Base64 and eval() — How Hackers Hide Malicious PHP Code
Why do hackers obfuscate code?
Malicious PHP code is easy to identify when it is readable. That is why hackers encode it so that it looks like a meaningless string — security scanners and website administrators may overlook it as “something system-related.” The most popular technique is Base64 encoding combined with the eval() function.
<?php eval(base64_decode("cGhwaW5mbygpOw==")); ?>
This snippet decodes to phpinfo(); — in a real attack, a full-fledged backdoor or code that sends spam would be used instead of phpinfo().
How do you read obfuscated code?
Never run unknown obfuscated code directly. Instead, use a safe decoding method:
php -r "echo base64_decode('cGhwaW5mbygpOw==');"
Or use an online site such as base64decode.org (but never paste code that may contain customer data into public services).
Multi-layer obfuscation
Advanced malware uses multi-layer obfuscation: Base64 code decodes into another encoded string, which only reveals the actual code after several iterations. Sometimes the code is also split into fragments stored in variables and assembled dynamically at runtime.
In such cases, professional analysis requires tools for static and dynamic PHP analysis, which is beyond the scope of a manual review.
Which functions should you look for?
eval() — executes a string as PHP code
base64_decode() — decodes a Base64 string
str_rot13() — a simple character rotation, often combined with Base64
gzinflate(), gzuncompress() — decompression, another obfuscation layer
preg_replace('/./e', ...) — in older PHP versions, executes code using the /e modifier
create_function() — creates and executes functions on the fly
The mere presence of these functions does not always mean code is malicious (for example, some legitimate plugins use base64_decode() to store binary data). But every occurrence of eval() combined with base64_decode() is a serious red flag and requires immediate verification.
If you have found obfuscated code on your server and do not know how to assess it safely — contact us. We will analyze every suspicious file and provide a report of what we found.