mirror of
https://github.com/scr34m/php-malware-scanner.git
synced 2026-06-16 12:30:35 +00:00
Compare commits
3 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
088c0761b3 | ||
|
|
18b06fc48b | ||
|
|
f1b8b89ca5 |
@@ -16,7 +16,7 @@ opendns
|
||||
phishtank
|
||||
sophos
|
||||
surfright
|
||||
symantec
|
||||
# symantec - removed because already a TLD too so generate many false positives
|
||||
|
||||
# SEO poison, pharmacy redirect
|
||||
dealonline.su
|
||||
@@ -386,4 +386,10 @@ cGhwOi8vaW5wdXQ=
|
||||
explode('?>',$shell
|
||||
|
||||
# common mobile agent check in SEO poison scripts
|
||||
Array("1207", "3gso", "4thp", "501i", "502i", "503i", "504i", "505i", "506i",
|
||||
Array("1207", "3gso", "4thp", "501i", "502i", "503i", "504i", "505i", "506i",
|
||||
|
||||
# eval url decoded string
|
||||
eval(rawurldecode('
|
||||
|
||||
# simple obfuscated gzuncompress
|
||||
'gz'.'unc'.'ompress'
|
||||
@@ -60,7 +60,7 @@ chr\s*\(\s*101\s*\)\s*\.\s*chr\s*\(\s*118\s*\)\s*\.\s*chr\s*\(\s*97\s*\)\s*\.\s*
|
||||
|
||||
#Detects the '_' character encoded in a string like "\x5F". '_' is present in many functions that malware would want to hide.
|
||||
# '_' as "\x5f"
|
||||
\\[Xx](5[Ff])
|
||||
# \\[Xx](5[Ff]) - removed because generate many false positives
|
||||
|
||||
#Detects the '_' character placed inside a call to the 'chr()' function
|
||||
# '_' as 'chr(95)' or 'chr(0x5f)'
|
||||
@@ -135,4 +135,16 @@ explode\('\|\x01\|\x03\|\x03', gzinflate\(
|
||||
@header\(\w{3,5}::\w{1,2}\('_\w{1,3}', '_' \. '\w{1,3}' . '\w{1,3}'\)\);
|
||||
|
||||
# backdoor reported #72
|
||||
@\$[a-z]{1}\[\d+\]\(\$[a-z]{1}\[\d+\]\);
|
||||
@\$[a-z]{1}\[\d+\]\(\$[a-z]{1}\[\d+\]\);
|
||||
|
||||
# reported #77
|
||||
\$[a-z]11 \^ [a-z]8\(\$[a-z]6, \$[a-z]14, \$[a-z]6\[13\]\(\$[a-z]11\)\)\)\);
|
||||
|
||||
# eval function return and concat
|
||||
eval\([A-Za-z]{5,}\(\) \. '
|
||||
|
||||
# eval function return, parameter is a hex string
|
||||
eval\([A-Za-z0-9]{5,}\(\"[A-Z0-9]{16,}
|
||||
|
||||
# gzip payload called by variable named function
|
||||
\$[a-zA-Z0-9]{6,}\('\x78\x9C\xAD\x90\x41\x0E
|
||||
@@ -284,3 +284,5 @@ a54895edc1402cf1b7b5ecd3f5d85e6b wp-includes/formatting.php -> Wordpress Core 6.
|
||||
1e2d246c57d2123aa8938c8263cb1d3d wp-content/plugins/wordpress-seo/admin/tracking/class-tracking-server-data.php -> Yoast SEO plugin 19.2
|
||||
cacb5670ebb2de31976a4b2eb06cac86 wp-content/plugins/worker/src/MWP/ServiceContainer/Abstract.php -> managewp plugin 4.9.14 from managewp.com
|
||||
ffa76b9ff298702a733747521cfdee69 wp-content/plugins/worker/src/MWP/Action/GetState.php -> managewp plugin 4.9.14 from managewp.com
|
||||
ccce5f45d1ac66bd2bebe75d666b5720 wp-content/plugins/redirection/models/regex.php
|
||||
ae810d74d638c611d8bd958777c9ac6a wp-content/plugins/ssl-insecure-content-fixer/includes/nonces.php
|
||||
|
||||
Reference in New Issue
Block a user