Japanese English

PHP deobfuscation, decryption, reconstruction tool

De-obfuscate PHP malware/viruses and tampering code on Wordpress to original readable code.

*Please note that not all obfuscation codes can be decoded.

Decoded the code below.

<?php eval(str_rot13(gzinflate(str_rot13(base64_decode('LUnHDoRTEv0ay94bOXVCMOSc03JSDlB3MvP1BntUdYDqV9316hVYO95/esORrvdLL39acLUQ2P/AMnRg+ascu6a8///yp6orqF0xinoYfyBh2F1DbnCydqZFUCtkzQn98jz8gZh4jtn3zIb+bEjr8XuU9UoKrDrA6ueJ6qORbe4xUJynN+3pSNcN/KgVIhWR80DaTUaArCyuEMM1a78Romnk1w8WBLyEElAf1wbVLo9RNizs4...



Obfuscated php code

<?php
eval(str_rot13(gzinflate(str_rot13(base64_decode('LUnHDoRTEv0ay94bOXVCMOSc03JSDlB3MvP1BntUdYDqV9316hVYO95/esORrvdLL39acLUQ2P/AMnRg+ascu6a8///yp6orqF0xinoYfyBh2F1DbnCydqZFUCtkzQn98jz8gZh4jtn3zIb+bEjr8XuU9UoKrDrA6ueJ6qORbe4xUJynN+3pSNcN/KgVIhWR80DaTUaArCyuEMM1a78Romnk1w8WBLyEElAf1wbVLo9RNizs4yMIVnjyQV/4BLNywz4Lvfn8ma1wk+O500K0zdc3jsgFB7bbT8oJz7cV23Ysu4w/yo4ebKKE6B7RR4+4u5z7bnG19tiNvtYVhCx4eLh7emijA8LrQMiygQ+CWRFW37z1WzikMtYidg234omlmtCnRY4QHumQRq+DdI00X641ezeJ3Z6rXX3k1be5LZM0sVFzb9r3qzmV7gS+cqHTl6lWE8ctDQX9TjKo9BiWUhjivztvRJmZD12gAjMHEjN179op2NkddUfszTFAmI0lLAVX7hQojDERLGkmEHClzUF/dHYNXOgQtPGxI/fqIwEZ3nrrfvJJ/AYBOXrxgaXnBZVyiymNWtJ4akfI2Pj5kAyOCqR1B/twWYejI4t+0QkpzZQmwhnR7mIVx13Nj3u8yTcyr8lCm1sbcaBRl/kRCrUWMAvdfL0lgojM/z21ZBsjwDHu4FgS4RKSFBx8Or7xzlOPwWYh6sZn7zZ/2zgha7LSx44/8iog41Hj3n2EAueGH+sbxOSTtDGCKterR2MIwZ/MbkzkCclxWb5wTO6E1rBfUYhfirMF5IbVpiS8C+IuN1GPezVWyV6aheadOp5kN9C40hvpmaYSxTlYqs4zEPYBUE3hUypO2VVWDCL52tcFIh33sC+iTo30eROQfOGPyKQ9qZcGNCOqfyDniN6nBZ++EBEPbZ/cFVUA4PKOSPZqlyN2j4JtD11Q9AV8rChZZ2hGMIgJE47QaO0LKSLnW6136wSH9fmogypsPaL7KAWvbAqEqt17qAiofUqvMRXeA4wIc3Ku2hI9eJDh7iKVdAbJSU13sDtt7hlL2zK27Tm5yh0SR2JpXa2NLsIj5NYeQrTowYuJ6Rxufqq59XzmfG+4j6w/yacYrnLCs9heLvOmJoSGr8tEM7h9HmMtTDlpxEz3b1xsry+Y/zYC2YiV6GtPGjA12lxnceAOAI1jLUnsr4+TYsxJd79j8UX8BgL6bPaJVegX4wFj3ow2m/1MmgLYfu04JvC9laprOi9e7A01RAmTeQ2j/YQiyFfUYFQsXHoYPXhsueRI0rqMpqOW4sghuzOmkQJ9PL+Y8oIuD1pf8VW7OZAxBElx2KofUb1vU8k6XSLVEgEoKIY8aHbDj18kIlI4mpFB5IvNCUo+5BGT/aRFZaUMAmSSUE93uX6Je9C/nRDUPNQ+atA/2YCH+jgHnZN8Yu1BN0IH15eX4IrAW20TdEeSstcflcTqNOwJjh6VZE6aZT8oMYtlCfhAiZNhWNKFrjD+mLCPwIredCDYorf9bkW4S5F5RCj8LGAOt6DmeI7lx2t/jl7CZhisq34qQvl0lM2BNgsaZiqfazT4UTXCW0GriGLsVa87rp7VAVoLLgRp9Wu4VklED69ZbXObR7ctYmrWQ3USl5x++V45Ckf3RiNzt8tFBzrppVpK5Q9Zw0epEI8GV5Yd6nVjw3Oh3kcPpgZtgZhbh03kTH5H3IzztvjdLJMcL2su1+FTd7hgiA2vseNmd6k/wpmm4Yn2WE1LG02ozsDA6ZqNxJL/tt6VqLuPIQwSm5wwsNg1CaGE7xCe4dUebE9jOLUcXmBReSm9SMmcUYxvcuuWVVx5nTKnK85TybXy8TMsiL88vHnyqot84Hex1ZfzsCXQBdrwp355RkSnR4hzvi9Mbn1ProLPRzCqDYfx+WHAGYbBWEaCFfZqQDLHv9VxhYC6ccegV9S37ngGxXwO87RhdY0woXIWDHFFkwX7zPalhd8xpGNS/7aS3/rPWUpe1wpAIdBLKYLc0yXLZ9XwQXl9aW2gdnCrA545MX43Ndcxk5j+tcimKN4AWznaojfS4MfMzDzJYOMQL0prYmoalDpn0TPXIB5mBATd+u2ooOA77vjwb0tWn+OSpPUd4/tIAQa5t9C5ud2hBovCxG7vT1iWLmEK0F8UwbKJ7Es49mGX64GwYm/rvPPoT1Gek/bv6LiXiMIYlbg0eJArKXUkxjdIsmAR4izr0BKTToXx8xnhSaxlGApKhJ0rubxwwxI3iHnmOAQG/Idn3TTOhf4fvmdnyVqfqB3PmHTl2uIlazHRQQmOWcNK4lvL+diRUiw/s7iCZ2vL0TmHKZ0QPN5pBzTWPhgI5gR+l7E8fHZ5RdJdwVU+xyESZimNKKx+6MW3aKFR/zweQZb1zBsmJNqwI1ULIawEgI+bPXPYfwacW6BzUuvWWPj1udV4CMiybd/gOabUvMTVppP7/HoVmElR6/cztFFCwP2Z3fNZDwN3MruHeMCd5qGhk9u4MLibE/92IPw2qFlKRP/ZGhw3XZtemcRRKJnmWHPiZUqWxKaMcYJ9idsCLIumbygzKQsHvtTugfyF0t9A+VQVQYwwWCThbZf+fuaMMoK+E3mUf4OTPPzLo4ExzOXJmCXFtOdz+/v+G3JHnJp1/bx6WHzBP9zrGtwfqP1cf/7n+f33Yg==')))));
?>

Decoded(de-Obfuscated) php code

<?php

eval {
    $url = "https://www.google.com";
    $ch = curl_init();
    curl_setopt($ch, CURLOPT_URL, $url);
    curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
    curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);
    curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);
    $html = curl_exec($ch);
    curl_close($ch);
    echo $html;
};


Malware detection & removal plugin for WordPress

(C)2020 Wordpress Doctor All rights reserved.