I've seen this now on a couple Evo sites, some of which I think were up to date and patched running 1.0.14 (?) but I can't guarantee when the patch was installed vs. when the hack appeared.
The payload is not base64 encoded, just ut8 and other character entities to obscure function and variable names (use
http://www.unphp.net/ to decode it). There are lots of lines like this:
${"G\x4cO\x42AL\x53"}["\x77\x6dbl\x63\x67\x63"] = "ips";
which decode to something like this:
${"GLOBALS"}["wmblcgc"]="ips";
The file includes the following functions:
* error_404
* http_request_custom
* getUseragent
* getReferer
* convertIpToString
* getIp
In the access logs, the file is requested something like this:
123.12.12.123 - - [16/Jun/2014:18:25:44 -0700] "GET /lang.php?data=527FAFaJSSynJ1oFsEur9HH/Is2+hJQBbPXldtbEvvY= HTTP/1.1" 200 32 "-" "Mozilla/5.0 (Linux; U; Android 4.2; en-us; Nexus 10 Build/JVP15I) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30"
This appears to be uploading files and data back to a Chinese server: 125.89.44.28 (
http://myip.ms/view/ip_addresses/2102995968/125.89.44.0_125.89.44.255). The script looks like it makes a bunch of outgoing requests to
http://67.35.103.53:80/fdn/entry.php?ip=xxxxx&path=xxxxxxx&useragent=Mozilla%2F5.0+%28Macintosh%3B+Intel+Mac+OS+X+10_9_3%29+AppleWebKit%2F537.36+%28KHTML%2C+like+Gecko%29+Chrome%2F35.0.1916.153+Safari%2F537.36
If anyone has any more information about this (including info on how it got onto an Evo site), please share it here.
[ed. note: Everettg_99 last edited this post 12 years, 3 months ago.]