mirror of
https://github.com/scr34m/php-malware-scanner.git
synced 2026-06-16 12:30:35 +00:00
Compare commits
5 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f0bdb1f1e1 | ||
|
|
43876b337b | ||
|
|
1fad164790 | ||
|
|
f4d53e89d8 | ||
|
|
34ea02323b |
@@ -36,6 +36,7 @@ Usage: php scan.php -d <directory>
|
|||||||
-o --output-format Custom defined output format
|
-o --output-format Custom defined output format
|
||||||
-j --wordpress-version Version of wordpress to get md5 signatures
|
-j --wordpress-version Version of wordpress to get md5 signatures
|
||||||
--combined-whitelist Combined whitelist
|
--combined-whitelist Combined whitelist
|
||||||
|
--custom-whitelist Loads whitelist from specified file and merge with existing
|
||||||
--disable-stats Disable statistics output
|
--disable-stats Disable statistics output
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|||||||
@@ -180,6 +180,7 @@ kZWZpbm
|
|||||||
|
|
||||||
# Obfuscation related code
|
# Obfuscation related code
|
||||||
eval("?>
|
eval("?>
|
||||||
|
eval('?>
|
||||||
"base64_decode"
|
"base64_decode"
|
||||||
='base'.(32*2).'_de'.'code'
|
='base'.(32*2).'_de'.'code'
|
||||||
"p"."r"."e"."g"."_"
|
"p"."r"."e"."g"."_"
|
||||||
@@ -202,6 +203,8 @@ gz'.'inf'.'late
|
|||||||
# fopo.com.ar - free online php obfuscator. It conveniently leaves comments in the code.
|
# fopo.com.ar - free online php obfuscator. It conveniently leaves comments in the code.
|
||||||
http://www.fopo.com.ar/
|
http://www.fopo.com.ar/
|
||||||
@eval("\
|
@eval("\
|
||||||
|
";eval(
|
||||||
|
eval(eval(
|
||||||
|
|
||||||
#Malware/Attack specific strings/fingerprints/signatures
|
#Malware/Attack specific strings/fingerprints/signatures
|
||||||
MagelangCyber
|
MagelangCyber
|
||||||
@@ -374,3 +377,13 @@ ZeroByte
|
|||||||
# SEO poisoning control site call
|
# SEO poisoning control site call
|
||||||
"http://$xxx
|
"http://$xxx
|
||||||
?useragent=$botbotbot
|
?useragent=$botbotbot
|
||||||
|
|
||||||
|
# php://input encoded in base64
|
||||||
|
cGhwOi8vaW5wdXQ=
|
||||||
|
|
||||||
|
# backdoor script
|
||||||
|
<font color="red">Upload Gagal..</font><br />
|
||||||
|
explode('?>',$shell
|
||||||
|
|
||||||
|
# common mobile agent check in SEO poison scripts
|
||||||
|
Array("1207", "3gso", "4thp", "501i", "502i", "503i", "504i", "505i", "506i",
|
||||||
@@ -116,4 +116,20 @@ function\s+_[0-9]{8,}\(
|
|||||||
create_function\s*\(\s*['"]{2}
|
create_function\s*\(\s*['"]{2}
|
||||||
|
|
||||||
# control concated from cookie at the call
|
# control concated from cookie at the call
|
||||||
(\$[a-z]{2,}=urldecode\(\$_COOKIE\['[a-z]{2,}'\]\);){3,}
|
(\$[a-z]{2,}=urldecode\(\$_COOKIE\['[a-z]{2,}'\]\);){3,}
|
||||||
|
|
||||||
|
# ${$O{18}.$O{7}.$O{24}.$O{2}.$O{50}.$O{8}
|
||||||
|
(\$[A-Z]+\{\d+\}\.){3,}
|
||||||
|
|
||||||
|
# comment in variable name $_REQUEST /*YUsrqpbzvXTSa...QpDNTPYQvLSFPCqsSnWNVqPdSIAYaQj*/[
|
||||||
|
\$_REQUEST\s*\/\*[A-Za-z]+\*\/\[
|
||||||
|
|
||||||
|
# cookie payload if(isset($_COOKIE)){$p=$_COOKIE;(count($p)==55&&in_array(gettype($p).count($p),$p))?(($p[68]=$p[68].$p[22])&&($p[35]=$p[68]($p[35]))&&($p=$p[35]($p[13],$p[68]($p[45])))&&$p()):$p;}
|
||||||
|
\(count\(\$p\)==\d+&&in_array\(gettype\(\$p\)\.count\(\$p\),\$p\)\)
|
||||||
|
|
||||||
|
# gzipped payload post process
|
||||||
|
explode\('\|\x01\|\x03\|\x03', gzinflate\(
|
||||||
|
|
||||||
|
# backdoor reported #71
|
||||||
|
@header\(\w{3,5}::\w{1,2}\('_\w{1,3}' \. '\w{1,3}', '_\w{1,3}'\)\);
|
||||||
|
@header\(\w{3,5}::\w{1,2}\('_\w{1,3}', '_' \. '\w{1,3}' . '\w{1,3}'\)\);
|
||||||
|
|||||||
39
scan.php
39
scan.php
@@ -42,6 +42,7 @@ class MalwareScanner
|
|||||||
private $flagScanEverything = false;
|
private $flagScanEverything = false;
|
||||||
private $flagCombinedWhitelist = false;
|
private $flagCombinedWhitelist = false;
|
||||||
private $flagDisableStats = false;
|
private $flagDisableStats = false;
|
||||||
|
private $customWhitelist = array();
|
||||||
private $outputFormat = '';
|
private $outputFormat = '';
|
||||||
private $whitelist = array();
|
private $whitelist = array();
|
||||||
private $ignore = array();
|
private $ignore = array();
|
||||||
@@ -191,16 +192,21 @@ class MalwareScanner
|
|||||||
return $list;
|
return $list;
|
||||||
}
|
}
|
||||||
|
|
||||||
//Loads the whitelist file
|
/**
|
||||||
public function loadWhitelist()
|
* Loads the whitelist files
|
||||||
|
*/
|
||||||
|
public function loadWhitelists()
|
||||||
{
|
{
|
||||||
if (!is_file(__DIR__ . '/whitelist.txt')) {
|
$a = array_merge([__DIR__ . '/whitelist.txt'], $this->customWhitelist);
|
||||||
return;
|
foreach ($a as $file) {
|
||||||
}
|
if (is_file($file)) {
|
||||||
$fp = fopen(__DIR__ . '/whitelist.txt', 'r');
|
$fp = fopen($file, 'r');
|
||||||
while (!feof($fp)) {
|
while (!feof($fp)) {
|
||||||
$line = fgets($fp);
|
$line = fgets($fp);
|
||||||
$this->whitelist[] = substr($line, 0, 32);
|
$this->whitelist[] = substr($line, 0, 32);
|
||||||
|
}
|
||||||
|
fclose($fp);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -248,6 +254,7 @@ class MalwareScanner
|
|||||||
'wordpress-version:',
|
'wordpress-version:',
|
||||||
'scan-everything',
|
'scan-everything',
|
||||||
'combined-whitelist',
|
'combined-whitelist',
|
||||||
|
'custom-whitelist:',
|
||||||
'disable-stats'
|
'disable-stats'
|
||||||
)
|
)
|
||||||
);
|
);
|
||||||
@@ -334,6 +341,13 @@ class MalwareScanner
|
|||||||
if (isset($options['combined-whitelist'])) {
|
if (isset($options['combined-whitelist'])) {
|
||||||
$this->setFlagCombinedWhitelist(true);
|
$this->setFlagCombinedWhitelist(true);
|
||||||
}
|
}
|
||||||
|
if (isset($options['custom-whitelist'])) {
|
||||||
|
$a = $options['custom-whitelist'];
|
||||||
|
if (!is_array($a)) {
|
||||||
|
$a = array($a);
|
||||||
|
}
|
||||||
|
$this->setCustomWhitelist(array_unique($a));
|
||||||
|
}
|
||||||
if (isset($options['disable-stats'])) {
|
if (isset($options['disable-stats'])) {
|
||||||
$this->setFlagDisableStats(true);
|
$this->setFlagDisableStats(true);
|
||||||
}
|
}
|
||||||
@@ -435,6 +449,11 @@ class MalwareScanner
|
|||||||
$this->flagDisableStats = $b;
|
$this->flagDisableStats = $b;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public function setCustomWhitelist($a)
|
||||||
|
{
|
||||||
|
$this->customWhitelist = $a;
|
||||||
|
}
|
||||||
|
|
||||||
// @see http://stackoverflow.com/a/13914119
|
// @see http://stackoverflow.com/a/13914119
|
||||||
private function pathMatches($path, $pattern, $ignoreCase = false)
|
private function pathMatches($path, $pattern, $ignoreCase = false)
|
||||||
{
|
{
|
||||||
@@ -626,7 +645,7 @@ class MalwareScanner
|
|||||||
{
|
{
|
||||||
$this->initializePatterns();
|
$this->initializePatterns();
|
||||||
|
|
||||||
$this->loadWhitelist();
|
$this->loadWhitelists();
|
||||||
|
|
||||||
if ($this->flagCombinedWhitelist && !$this->updateCombinedWhitelist()) {
|
if ($this->flagCombinedWhitelist && !$this->updateCombinedWhitelist()) {
|
||||||
return false;
|
return false;
|
||||||
|
|||||||
Reference in New Issue
Block a user