Pattern updates from new infections

This commit is contained in:
Gabor Gyorvari
2021-05-27 06:38:53 +02:00
parent 34ea02323b
commit f4d53e89d8
2 changed files with 19 additions and 1 deletions

View File

@@ -180,6 +180,7 @@ kZWZpbm
# Obfuscation related code
eval("?>
eval('?>
"base64_decode"
='base'.(32*2).'_de'.'code'
"p"."r"."e"."g"."_"
@@ -202,6 +203,8 @@ gz'.'inf'.'late
# fopo.com.ar - free online php obfuscator. It conveniently leaves comments in the code.
http://www.fopo.com.ar/
@eval("\
";eval(
eval(eval(
#Malware/Attack specific strings/fingerprints/signatures
MagelangCyber
@@ -374,3 +377,9 @@ ZeroByte
# SEO poisoning control site call
"http://$xxx
?useragent=$botbotbot
# php://input encoded in base64
cGhwOi8vaW5wdXQ=
# backdoor script
<font color="red">Upload Gagal..</font><br />

View File

@@ -116,4 +116,13 @@ function\s+_[0-9]{8,}\(
create_function\s*\(\s*['"]{2}
# control concated from cookie at the call
(\$[a-z]{2,}=urldecode\(\$_COOKIE\['[a-z]{2,}'\]\);){3,}
(\$[a-z]{2,}=urldecode\(\$_COOKIE\['[a-z]{2,}'\]\);){3,}
# ${$O{18}.$O{7}.$O{24}.$O{2}.$O{50}.$O{8}
(\$[A-Z]+\{\d+\}\.){3,}
# comment in variable name $_REQUEST /*YUsrqpbzvXTSa...QpDNTPYQvLSFPCqsSnWNVqPdSIAYaQj*/[
\$_REQUEST\s*\/\*[A-Za-z]+\*\/\[
# cookie payload if(isset($_COOKIE)){$p=$_COOKIE;(count($p)==55&&in_array(gettype($p).count($p),$p))?(($p[68]=$p[68].$p[22])&&($p[35]=$p[68]($p[35]))&&($p=$p[35]($p[13],$p[68]($p[45])))&&$p()):$p;}
\(count\(\$p\)==\d+&&in_array\(gettype\(\$p\)\.count\(\$p\),\$p\)\)