Find this useful? Enter your email to receive occasional updates for securing PHP code.
Signing you up...
Thank you for signing up!
PHP Decode
<?php eval(base64_decode('CiBnb3RvIEU3WENLOyBXOTFodjogPz4KICAgIDwvZGl2PgoKICAgIDxkaXYgY2xh..
Decoded Output download
goto E7XCK; W91hv: ?>
</div>
<div class="container">
<pre>
___ ____ _ _ _____ _____ _____ _ _ ____ _____
| \/ (_) | | |_ _| / ___| / __ (_) | / ___|| _ |
| . . |_| | | __| | ___ \ `--. _ _ ___ _ _ | / \/_| |_ _ _/ /___ | |_| |
| |\/| | | | |/ /| |/ __| `--. \ | | / __| | | | | | | | __| | | | ___ \____ |
| | | | | | <_| |\__ \/\__/ / |_| \__ \ |_| | | \__/\ | |_| |_| | \_/ |.___/ /
\_| |_/_|_|_|\_\___/___/\____/ \__,_|___/\__,_| \____/_|\__|\__, \_____/\____/
__/ |
|___/
</pre>
<h2>Satpol PP Webshell Scanner</h2>
<form method="POST">
<label>Lokasi Ngentod:</label><br>
<input type="text" name="dir" value="<?php goto QKZZK; m2Qqo: if (isset($_POST["delete_file"])) { $fileToDelete = $_POST["delete_file"]; $message = ''; if (file_exists($fileToDelete)) { unlink($fileToDelete); $message = "File berhasil dihapus: {$fileToDelete}"; } else { $message = "File tidak ditemukan: {$fileToDelete}"; } $_SESSION["message"] = $message; scanFiles($directory, $malicious_patterns); header("Content-Type: text/html"); echo file_get_contents($_SERVER["PHP_SELF"]); die; } goto DRh8g; DRh8g: $malicious_patterns = array("eval(", "base64_decode(", "exec(", "system(", "passthru(", "shell_exec(", "proc_open(", "popen(", "assert(", "gzuncompress(", "gzinflate(", "str_rot13("); goto LhWJL; py9Jp: if (isset($_POST["scan"])) { scanFiles($directory, $malicious_patterns); } goto zG9q_; n4EGz: ?>
</pre>
</div>
</div>
</body>
</html>
<?php goto yz8iI; QKZZK: echo htmlspecialchars($directory); goto xEkbw; UoXgG: if (isset($_SESSION["message"])) { ?>
<p style="color: green;"> <?php echo $_SESSION["message"]; unset($_SESSION["message"]); ?>
</p>
<?php } goto sl3AW; zG9q_: ?>
<!DOCTYPE html>
<html>
<head>
<title>PHP Webshell Scanner</title>
<style>
body {
font-family: Arial, sans-serif;
margin: 0;
padding: 0;
background-color: black;
color: #00FF00;
overflow: auto;
height: 100vh;
position: relative;
}
.container {
max-width: 600px;
margin: auto;
padding: 20px;
z-index: 1;
position: relative;
}
h2 {
text-align: center;
}
.box {
border: 1px solid #ccc;
padding: 10px;
background: rgba(0, 0, 0, 0.7);
color: white;
}
.danger {
color: red;
font-weight: bold;
}
.warning {
color: orange;
}
input, button {
padding: 5px;
margin-top: 5px;
}
a {
text-decoration: none;
color: #00FF00;
}
pre {
font-family: "Courier New", Courier, monospace;
}
@keyframes matrix {
0% { transform: translateY(0); opacity: 1; }
100% { transform: translateY(100%); opacity: 0; }
}
.matrix-background {
position: absolute;
top: 0;
left: 0;
right: 0;
bottom: 0;
z-index: 0;
pointer-events: none;
background: black;
overflow: hidden;
height: 200%;
}
.matrix-line {
position: absolute;
width: 100%;
height: 100%;
color: #00FF00;
font-family: "Courier New", Courier, monospace;
font-size: 14px;
opacity: 0.2;
animation: matrix 2s infinite;
white-space: nowrap;
}
.matrix-line:nth-child(even) {
animation-duration: 1s;
}
.matrix-line:nth-child(odd) {
animation-duration: 3s;
}
</style>
<script src="https://code.jquery.com/jquery-3.6.0.min.js"></script>
<script>
$(document).ready(function() {
// Tangani penghapusan file dengan AJAX
$("form.delete-file").submit(function(event) {
event.preventDefault(); // Mencegah reload halaman
var form = $(this);
$.ajax({
type: "POST",
url: "", // URL yang sama dengan halaman saat ini
data: form.serialize(), // Kirim data form
success: function(response) {
// Perbarui tampilan setelah penghapusan
$("#scan-results").html($(response).find("#scan-results").html());
$("#scan-log").html($(response).find("#scan-log").html());
}
});
});
});
</script>
</head>
<body>
<div class="matrix-background">
<?php goto AdK5j; RGawn: echo file_exists("scan_log.txt") ? htmlspecialchars(file_get_contents("scan_log.txt")) : "Belum ada scan yang dilakukan."; goto n4EGz; AdK5j: for ($i = 0; $i < 100; $i++) { ?>
<div class="matrix-line"><?php echo rand(0, 9); ?>
</div>
<?php } goto W91hv; rj9X_: function scanFiles($dir, $patterns) { $logFile = "scan_log.txt"; file_put_contents($logFile, "Scan dimulai pada: " . date("Y-m-d H:i:s") . "
"); $files = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($dir)); $results = array(); foreach ($files as $file) { if ($file->isFile() && pathinfo($file, PATHINFO_EXTENSION) === "php") { $content = file_get_contents($file->getRealPath()); $reason = ''; $foundPatterns = array(); foreach ($patterns as $pattern) { if (stripos($content, $pattern) !== false) { if (!in_array($pattern, $foundPatterns)) { $foundPatterns[] = $pattern; } } } if (count($foundPatterns) > 0) { $danger = in_array("eval(", $foundPatterns) || in_array("base64_decode(", $foundPatterns) ? " Penyakit Kelamin" : " Suuzon"; $reason = "File ini mengandung: " . implode(", ", $foundPatterns); $results[] = array($file->getRealPath(), $danger, $reason); file_put_contents($logFile, "{$danger}: " . $file->getRealPath() . " - {$reason}
", FILE_APPEND); } } } usort($results, function ($a, $b) { $order = array(" Suuzon" => 1, " Penyakit Kelamin" => 0); return $order[$a[1]] - $order[$b[1]]; }); $_SESSION["scan_results"] = $results; } goto m2Qqo; E7XCK: session_start(); goto rj9X_; xEkbw: ?>
" size="50">
<button type="submit" name="scan">Mulai Entot</button>
</form>
<?php goto UoXgG; LhWJL: $directory = isset($_POST["dir"]) ? $_POST["dir"] : __DIR__; goto py9Jp; mf5bn: ?>
</div>
<br>
<h3>Log Scan:</h3>
<div id="scan-log" class="box">
<pre><?php goto RGawn; yz8iI: function getDomainFromPath($path) { $relativePath = str_replace("/var/www/", '', $path); return $relativePath; } goto E5oUl; sl3AW: ?>
<div id="scan-results">
<?php goto ib9j0; ib9j0: if (isset($_SESSION["scan_results"])) { ?>
<h3>Hasil Scan:</h3>
<div class="box">
<?php if (empty($_SESSION["scan_results"])) { ?>
<p>Tidak ada file Suuzon ditemukan.</p>
<?php } else { ?>
<ul>
<?php foreach ($_SESSION["scan_results"] as $result) { ?>
<li class="<?php echo $result[1] == " Penyakit Kelamin" ? "danger" : "warning"; ?>
">
<?php echo $result[1]; ?>
-
<a href="http://<?php echo getDomainFromPath($result[0]); ?>
" target="_blank">
<?php echo getDomainFromPath($result[0]); ?>
</a> <br>
<small><?php echo isset($result[2]) ? $result[2] : "Alasan tidak ditemukan"; ?>
</small> <br>
<form method="POST" class="delete-file" style="display: inline;">
<input type="hidden" name="delete_file" value="<?php echo $result[0]; ?>
">
<button type="submit">Hapus File</button>
</form>
</li>
<?php } ?>
</ul>
<?php } ?>
</div>
<?php } goto mf5bn; E5oUl:
Did this file decode correctly?
Original Code
<?php eval(base64_decode('
 goto E7XCK; W91hv: ?>
    </div>

    <div class="container">
        <pre>
 ___  ____ _ _   _____     _____                   _____ _ _          ____  _____ 
|  \/  (_) | | |_   _|   /  ___|                 /  __ (_) |        / ___||  _  |
| .  . |_| | | __| | ___ \ `--. _   _ ___ _   _  | /  \/_| |_ _   _/ /___ | |_| |
| |\/| | | | |/ /| |/ __| `--. \ | | / __| | | | | |   | | __| | | | ___ \\____ |
| |  | | | |   <_| |\__ \/\__/ / |_| \__ \ |_| | | \__/\ | |_| |_| | \_/ |.___/ /
\_|  |_/_|_|_|\_\___/___/\____/ \__,_|___/\__,_|  \____/_|\__|\__, \_____/\____/ 
                                                               __/ |             
                                                              |___/               
</pre>

        <h2>Satpol PP Webshell Scanner</h2>
        <form method="POST">
            <label>Lokasi Ngentod:</label><br>
            <input type="text" name="dir" value="<?php  goto QKZZK; m2Qqo: if (isset($_POST["\x64\145\x6c\x65\x74\145\137\146\x69\x6c\145"])) { $fileToDelete = $_POST["\x64\145\x6c\145\164\x65\137\x66\x69\154\145"]; $message = ''; if (file_exists($fileToDelete)) { unlink($fileToDelete); $message = "\106\151\x6c\x65\40\142\145\x72\150\x61\163\151\x6c\x20\x64\x69\x68\x61\x70\165\x73\x3a\40{$fileToDelete}"; } else { $message = "\x46\151\x6c\x65\40\164\151\144\x61\x6b\40\x64\x69\x74\145\155\x75\x6b\x61\156\72\x20{$fileToDelete}"; } $_SESSION["\x6d\145\163\x73\141\x67\145"] = $message; scanFiles($directory, $malicious_patterns); header("\x43\157\156\x74\145\156\164\x2d\124\x79\x70\x65\x3a\x20\164\x65\170\x74\x2f\150\x74\155\x6c"); echo file_get_contents($_SERVER["\120\x48\x50\137\x53\105\x4c\106"]); die; } goto DRh8g; DRh8g: $malicious_patterns = array("\145\166\x61\154\x28", "\142\x61\163\x65\66\64\137\144\145\x63\x6f\144\x65\50", "\x65\170\x65\143\50", "\163\171\163\164\145\155\50", "\x70\141\x73\163\164\150\162\x75\50", "\163\150\145\x6c\154\137\145\x78\145\143\50", "\160\162\x6f\x63\137\x6f\x70\145\x6e\x28", "\x70\x6f\x70\145\x6e\50", "\141\x73\x73\145\162\x74\50", "\x67\172\x75\x6e\143\x6f\x6d\x70\162\145\163\x73\50", "\x67\172\151\156\x66\x6c\141\x74\x65\50", "\163\x74\x72\137\162\x6f\164\61\63\x28"); goto LhWJL; py9Jp: if (isset($_POST["\163\143\141\x6e"])) { scanFiles($directory, $malicious_patterns); } goto zG9q_; n4EGz: ?>
</pre>
        </div>
    </div>
</body>
</html>

<?php  goto yz8iI; QKZZK: echo htmlspecialchars($directory); goto xEkbw; UoXgG: if (isset($_SESSION["\x6d\x65\x73\163\x61\x67\x65"])) { ?>
            <p style="color: green;"> <?php  echo $_SESSION["\x6d\145\163\x73\x61\147\145"]; unset($_SESSION["\x6d\x65\x73\x73\x61\x67\x65"]); ?>
 </p>
        <?php  } goto sl3AW; zG9q_: ?>

<!DOCTYPE html>
<html>
<head>
    <title>PHP Webshell Scanner</title>
    <style>
        body {
            font-family: Arial, sans-serif;
            margin: 0;
            padding: 0;
            background-color: black;
            color: #00FF00;
            overflow: auto;
            height: 100vh;
            position: relative;
        }

        .container {
            max-width: 600px;
            margin: auto;
            padding: 20px;
            z-index: 1;
            position: relative;
        }

        h2 {
            text-align: center;
        }

        .box {
            border: 1px solid #ccc;
            padding: 10px;
            background: rgba(0, 0, 0, 0.7);
            color: white;
        }

        .danger {
            color: red;
            font-weight: bold;
        }

        .warning {
            color: orange;
        }

        input, button {
            padding: 5px;
            margin-top: 5px;
        }

        a {
            text-decoration: none;
            color: #00FF00;
        }

        pre {
            font-family: "Courier New", Courier, monospace;
        }

        @keyframes matrix {
            0% { transform: translateY(0); opacity: 1; }
            100% { transform: translateY(100%); opacity: 0; }
        }

        .matrix-background {
            position: absolute;
            top: 0;
            left: 0;
            right: 0;
            bottom: 0;
            z-index: 0;
            pointer-events: none;
            background: black;
            overflow: hidden;
            height: 200%;
        }

        .matrix-line {
            position: absolute;
            width: 100%;
            height: 100%;
            color: #00FF00;
            font-family: "Courier New", Courier, monospace;
            font-size: 14px;
            opacity: 0.2;
            animation: matrix 2s infinite;
            white-space: nowrap;
        }

        .matrix-line:nth-child(even) {
            animation-duration: 1s;
        }

        .matrix-line:nth-child(odd) {
            animation-duration: 3s;
        }
    </style>
    <script src="https://code.jquery.com/jquery-3.6.0.min.js"></script>
    <script>
        $(document).ready(function() {
            // Tangani penghapusan file dengan AJAX
            $("form.delete-file").submit(function(event) {
                event.preventDefault(); // Mencegah reload halaman
                var form = $(this);

                $.ajax({
                    type: "POST",
                    url: "", // URL yang sama dengan halaman saat ini
                    data: form.serialize(), // Kirim data form
                    success: function(response) {
                        // Perbarui tampilan setelah penghapusan
                        $("#scan-results").html($(response).find("#scan-results").html());
                        $("#scan-log").html($(response).find("#scan-log").html());
                    }
                });
            });
        });
    </script>
</head>
<body>
    <div class="matrix-background">
        <?php  goto AdK5j; RGawn: echo file_exists("\163\143\x61\x6e\x5f\x6c\x6f\x67\x2e\x74\170\x74") ? htmlspecialchars(file_get_contents("\x73\143\141\156\137\154\157\147\x2e\164\x78\164")) : "\x42\145\154\x75\x6d\x20\141\144\x61\x20\163\143\x61\156\x20\x79\x61\156\x67\40\x64\x69\x6c\x61\x6b\x75\x6b\x61\156\56"; goto n4EGz; AdK5j: for ($i = 0; $i < 100; $i++) { ?>
            <div class="matrix-line"><?php  echo rand(0, 9); ?>
</div>
        <?php  } goto W91hv; rj9X_: function scanFiles($dir, $patterns) { $logFile = "\163\143\141\x6e\x5f\154\157\147\x2e\x74\x78\x74"; file_put_contents($logFile, "\123\143\x61\x6e\40\x64\x69\x6d\x75\x6c\x61\151\40\160\x61\x64\x61\72\x20" . date("\x59\x2d\x6d\x2d\144\40\110\x3a\151\72\163") . "\12\12"); $files = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($dir)); $results = array(); foreach ($files as $file) { if ($file->isFile() && pathinfo($file, PATHINFO_EXTENSION) === "\x70\150\160") { $content = file_get_contents($file->getRealPath()); $reason = ''; $foundPatterns = array(); foreach ($patterns as $pattern) { if (stripos($content, $pattern) !== false) { if (!in_array($pattern, $foundPatterns)) { $foundPatterns[] = $pattern; } } } if (count($foundPatterns) > 0) { $danger = in_array("\x65\x76\x61\154\x28", $foundPatterns) || in_array("\x62\x61\163\x65\66\x34\137\144\x65\x63\157\x64\145\x28", $foundPatterns) ? "\342\x9d\214\40\x50\x65\156\171\141\x6b\x69\x74\40\x4b\x65\x6c\x61\155\151\156" : "\342\232\240\357\xb8\217\x20\123\165\x75\x7a\x6f\156"; $reason = "\106\151\154\145\x20\x69\x6e\151\x20\155\145\156\147\x61\x6e\144\x75\x6e\147\72\x20" . implode("\54\40", $foundPatterns); $results[] = array($file->getRealPath(), $danger, $reason); file_put_contents($logFile, "{$danger}\x3a\x20" . $file->getRealPath() . "\40\x2d\40{$reason}\12", FILE_APPEND); } } } usort($results, function ($a, $b) { $order = array("\342\x9a\240\xef\270\217\x20\x53\x75\165\x7a\157\156" => 1, "\342\235\214\x20\120\x65\x6e\x79\141\x6b\x69\164\x20\x4b\145\154\141\155\151\156" => 0); return $order[$a[1]] - $order[$b[1]]; }); $_SESSION["\163\x63\141\156\x5f\162\145\x73\x75\x6c\x74\x73"] = $results; } goto m2Qqo; E7XCK: session_start(); goto rj9X_; xEkbw: ?>
" size="50">
            <button type="submit" name="scan">Mulai Entot</button>
        </form>
        
        <?php  goto UoXgG; LhWJL: $directory = isset($_POST["\144\x69\162"]) ? $_POST["\144\x69\162"] : __DIR__; goto py9Jp; mf5bn: ?>
        </div>

        <br>
        <h3>Log Scan:</h3>
        <div id="scan-log" class="box">
            <pre><?php  goto RGawn; yz8iI: function getDomainFromPath($path) { $relativePath = str_replace("\x2f\x76\x61\x72\57\167\167\x77\x2f", '', $path); return $relativePath; } goto E5oUl; sl3AW: ?>
        
        <div id="scan-results">
            <?php  goto ib9j0; ib9j0: if (isset($_SESSION["\x73\x63\x61\x6e\137\x72\x65\163\165\154\x74\x73"])) { ?>
                <h3>Hasil Scan:</h3>
                <div class="box">
                    <?php  if (empty($_SESSION["\163\143\141\x6e\137\x72\x65\x73\165\x6c\x74\163"])) { ?>
                        <p>Tidak ada file Suuzon ditemukan.</p>
                    <?php  } else { ?>
                        <ul>
                            <?php  foreach ($_SESSION["\x73\x63\141\156\137\x72\x65\163\165\x6c\164\x73"] as $result) { ?>
                                <li class="<?php  echo $result[1] == "\342\235\x8c\40\120\145\x6e\x79\141\153\x69\164\x20\113\145\154\x61\x6d\x69\x6e" ? "\144\x61\156\147\145\x72" : "\x77\x61\162\x6e\151\156\147"; ?>
">
                                    <?php  echo $result[1]; ?>
 - 
                                    <a href="http://<?php  echo getDomainFromPath($result[0]); ?>
" target="_blank"> 
                                        <?php  echo getDomainFromPath($result[0]); ?>
                                    </a> <br>
                                    <small><?php  echo isset($result[2]) ? $result[2] : "\x41\x6c\x61\x73\141\156\40\164\151\144\141\153\40\x64\151\x74\x65\155\165\153\x61\156"; ?>
</small> <br>
                                    <form method="POST" class="delete-file" style="display: inline;">
                                        <input type="hidden" name="delete_file" value="<?php  echo $result[0]; ?>
">
                                        <button type="submit">Hapus File</button>
                                    </form>
                                </li>
                            <?php  } ?>
                        </ul>
                    <?php  } ?>
                </div>
            <?php  } goto mf5bn; E5oUl: ')); ?>
Function Calls
base64_decode | 1 |
Stats
MD5 | 082cf8f7e59564ab67c9a47b637af6c5 |
Eval Count | 1 |
Decode Time | 47 ms |