Open-source atomic malware analysis

Analyze another

e9eb2ca22dfcd5e93984716b64dddeb82c0cac4541b6588c06f102a024d5fb2a.php

PHP
Verdict: SUSPICIOUS
Mal-ecule
O₂(AsC)H(Cm)Md(Pa)Th
Size 239 B download
First seen 118 days ago
Analyzed 117 days ago
Ecosystem MalwareBazaar

Objectives

suspicious severity, 95% confident.
anti-static/obfuscation/string preg_replace with /e modifier (code execution)
notable severity, 70% confident.
command-and-control/backdoor AJAX request handler pattern

Micro-behaviors

notable severity, 85% confident.
communications/http/request HTTP POST parameter access ($_POST)

Metadata

component severity, 80% confident.
package Very short file (under 12 lines)

Third-party

hostile severity, 90% confident.
SigBase/EXT/WEBSHELL/PHP php webshell having some kind of input and some kind of payload. restricted to small files or big ones including suspicious strings

Identity

SHA-256 e9eb2ca22dfcd5e93984716b64dddeb82c0cac4541b6588c06f102a024d5fb2a
Filename e9eb2ca22dfcd5e93984716b64dddeb82c0cac4541b6588c06f102a024d5fb2a.php

Origin

Source harvest
Feed datasets
Ecosystem MalwareBazaar

Timeline

First seen 24 Apr 2026 16:19 UTC
Last analyzed 26 Apr 2026 04:44 UTC
Last updated 26 Apr 2026 04:44 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d