diff --git a/definitions/patterns_re.txt b/definitions/patterns_re.txt index 88aaf39..bde45be 100644 --- a/definitions/patterns_re.txt +++ b/definitions/patterns_re.txt @@ -66,3 +66,9 @@ chr\s*\(\s*['"]?\s*((95)|(0[Xx]5[Ff]))\s*['"]?\s*\) #We can increase from 1100 later if we need to. #Long single line of PHP. ^.*<\?php.{1100,}\?>.*$ + +#Escaped path characters: \x2fho\x6de/\x69mp\x75ls\x69oq\x65/w\x77w. or \x2fhome\x2fimpu\x6csioq\x65/www\x2emusc +(\\x[0-9abcdef]{2}[a-z0-9.-\/]{1,4}){4,} + +#Malware inffected files sometimes marked with comments like /*87cda*/ to avoid infect again +\/\*[a-z0-9]{5}\*\/