Most times code is base64 encode. You can decode if you wants if just base64. But Horatio is write, 99% It a shellcode.
Are all sites on same server? Shared hosting?
Reverse IP Lookup - Find Other Web Sites Hosted on a Web Server
If nots maybe all you sites have same hole.
Whats your sites runnings? If wordpress make sures all is updated. If some bad php somewheres or old imagemagick could allow remote code exectuions and allows persons to upload shells.
Maybe nots your faults if on shared hosting.
Maybe other gfy guys can helps that knows mores than me (I expert in onlys blogspots). if he set permissions to 555, woulds that helps?