842 B download
First seen 117 days ago
Analyzed 115 days ago
Ecosystem webshell

Objectives

notable severity, 70% confident.
anti-static/obfuscation base64_encode function call for encoding payloads
notable severity, 70% confident.
command-and-control/backdoor AJAX request handler pattern
notable severity, 75% confident.
execution/interpreter/eval PHP eval() function call

Micro-behaviors

notable severity, 85% confident.
communications/http/request HTTP POST parameter access ($_POST)
notable severity, 95% confident.
os Disables error reporting (error_reporting(0))
notable severity, 70% confident.
process/control Remove execution time limit
notable severity, 75% confident.
process/interpreter PHP eval() token present
baseline severity, 70% confident.
crypto/hash MD5 hash computation
baseline severity, 80% confident.
process/create Command injection characters in config-like strings

Metadata

component severity, 90% confident.
package File has 30 or more lines

Third-party

hostile severity, 90% confident.
SigBase/EXT/WEBSHELL/PHP php webshell having some kind of input and some kind of payload. restricted to small files or big ones including suspicious strings
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP PHP webshell which eval()s obfuscated string

Identity

SHA-256 da22a417d7c481815a45fdfa9cb74c95a8af6910607f673fe345722bbc0f856f
Filename 20220213_03.php

Origin

Source harvest
Feed datasets
Ecosystem webshell

Timeline

First seen 24 Apr 2026 16:15 UTC
Last analyzed 26 Apr 2026 08:58 UTC
Last updated 26 Apr 2026 08:58 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d