Find this useful? Enter your email to receive occasional updates for securing PHP code.

Signing you up...

Thank you for signing up!

PHP Decode

<?php eval("?>".base64_decode("PD9waHANCmVycm9yX3JlcG9ydGluZygwKTsNCnNlc3Npb25fc3RhcnQoKTs..

Decoded Output download

?>b'<?php
error_reporting(0);
session_start();
date_default_timezone_set("Asia/Ho_Chi_Minh");
$end="[0m";
$black="[0;30m";
$blackb="[1;30m";
$white="[0;37m";
$whiteb="[1;37m";
$red="[0;31m";
$redb="[1;31m";
$green="[0;32m";
$greenb="[1;32m";
$yellow="[0;33m";
$yellowb="[1;33m";
$syan="[1;36m";
$blue="[0;34m";
$blueb="[1;34m";
$purple="[0;35m";
$purpleb="[1;35m";
$lightblue="[0;36m";
$lightblue="[1;35m";
$lightblueb="[1;36m";
$hong="[1;95m";
$input = array($d2="[1;36m",$tmd3="[1;37m",$tmd4="[1;37m",$tmd5="[0;31m",$tmd6="[1;31m",$tmd7="[0;32m",$tmd8="[1;32m",$tmd9="[0;33m",$tmd10="[1;33m",$tmd11="[0;34m",$tmd12="[1;34m",$tmd13="[0;35m",$tmd14="[1;35m",$tmd15="[0;36m",$tmd16="[1;36m");
$rand_keys = array_rand($input, 10);
$input = array($tmd1="[1;46m",$tmd2="[1;36m",$tmd3="[1;37m",$tmd4="[1;37m",$tmd5="[0;31m",$tmd6="[1;31m",$tmd7="[0;32m",$tmd8="[1;32m",$tmd9="[0;33m",$tmd10="[1;33m",$tmd11="[0;34m",$tmd12="[1;34m",$tmd13="[0;35m",$tmd14="[1;35m",$tmd15="[0;36m",$tmd16="[1;36m");
@system(\'clear\');
$data = file_get_contents(\'id.txt\');
$a = strlen($data);
if($a == \'0\') {
	$cc = \'HY XA DNG CH NY V DN ID TI KHON CN REPORT VO Y\';
	$mofilene = fopen("id.txt","a");
            fwrite($mofilene, $cc);
            fclose($mofilene); 

echo "[1;37m ~[1;32m VUI LNG NHP ID VO FILE:[1;37m id.txt
";
	exit();
	}
echo "[1;32m
[1;32m [1;96m   [1;97m  [1;32m                                                      
[1;32m [1;96m         [1;95m   IP : $ip  [1;32m                 
[1;32m [1;96m        [1;94m   ZALO : 0967699321  [1;32m        
[1;32m [1;96m             [0;33m   TIME : $time  [1;32m                 
[1;32m [1;96m          [1;92m   YOUTUBE : NVT-TOOL  [1;32m       
[1;32m [1;96m            [1;97m    TOOL AUTO DAME NOT   [1;32m    
[1;32m [1;96m               [0;31m   BN QUYN BY NVT-TOOL  [1;32m    
[1;32m [1;96m   [1;97m  [1;32m                                                      
[1;32m
 $green ------------------------------------------------------
$redb  ------------------------------------------------------
$yellow  ------------------------------------------------------ 
[1;37m~[1;31m[[1;32m[1;31m][1;37m =>[1;32m NHP COOKIE CLONE  FAKE : [1;37m";
$cookie = trim(fgets(STDIN));
@system(\'clear\');
echo "[1;32m
[1;32m [1;96m   [1;97m  [1;32m                                                      
[1;32m [1;96m         [1;95m   IP : $ip  [1;32m                 
[1;32m [1;96m        [1;94m   ZALO : 0967699321  [1;32m        
[1;32m [1;96m             [0;33m   TIME : $time  [1;32m                 
[1;32m [1;96m          [1;92m   YOUTUBE : NVT-TOOL  [1;32m       
[1;32m [1;96m            [1;97m    TOOL AUTO DAME NOT   [1;32m    
[1;32m [1;96m               [0;31m   BN QUYN BY NVT-TOOL  [1;32m    
[1;32m [1;96m   [1;97m  [1;32m                                                      
[1;32m
 $green ------------------------------------------------------
$redb  ------------------------------------------------------
$yellow  ------------------------------------------------------ 
";


while (true){
	$fp = fopen("id.txt", "r");
while(! feof($fp)) {
    $id = fgets($fp);
    $id = substr($id, 0, 15);
    $dem++;
    echo " [1;31m [[1;36m$dem[1;31m]  [1;30m ".date("H:i")." [1;31m [1;32mDAME NOT [1;31m[1;37m ID [1;35m: ".$id."
";
$url  = "https://mbasic.facebook.com/".$id."";
    $head = array(
        "Host: mbasic.facebook.com",
        "upgrade-insecure-requests: 1",
        "save-data: on",
        "user-agent: Mozilla/5.0 (Linux; Android 10; Redmi Note 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.92 Mobile Safari/537.36",
        "accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*" . "/" . "*;q=0.8,application/signed-exchange;v=b3;q=0.9",
        "sec-fetch-site: same-origin",
        "sec-fetch-mode: navigate",
        "sec-fetch-user: ?1",
        "sec-fetch-dest: document",
        "accept-language: vi-VN,vi;q=0.9,fr-FR;q=0.8,fr;q=0.7,en-US;q=0.6,en;q=0.5"
    );
    $ch   = curl_init();
    curl_setopt_array($ch, array(
        CURLOPT_URL => $url,
        CURLOPT_FOLLOWLOCATION => false,
        CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_POST => 1,
        CURLOPT_HTTPGET => true,
        CURLOPT_SSL_VERIFYPEER => 0,
        CURLOPT_HTTPHEADER => $head,
        CURLOPT_HEADER => true,
        CURLOPT_COOKIE => $cookie,
        CURLOPT_ENCODING => TRUE
    ));
    $data = curl_exec($ch);
    if (strpos($data, "xs=deleted") == true) {
        echo "[1;37m~[1;33m[[1;31mdie[1;33m] [1;37m=> [1;31mCOOKIE DIE !!!!
";
        exit();
    } 
        $one = explode("location: ", $data);
        $two = explode("rdr", $one[1]);
        $urldata = $two[0] . "rdr";
        $hiader = array(
"Host: mbasic.facebook.com",
"upgrade-insecure-requests: 1",
"user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Kiwi Chrome/68.0.3438.0 Safari/537.36",
"accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
"referer: ".$url.""
        );
        curl_setopt_array($ch, array(
            CURLOPT_URL => $urldata,
            CURLOPT_FOLLOWLOCATION => false,
            CURLOPT_RETURNTRANSFER => 1,
            CURLOPT_POST => 1,
            CURLOPT_HTTPGET => true,
            CURLOPT_SSL_VERIFYPEER => 0,
            CURLOPT_HTTPHEADER => $hiader,
            CURLOPT_HEADER => true,
            CURLOPT_ENCODING => TRUE
        ));
        $a = curl_exec($ch);
        curl_close($ch);
        
        $data			= explode(\'"\',explode(\'/nfx/basic/direct_actions/\', $a)[1])[0];
        $l1 = explode(\'amp;\', $data)[0];
    $l2 = explode(\'amp;\', $data)[1];
    $l3 = explode(\'amp;\', $data)[2];
    
    $link1 = "https://mbasic.facebook.com/nfx/basic/direct_actions/".$l1."".$l2."".$l3."";
    $head = array(
"Host: mbasic.facebook.com",
"upgrade-insecure-requests: 1",
"user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Kiwi Chrome/68.0.3438.0 Safari/537.36",
"accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
"referer: ".$urldata.""
    );
    $ch   = curl_init();
    curl_setopt_array($ch, array(
        CURLOPT_URL => $link1,
        CURLOPT_FOLLOWLOCATION => false,
        CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_POST => 1,
        CURLOPT_HTTPGET => true,
        CURLOPT_SSL_VERIFYPEER => 0,
        CURLOPT_HTTPHEADER => $head,
        CURLOPT_HEADER => true,
        CURLOPT_COOKIE => $cookie,
        CURLOPT_ENCODING => TRUE
    ));
    $a = curl_exec($ch);
    curl_close($ch);
    $data			= explode(\'"\',explode(\'/nfx/basic/handle_action/\', $a)[1])[0];
  $z1 = explode(\'amp;\', $data)[0];
    $z2 = explode(\'amp;\', $data)[1];
      $z3 = explode(\'amp;\', $data)[2];
    $z4 = explode(\'amp;\', $data)[3];
      $z5 = explode(\'amp;\', $data)[4];
      $z6 = explode(\'amp;\', $data)[5];
$fb_dtsg			= explode(\'" autocomplete="off"\',explode(\'name="fb_dtsg" value="\', $a)[1])[0];
    $jazoest			= explode(\'" autocomplete="off"\',explode(\'name="jazoest" value="\', $a)[1])[0];
$link2 = "https://mbasic.facebook.com/nfx/basic/handle_action/".$z1."".$z2."".$z3."".$z4."".$z5."".$z6."";
     $data = "fb_dtsg=".$fb_dtsg."&jazoest=".$jazoest."&action_key=RESOLVE_PROBLEM&submit=Gi";
     $header = array(
"Host: mbasic.facebook.com",
"content-length: ".strlen($data),
"cache-control: max-age=0",
"origin: https://mbasic.facebook.com",
"upgrade-insecure-requests: 1",
"content-type: application/x-www-form-urlencoded",
"user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Kiwi Chrome/68.0.3438.0 Safari/537.36",
"accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
"referer: ".$link1.""
     );
   $ch   = curl_init();
    curl_setopt_array($ch, array(
        CURLOPT_URL => $link2,
          CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_POST => 1,
        CURLOPT_POSTFIELDS => $data,
        CURLOPT_SSL_VERIFYPEER => 0,
        CURLOPT_COOKIE => $cookie,
        CURLOPT_HTTPHEADER => $header,
        CURLOPT_ENCODING => TRUE,
        CURLOPT_FOLLOWLOCATION => true
        ));
        $cc = curl_exec($ch);
       $link3 = curl_getinfo($ch,CURLINFO_EFFECTIVE_URL);
        curl_close($ch);
        $head = array(
"Host: mbasic.facebook.com",
"cache-control: max-age=0",
"upgrade-insecure-requests: 1",
"user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Kiwi Chrome/68.0.3438.0 Safari/537.36",
"accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
"referer: ".$link2.""
        );
   $ch   = curl_init();
    curl_setopt_array($ch, array(
        CURLOPT_URL => $link3,
        CURLOPT_FOLLOWLOCATION => false,
        CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_POST => 1,
        CURLOPT_HTTPGET => true,
        CURLOPT_SSL_VERIFYPEER => 0,
        CURLOPT_HTTPHEADER => $head,
        CURLOPT_HEADER => true,
        CURLOPT_COOKIE => $cookie,
        CURLOPT_ENCODING => TRUE
    ));
    $a = curl_exec($ch);
    curl_close($ch);
   
   $data			= explode(\'"\',explode(\'/ixt/screen/frxtagselectionscreencustom/post/msite/\', $a)[1])[0];
        $x1 = explode(\'amp;\', $data)[0];
    $x2 = explode(\'amp;\', $data)[1];
$fb_dtsg			= explode(\'" autocomplete="off"\',explode(\'name="fb_dtsg" value="\', $a)[1])[0];
    $jazoest			= explode(\'" autocomplete="off"\',explode(\'name="jazoest" value="\', $a)[1])[0];
$link4 = "https://mbasic.facebook.com/ixt/screen/frxtagselectionscreencustom/post/msite/".$x1."".$x2."";
   $data = "fb_dtsg=".$fb_dtsg."&jazoest=".$jazoest."&tag=spam&action=Gi";
 $header = array(
"Host: mbasic.facebook.com",
"content-length: ".strlen($data),
"cache-control: max-age=0",

"origin: https://mbasic.facebook.com",
"upgrade-insecure-requests: 1",
"content-type: application/x-www-form-urlencoded",
"user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Kiwi Chrome/68.0.3438.0 Safari/537.36",
"accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
"referer: ".$link3.""
 );
  $ch   = curl_init();
    curl_setopt_array($ch, array(
        CURLOPT_URL => $link4,
          CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_POST => 1,
        CURLOPT_POSTFIELDS => $data,
        CURLOPT_SSL_VERIFYPEER => 0,
        CURLOPT_COOKIE => $cookie,
        CURLOPT_HTTPHEADER => $header,
        CURLOPT_ENCODING => TRUE,
        CURLOPT_FOLLOWLOCATION => true
        ));
        $cc = curl_exec($ch);
       $link5 = curl_getinfo($ch,CURLINFO_EFFECTIVE_URL);
        curl_close($ch);
        $heads = array(
"Host: mbasic.facebook.com",
"cache-control: max-age=0",
"upgrade-insecure-requests: 1",
"user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Kiwi Chrome/68.0.3438.0 Safari/537.36",
"accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
"referer: ".$link4.""
        );
      $ch   = curl_init();
    curl_setopt_array($ch, array(
        CURLOPT_URL => $link5,
        CURLOPT_FOLLOWLOCATION => false,
        CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_POST => 1,
        CURLOPT_HTTPGET => true,
        CURLOPT_SSL_VERIFYPEER => 0,
        CURLOPT_HTTPHEADER => $heads,
        CURLOPT_HEADER => true,
        CURLOPT_COOKIE => $cookie,
        CURLOPT_ENCODING => TRUE
    ));
    $a = curl_exec($ch);
    curl_close($ch);
    
    $data			= explode(\'"\',explode(\'/rapid_report/basic/actions/post/\', $a)[1])[0];
$x1 = explode(\'amp;\', $data)[0];
    $x2 = explode(\'amp;\', $data)[1];
    $x3 = explode(\'amp;\', $data)[2];
        $x4 = explode(\'amp;\', $data)[3];
$fb_dtsg			= explode(\'" autocomplete="off"\',explode(\'name="fb_dtsg" value="\', $a)[1])[0];
    $jazoest			= explode(\'" autocomplete="off"\',explode(\'name="jazoest" value="\', $a)[1])[0];
$link6 = "https://mbasic.facebook.com/rapid_report/basic/actions/post/".$x1."".$x2."".$x3."".$x4."";    
 $data = "fb_dtsg=".$fb_dtsg."&jazoest=".$jazoest."&action=Gi";
    $header = array(
"Host: mbasic.facebook.com",
"content-length: ".strlen($data),
"cache-control: max-age=0",
"origin: https://mbasic.facebook.com",
"upgrade-insecure-requests: 1",
"content-type: application/x-www-form-urlencoded",
"user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Kiwi Chrome/68.0.3438.0 Safari/537.36",
"accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
"referer: ".$link5.""    
    );
$ch   = curl_init();
    curl_setopt_array($ch, array(
        CURLOPT_URL => $link6,
          CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_POST => 1,
        CURLOPT_POSTFIELDS => $data,
        CURLOPT_SSL_VERIFYPEER => 0,
        CURLOPT_COOKIE => $cookie,
        CURLOPT_HTTPHEADER => $header,
        CURLOPT_ENCODING => TRUE,
        CURLOPT_FOLLOWLOCATION => true
        ));
        $cc = curl_exec($ch);
       $link7 = curl_getinfo($ch,CURLINFO_EFFECTIVE_URL);
        curl_close($ch);
    
    
    }
}
@system(\'clear\');
echo "[1;32m
[1;32m [1;96m   [1;97m  [1;32m                                                      
[1;32m [1;96m         [1;95m   IP : $ip  [1;32m                 
[1;32m [1;96m        [1;94m   ZALO : 0967699321  [1;32m        
[1;32m [1;96m             [0;33m   TIME : $time  [1;32m                 
[1;32m [1;96m          [1;92m   YOUTUBE : NVT-TOOL  [1;32m       
[1;32m [1;96m            [1;97m    TOOL AUTO DAME NOT   [1;32m    
[1;32m [1;96m               [0;31m   BN QUYN BY NVT-TOOL  [1;32m    
[1;32m [1;96m   [1;97m  [1;32m                                                      
[1;32m
 $green ------------------------------------------------------
$redb  ------------------------------------------------------
$yellow  ------------------------------------------------------ 
";
 
while (true){
	$fp = fopen("id.txt", "r");
while(! feof($fp)) {
    $id = fgets($fp);
    $id = substr($id, 0, 15);
    $dem++;
    echo " [1;31m [[1;36m$dem[1;31m]  [1;30m ".date("H:i")." [1;31m [1;32mDAME NOT [1;31m[1;37m ID [1;35m: ".$id."
";
$url  = "https://mbasic.facebook.com/".$id."";
    $head = array(
        "Host: mbasic.facebook.com",
        "upgrade-insecure-requests: 1",
        "save-data: on",
        "user-agent: Mozilla/5.0 (Linux; Android 10; Redmi Note 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.92 Mobile Safari/537.36",
        "accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*" . "/" . "*;q=0.8,application/signed-exchange;v=b3;q=0.9",
        "sec-fetch-site: same-origin",
        "sec-fetch-mode: navigate",
        "sec-fetch-user: ?1",
        "sec-fetch-dest: document",
        "accept-language: vi-VN,vi;q=0.9,fr-FR;q=0.8,fr;q=0.7,en-US;q=0.6,en;q=0.5"
    );
    $ch   = curl_init();
    curl_setopt_array($ch, array(
        CURLOPT_URL => $url,
        CURLOPT_FOLLOWLOCATION => false,
        CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_POST => 1,
        CURLOPT_HTTPGET => true,
        CURLOPT_SSL_VERIFYPEER => 0,
        CURLOPT_HTTPHEADER => $head,
        CURLOPT_HEADER => true,
        CURLOPT_COOKIE => $cookie,
        CURLOPT_ENCODING => TRUE
    ));
    $data = curl_exec($ch);
    if (strpos($data, "xs=deleted") == true) {
        echo "[1;37m~[1;33m[[1;31mdie[1;33m] [1;37m=> [1;31mCOOKIE DIE  !!!!
";
        exit();
    } 
        $one = explode("location: ", $data);
        $two = explode("rdr", $one[1]);
        $urldata = $two[0] . "rdr";
        $hiader = array(
"Host: mbasic.facebook.com",
"upgrade-insecure-requests: 1",
"user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Kiwi Chrome/68.0.3438.0 Safari/537.36",
"accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
"referer: ".$url.""
        );
        curl_setopt_array($ch, array(
            CURLOPT_URL => $urldata,
            CURLOPT_FOLLOWLOCATION => false,
            CURLOPT_RETURNTRANSFER => 1,
            CURLOPT_POST => 1,
            CURLOPT_HTTPGET => true,
            CURLOPT_SSL_VERIFYPEER => 0,
            CURLOPT_HTTPHEADER => $hiader,
            CURLOPT_HEADER => true,
            CURLOPT_ENCODING => TRUE
        ));
        $a = curl_exec($ch);
        curl_close($ch);
        
        $data			= explode(\'"\',explode(\'/nfx/basic/direct_actions/\', $a)[1])[0];
        $l1 = explode(\'amp;\', $data)[0];
    $l2 = explode(\'amp;\', $data)[1];
    $l3 = explode(\'amp;\', $data)[2];
    
    $link1 = "https://mbasic.facebook.com/nfx/basic/direct_actions/".$l1."".$l2."".$l3."";
    $head = array(
"Host: mbasic.facebook.com",
"upgrade-insecure-requests: 1",
"user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Kiwi Chrome/68.0.3438.0 Safari/537.36",
"accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
"referer: ".$urldata.""
    );
    $ch   = curl_init();
    curl_setopt_array($ch, array(
        CURLOPT_URL => $link1,
        CURLOPT_FOLLOWLOCATION => false,
        CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_POST => 1,
        CURLOPT_HTTPGET => true,
        CURLOPT_SSL_VERIFYPEER => 0,
        CURLOPT_HTTPHEADER => $head,
        CURLOPT_HEADER => true,
        CURLOPT_COOKIE => $cookie,
        CURLOPT_ENCODING => TRUE
    ));
    $a = curl_exec($ch);
    curl_close($ch);
    $data			= explode(\'"\',explode(\'/nfx/basic/handle_action/\', $a)[1])[0];
  $z1 = explode(\'amp;\', $data)[0];
    $z2 = explode(\'amp;\', $data)[1];
      $z3 = explode(\'amp;\', $data)[2];
    $z4 = explode(\'amp;\', $data)[3];
      $z5 = explode(\'amp;\', $data)[4];
      $z6 = explode(\'amp;\', $data)[5];
$fb_dtsg			= explode(\'" autocomplete="off"\',explode(\'name="fb_dtsg" value="\', $a)[1])[0];
    $jazoest			= explode(\'" autocomplete="off"\',explode(\'name="jazoest" value="\', $a)[1])[0];
$link2 = "https://mbasic.facebook.com/nfx/basic/handle_action/".$z1."".$z2."".$z3."".$z4."".$z5."".$z6."";
     $data = "fb_dtsg=".$fb_dtsg."&jazoest=".$jazoest."&action_key=RESOLVE_PROBLEM&submit=Gi";
     $header = array(
"Host: mbasic.facebook.com",
"content-length: ".strlen($data),
"cache-control: max-age=0",
"origin: https://mbasic.facebook.com",
"upgrade-insecure-requests: 1",
"content-type: application/x-www-form-urlencoded",
"user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Kiwi Chrome/68.0.3438.0 Safari/537.36",
"accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
"referer: ".$link1.""
     );
   $ch   = curl_init();
    curl_setopt_array($ch, array(
        CURLOPT_URL => $link2,
          CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_POST => 1,
        CURLOPT_POSTFIELDS => $data,
        CURLOPT_SSL_VERIFYPEER => 0,
        CURLOPT_COOKIE => $cookie,
        CURLOPT_HTTPHEADER => $header,
        CURLOPT_ENCODING => TRUE,
        CURLOPT_FOLLOWLOCATION => true
        ));
        $cc = curl_exec($ch);
       $link3 = curl_getinfo($ch,CURLINFO_EFFECTIVE_URL);
        curl_close($ch);
        $head = array(
"Host: mbasic.facebook.com",
"cache-control: max-age=0",
"upgrade-insecure-requests: 1",
"user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Kiwi Chrome/68.0.3438.0 Safari/537.36",
"accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
"referer: ".$link2.""
        );
   $ch   = curl_init();
    curl_setopt_array($ch, array(
        CURLOPT_URL => $link3,
        CURLOPT_FOLLOWLOCATION => false,
        CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_POST => 1,
        CURLOPT_HTTPGET => true,
        CURLOPT_SSL_VERIFYPEER => 0,
        CURLOPT_HTTPHEADER => $head,
        CURLOPT_HEADER => true,
        CURLOPT_COOKIE => $cookie,
        CURLOPT_ENCODING => TRUE
    ));
    $a = curl_exec($ch);
    curl_close($ch);
   
   $data			= explode(\'"\',explode(\'/ixt/screen/frxtagselectionscreencustom/post/msite/\', $a)[1])[0];
        $x1 = explode(\'amp;\', $data)[0];
    $x2 = explode(\'amp;\', $data)[1];
$fb_dtsg			= explode(\'" autocomplete="off"\',explode(\'name="fb_dtsg" value="\', $a)[1])[0];
    $jazoest			= explode(\'" autocomplete="off"\',explode(\'name="jazoest" value="\', $a)[1])[0];
$link4 = "https://mbasic.facebook.com/ixt/screen/frxtagselectionscreencustom/post/msite/".$x1."".$x2."";
   $data = "fb_dtsg=".$fb_dtsg."&jazoest=".$jazoest."&tag=spam&action=Gi";
 $header = array(
"Host: mbasic.facebook.com",
"content-length: ".strlen($data),
"cache-control: max-age=0",

"origin: https://mbasic.facebook.com",
"upgrade-insecure-requests: 1",
"content-type: application/x-www-form-urlencoded",
"user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Kiwi Chrome/68.0.3438.0 Safari/537.36",
"accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
"referer: ".$link3.""
 );
  $ch   = curl_init();
    curl_setopt_array($ch, array(
        CURLOPT_URL => $link4,
          CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_POST => 1,
        CURLOPT_POSTFIELDS => $data,
        CURLOPT_SSL_VERIFYPEER => 0,
        CURLOPT_COOKIE => $cookie,
        CURLOPT_HTTPHEADER => $header,
        CURLOPT_ENCODING => TRUE,
        CURLOPT_FOLLOWLOCATION => true
        ));
        $cc = curl_exec($ch);
       $link5 = curl_getinfo($ch,CURLINFO_EFFECTIVE_URL);
        curl_close($ch);
        $heads = array(
"Host: mbasic.facebook.com",
"cache-control: max-age=0",
"upgrade-insecure-requests: 1",
"user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Kiwi Chrome/68.0.3438.0 Safari/537.36",
"accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
"referer: ".$link4.""
        );
      $ch   = curl_init();
    curl_setopt_array($ch, array(
        CURLOPT_URL => $link5,
        CURLOPT_FOLLOWLOCATION => false,
        CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_POST => 1,
        CURLOPT_HTTPGET => true,
        CURLOPT_SSL_VERIFYPEER => 0,
        CURLOPT_HTTPHEADER => $heads,
        CURLOPT_HEADER => true,
        CURLOPT_COOKIE => $cookie,
        CURLOPT_ENCODING => TRUE
    ));
    $a = curl_exec($ch);
    curl_close($ch);
    
    $data			= explode(\'"\',explode(\'/rapid_report/basic/actions/post/\', $a)[1])[0];
$x1 = explode(\'amp;\', $data)[0];
    $x2 = explode(\'amp;\', $data)[1];
    $x3 = explode(\'amp;\', $data)[2];
        $x4 = explode(\'amp;\', $data)[3];
$fb_dtsg			= explode(\'" autocomplete="off"\',explode(\'name="fb_dtsg" value="\', $a)[1])[0];
    $jazoest			= explode(\'" autocomplete="off"\',explode(\'name="jazoest" value="\', $a)[1])[0];
$link6 = "https://mbasic.facebook.com/rapid_report/basic/actions/post/".$x1."".$x2."".$x3."".$x4."";    
 $data = "fb_dtsg=".$fb_dtsg."&jazoest=".$jazoest."&action=Gi";
    $header = array(
"Host: mbasic.facebook.com",
"content-length: ".strlen($data),
"cache-control: max-age=0",
"origin: https://mbasic.facebook.com",
"upgrade-insecure-requests: 1",
"content-type: application/x-www-form-urlencoded",
"user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Kiwi Chrome/68.0.3438.0 Safari/537.36",
"accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
"referer: ".$link5.""    
    );
$ch   = curl_init();
    curl_setopt_array($ch, array(
        CURLOPT_URL => $link6,
          CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_POST => 1,
        CURLOPT_POSTFIELDS => $data,
        CURLOPT_SSL_VERIFYPEER => 0,
        CURLOPT_COOKIE => $cookie,
        CURLOPT_HTTPHEADER => $header,
        CURLOPT_ENCODING => TRUE,
        CURLOPT_FOLLOWLOCATION => true
        ));
        $cc = curl_exec($ch);
       $link7 = curl_getinfo($ch,CURLINFO_EFFECTIVE_URL);
        curl_close($ch);
    
    
    }
}'

Did this file decode correctly?

Original Code

<?php eval("?>".base64_decode("")); ?>

Function Calls

base64_decode 1

Variables

None

Stats

MD5 513c613673923e4538fb77e8e370c4bc
Eval Count 1
Decode Time 68 ms