Local reference
Suspicious dependency
Inferred
Mal-ecule
O₂(AsC)H(Cm)Md(Pa)Th
Objectives
suspicious severity, 95% confident.
anti-static/obfuscation/string
preg_replace with /e modifier (code execution)
notable severity, 70% confident.
command-and-control/backdoor
AJAX request handler pattern
Micro-behaviors
notable severity, 85% confident.
communications/http/request
HTTP POST parameter access ($_POST)
Metadata
component severity, 80% confident.
package
Very short file (under 12 lines)
Third-party
hostile severity, 90% confident.
SigBase/EXT/WEBSHELL/PHP
php webshell having some kind of input and some kind of payload. restricted to small files or big ones including suspicious strings
Identity
| SHA-256 | e9eb2ca22dfcd5e93984716b64dddeb82c0cac4541b6588c06f102a024d5fb2a |
|---|---|
| Filename | e9eb2ca22dfcd5e93984716b64dddeb82c0cac4541b6588c06f102a024d5fb2a.php |
Origin
| Source | harvest |
|---|---|
| Feed | datasets |
| Ecosystem | MalwareBazaar |
Timeline
| First seen | 24 Apr 2026 16:19 UTC |
|---|---|
| Last analyzed | 26 Apr 2026 04:44 UTC |
| Last updated | 26 Apr 2026 04:44 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | bf48d |
Not seeing what you expected? Let us know