Skip to content
Aback Tools Logo

PHP Obfuscated String Extractor

Extract and decode hidden strings from obfuscated PHP code. Automatically detects base64_decode calls, hex2bin and pack() hex decoders, chr() concatenation chains, str_rot13 transformations, gzinflate compressed payloads, and custom decode functions. Shows encoded and decoded values side by side with confidence ratings and source context. Free, private, and no signup required.

PHP Obfuscated String Extractor

Extract and decode hidden strings from obfuscated PHP code. Detects base64_decode, hex2bin, chr() concatenation, str_rot13(), packed binary, gzinflate, and custom decode functions. Shows encoded and decoded values side by side with detection confidence ratings.

Examples:

Paste PHP code above and click Extract Strings to find and decode obfuscated strings. The tool detects base64_decode, hex2bin, chr() concatenation, str_rot13, packed binary, gzinflate, and custom decode function calls. Try loading an example to see how it works!

Features

6 Obfuscation Pattern Detectors

Automatically detects base64_decode(), hex2bin() and pack() hex decoders, chr() number concatenation chains (3+ calls), str_rot13() ROT13 transformations, gzinflate() compressed payloads, and custom user-defined decode functions. Each method uses specialized pattern matching.

Side-by-Side Encoded & Decoded View

Every extracted string shows the original encoded value alongside the decoded result in a clean card layout. Encoded values are displayed in monospace font, decoded values are highlighted in the primary color for easy visual scanning.

Confidence Scoring (1-5)

Each extracted string receives a confidence rating: 5 (Very High) for strings that decode to readable content with spaces or HTML, 4 (High) for successful decoding, 3 (Medium) for ROT13, and 2 (Low) for gzinflate and custom function detections.

Source Context & Line Numbers

Every detection includes surrounding PHP code context (100 characters) and the source line number, making it easy to locate the obfuscated string in the original code. Results are grouped by detection method with color-coded borders.

Use Cases

Malware & Backdoor Analysis

Analyze obfuscated PHP malware, webshells, and backdoors to extract hidden configuration URLs, C2 server addresses, encryption keys, and payload strings. Many PHP malware samples use base64_decode and chr() concatenation to hide strings from static analysis.

Vulnerability Research

Extract obfuscated strings from compromised or suspicious PHP applications during security assessments. Identify hidden admin URLs, backconnect endpoints, data exfiltration targets, and encoded exploit payloads within PHP source code.

PHP Obfuscation Reversal

Reverse-engineer legitimate PHP obfuscation used in commercial plugins and themes. Many PHP encoders use combinations of base64_decode, str_rot13, gzinflate, and custom functions to protect intellectual property.

Code Auditing & Review

During security code audits, use the string extractor to quickly identify encoded configuration values, API keys, database credentials, and other sensitive strings hidden through PHP obfuscation techniques.

Incident Response Forensics

During incident response, analyze PHP files found on compromised servers. Extract hidden IP addresses, domain names, file paths, and command strings from obfuscated PHP code to understand the scope of the compromise.

Educational Tool for PHP Security

Learn how PHP obfuscation techniques work by seeing encoded strings decoded in real time. Understand the different methods attackers use to hide strings and how each decoding technique reverses the obfuscation.

About PHP Obfuscated String Extraction

What Is PHP Obfuscated String Extraction?

PHP obfuscated string extraction is the process of identifying and decoding hidden strings within PHP code that have been intentionally obscured using encoding or encryption functions. Obfuscated PHP code typically stores sensitive values like API keys, URLs, commands, and configuration data as encoded strings that are decoded at runtime. Common techniques include base64_decode() for Base64 encoding, chr() concatenation for building strings from ASCII values,hex2bin() for hex-encoded data, and str_rot13() for ROT13 transformations. Extracting these strings is essential for understanding what the code actually does.

How Our Extractor Works

The extractor scans PHP source code using pattern-matched regular expressions for each known obfuscation technique. For base64_decode(), it extracts the string argument and decodes it using the browser's built-in atob() function. Forchr() concatenation, it collects all numeric arguments from chains of 3+ consecutive calls and converts them to characters. For hex2bin() andpack("H*"), it converts hex pairs to ASCII characters. Forstr_rot13(), it applies the ROT13 cipher to reveal the original string. Custom decode function calls are detected by identifying user-defined functions and their call sites.

Limitations & Considerations

This tool has limitations. gzinflate() and other PHP-only decompression functions cannot be executed in the browser and are noted as requiring PHP runtime.Custom decode functions are detected but their logic cannot be simulated without PHP execution. Dynamic string construction using variables, array lookups, or function return values is not supported. Nested obfuscation(e.g., base64_decode(gzinflate($data))) may require multiple passes. Always verify decoded output before trusting it - false positives are possible with short or coincidental strings.

Privacy & Security

This tool runs entirely in your browser using client-side JavaScript. The PHP code you paste, all extracted strings, decoded values, and analysis results are never uploaded to any server, stored in any database, or transmitted over the network. All parsing, pattern matching, and decoding execute locally on your device. There are no API calls, analytics tracking, cookies, or data collection of any kind. This makes it completely safe for analyzing proprietary PHP code, malware samples, or sensitive source code.

Frequently Asked Questions