↑ ↓ select, Enter open, Esc close

Search PHP files for typical malware patterns

Adjust the values, the command updates live
user@server
grep -rlE --include='*.php' 'eval\((base64_decode|gzinflate|gzuncompress|str_rot13)\(' /var/www/vhosts/example.com/httpdocs

Recursively searches all PHP files for code that decodes obfuscated data and executes it directly. This combination is typical of web shells and injected malicious code and rarely appears in clean code. Only the file names of matches are printed.

Note: This does not replace a malware scanner and does not find every variant. Look closely at matches in well-known libraries before deleting anything.

Also searched as

  • find eval base64_decode in php files
  • scan website for php malware
  • search for obfuscated php code

Related one-liners

All in Security

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.