PHP Malware Analysis

xmrig-6.16.4-linux-static-x64.tar.gz

md5: 0b79369b612a6e750635bb822bfb6f96

Jump to:

Screenshot


Attributes

URLs
  • https://objects.githubusercontent.com/github-production-release-asset-2e65be/88327406/0465c9e9-e7f1-4838-9cb3-af3ac5248af8?X-Amz-Algorithm=AWS4-HMAC-SHA256& (Deobfuscated, Original)


Deobfuscated PHP code

<html><body>You are being <a href="https://objects.githubusercontent.com/github-production-release-asset-2e65be/88327406/0465c9e9-e7f1-4838-9cb3-af3ac5248af8?X-Amz-Algorithm=AWS4-HMAC-SHA256&amp;X-Amz-Credential=AKIAIWNJYAX4CSVEH53A%2F20220319%2Fus-east-1%2Fs3%2Faws4_request&amp;X-Amz-Date=20220319T130218Z&amp;X-Amz-Expires=300&amp;X-Amz-Signature=ed7c7edf7a7d21374a83a982d183b530b9a5bff486034201ff9c52a8f330d20f&amp;X-Amz-SignedHeaders=host&amp;actor_id=0&amp;key_id=0&amp;repo_id=88327406&amp;response-content-disposition=attachment%3B%20filename%3Dxmrig-6.16.4-linux-static-x64.tar.gz&amp;response-content-type=application%2Foctet-stream">redirected</a>.</body></html>

Execution traces


Generated HTML code

<html><head></head><body></body></html>

Original PHP code

<html><body>You are being <a href="https://objects.githubusercontent.com/github-production-release-asset-2e65be/88327406/0465c9e9-e7f1-4838-9cb3-af3ac5248af8?X-Amz-Algorithm=AWS4-HMAC-SHA256&amp;X-Amz-Credential=AKIAIWNJYAX4CSVEH53A%2F20220319%2Fus-east-1%2Fs3%2Faws4_request&amp;X-Amz-Date=20220319T130218Z&amp;X-Amz-Expires=300&amp;X-Amz-Signature=ed7c7edf7a7d21374a83a982d183b530b9a5bff486034201ff9c52a8f330d20f&amp;X-Amz-SignedHeaders=host&amp;actor_id=0&amp;key_id=0&amp;repo_id=88327406&amp;response-content-disposition=attachment%3B%20filename%3Dxmrig-6.16.4-linux-static-x64.tar.gz&amp;response-content-type=application%2Foctet-stream">redirected</a>.</body></html>