This is wuftpd2.6.0x and qpop2.1.4 exploit ported to PHP. Even php in safe mode can not stop this script from working. Webhosting providers who provide PHP need to be careful.
13aada54c954522f4a2446611b67aa75d2fad31ef0fb63a0303da5710582411d
Eshell.c is a encrypted bindshell type backdoor which has a server daemon and client with AES encryption via libmix.
c32ad105680ad262b5dca88fcaaaf43d24a5994d3d79f9243bfc0001ca76c38b