Open-source atomic malware analysis

Analyze another

VirusShare_d390b56e7754a6f31fbac5095b01a930

PHP
Verdict: SUSPICIOUS
Mal-ecule
O(As₂)H(Po)Md
Size 11.7 KB download
First seen 95 days ago
Analyzed 93 days ago

Objectives

suspicious severity, 90% confident.
anti-static/obfuscation/code-metrics PHP source contains very long line
notable severity, 80% confident.
anti-static/obfuscation PHP variable function invocation pattern
component severity, 86% confident.
command-and-control/backdoor/webshell Very long embedded string

Micro-behaviors

suspicious severity, 75% confident.
process/interpreter PHP eval() token present
component severity, 84% confident.
data/text/llm "to the" doc cue

Metadata

notable severity, 90% confident.
encoded-payload Encoded payload detected: url
baseline severity, 100% confident.
lang php code embedded in string
component severity, 90% confident.
file/text Very long line

Identity

SHA-256 e9660d7eae7e0cc9fb752d81849cdbb758cb8f42bd3e5000c70256e520fbc9d5
Filename VirusShare_d390b56e7754a6f31fbac5095b01a930

Origin

Source harvest

Timeline

First seen 12 May 2026 19:06 UTC
First analyzed 15 May 2026 01:25 UTC
Last analyzed 15 May 2026 01:25 UTC
Last updated 15 May 2026 01:25 UTC

Labeling

Label bad
Label source harvest
Traits version 08128