mirror of
https://github.com/scr34m/php-malware-scanner.git
synced 2026-06-16 12:30:35 +00:00
Remove too regular patterns
This commit is contained in:
43
scan.php
43
scan.php
@@ -161,6 +161,7 @@ class MalwareScanner
|
|||||||
'\x65\x76\x61\x6C' /* case, dec/hex issue? */,
|
'\x65\x76\x61\x6C' /* case, dec/hex issue? */,
|
||||||
'ZXZhbCg', // eval
|
'ZXZhbCg', // eval
|
||||||
"'ev'.'al'.'",
|
"'ev'.'al'.'",
|
||||||
|
'/eval\s*\(/i',
|
||||||
|
|
||||||
'eval(base64_decode(',
|
'eval(base64_decode(',
|
||||||
'\x47\x4c\x4f\x42\x41LS', // GLOBALS
|
'\x47\x4c\x4f\x42\x41LS', // GLOBALS
|
||||||
@@ -175,31 +176,27 @@ class MalwareScanner
|
|||||||
/* too open? */
|
/* too open? */
|
||||||
// 'gzinflate(base64_decode(',
|
// 'gzinflate(base64_decode(',
|
||||||
'md5($_GET[', // md5($_GET["ms-load"])
|
'md5($_GET[', // md5($_GET["ms-load"])
|
||||||
'sendMail',
|
'/ShellBOT/i',
|
||||||
'echo "ok-ok"',
|
'/YW55cmVzdWx0cy5uZXQ=/i',
|
||||||
'/ShellBOT/i',
|
'/base64_decode\s*\(/i',
|
||||||
'/YW55cmVzdWx0cy5uZXQ=/i',
|
'/str_rot13/i',
|
||||||
'/eval\s*\(/i',
|
'/uudecode/i',
|
||||||
'/base64_decode\s*\(/i',
|
'/preg_replace',
|
||||||
'/str_rot13/i',
|
'bgeteam',
|
||||||
'/uudecode/i',
|
'DisablePHP=',
|
||||||
'/preg_replace',
|
'=urldecode',
|
||||||
'bgeteam',
|
'moban.html',
|
||||||
'DisablePHP=',
|
'<?php eval',
|
||||||
'=urldecode',
|
'$data = base64_decode("',
|
||||||
'moban.html',
|
'a,b,c,d,e,f,g',
|
||||||
'<?php eval',
|
|
||||||
'$data = base64_decode("',
|
|
||||||
|
|
||||||
'a,b,c,d,e,f,g',
|
|
||||||
' freetellafriend.com',
|
' freetellafriend.com',
|
||||||
'SHELL_PASSWORD',
|
'SHELL_PASSWORD',
|
||||||
'curl_get_from_webpage',
|
'curl_get_from_webpage',
|
||||||
'base=base64_encode',
|
'base=base64_encode',
|
||||||
'@x0powo',
|
'@x0powo',
|
||||||
'@preg_replace',
|
'@preg_replace',
|
||||||
'1@1.com',
|
'1@1.com',
|
||||||
'META http-equiv="refresh" content="0;',
|
'META http-equiv="refresh" content="0;',
|
||||||
'="create_";global'
|
'="create_";global'
|
||||||
);
|
);
|
||||||
if ($this->ExtraCheck) {
|
if ($this->ExtraCheck) {
|
||||||
|
|||||||
Reference in New Issue
Block a user