From 151df82b335d467335ff1af16f270cbec63329f5 Mon Sep 17 00:00:00 2001 From: Malin Date: Thu, 22 Sep 2016 09:46:19 +0200 Subject: [PATCH] Upload files to '' --- clean.php | 625 ++++++++++++++++++++++++++++++++++++++++++++++++++++ collate.php | 132 +++++++++++ findbot.pl | 227 +++++++++++++++++++ malware.pl | 268 ++++++++++++++++++++++ malware2.pl | 353 +++++++++++++++++++++++++++++ 5 files changed, 1605 insertions(+) create mode 100644 clean.php create mode 100644 collate.php create mode 100644 findbot.pl create mode 100644 malware.pl create mode 100644 malware2.pl diff --git a/clean.php b/clean.php new file mode 100644 index 0000000..f1f1b99 --- /dev/null +++ b/clean.php @@ -0,0 +1,625 @@ +", +"<\?php\s*\W.*([a-zA-Z0-9]{10}).*\s*=\s*\'(.*)\/epreg_replace(.*)explode\(chr\(\((.*)-1; ?>", +"<\/script>", +"<\?php\s*\W(.*)=\s*array\(\'(.*)=\s*array\(\'(.*)=\s*array\(\'(.*)==\";if\s*\(\Wfunction_exists\(\"(.*)\);\}\?>", +"<\!--.*([a-zA-Z0-9]{6}).*--><\/script><\!--\/.*([a-zA-Z0-9]{6}).*-->", +"eval\(base64_decode\(\W_POST\[\'.*([a-zA-Z0-9]{7}).*\'\]\)\);", +"<\/iframe>", +"\s*\(function\(\)\{var\s*agent\s*\=\s*navigator\.userAgent;(.*)\{location\.href\s*\=\s*\'http\:\/\/bit\.ly\/1aMmdYs\';\}\}\)\(\)\s*<\/script>", +"if\(document.loaded\)\s*\{\s*showBrowVer\(\);(.*)js_kod2\);\s*\}\s*\}\s*\}<\/script>", +"<\?php\s*\/\/\s*The\s*JS\s*here(.*)Eabi.p\!\'\s*\)\s*\);", +"<\/embed>", +"ErrorDocument(.*)http\:\/\/congatarcxisi.ru\/mays\/index.php", +"<\/iframe>", +"", +"<\?php\s*if\s*\(\Wisset(.*)aHR0cDovL21icm93c2Vyc3RhdHMuY29tL3N0YXRIL3N0YXQucGhw(.*)stCurlHandle\);\s*\}\s*\}\s*\?>", +"<\/iframe>", +"", +"<\?php\s*\W.*([a-zA-Z0-9]{5}).*=\s*\"(.*)exit\(\);\s*\}\s*\?>", +"", +"<\?php\s*\W.*([a-zA-Z0-9]{4}).*=\s*\"(.*)echo\s*\W.*([a-zA-Z0-9]{6}).*;\s*exit\(\);\s*\}\s*\?>", +"<\?php\s*\W.*([a-zA-Z0-9]{10}).*=\s*\'(.*)=\W.*([a-zA-Z0-9]{10}).*-1;\s*\?>", +"", +"<\!DOCTYPE(.*)BreezeBrowser(.*)printFullsizeContent\(\)(.*)<\/html>", +"\s*var\s*\_0x2b7d(.*)0x2b7d\[8\]\]\(hs\);\s*<\/script>", +"<\/iframe>", +"<\?PHP\s*\/\*\s*GNU(.*)gnu=false;\s*\}\s*\?>", +"\#c3284d\#(.*)\#\/c3284d\#", +"<\?php\s*if\s*\(isset\(\W_POST\[\"code\"\]\)\)\s*eval\(base64_decode\(\W_POST\[\"code\"\]\)\);\s*\?>", +"<\?\Wtds\=\"http\:\/\/(.*)\}\?>", +"\s*RewriteEngine\s*On\s*RewriteCond\s*\%\{HTTP_REFERER\}\s*\^\.\*\(google\|ask\|(.*)RewriteRule\s*\^\(\.\*\)\W\s*http\:\/\/datinginstallshield.ru\/pavilion\?8\s*\[R\=301,L\]", +"<\?\Wtds\=\"http\:\/\/(.*)echo\s*\Wx;\}\?>", +"<\?PHP\s*defined\(\'_OLD_JEXEC_\'\)\s*or\s*die\(@eval\(base64_decode\(\W_REQUEST\[\'(.*)\'\]\)\)\);\s*\?>", +"<\?php\s*\W.*([a-zA-Z0-9]{5}).*\s*=\s*\"(.*)exit\(\);\s*\}\s*\?>", +"^<\?php\s*\Whaikzdiigp(.*)quegvtluws\-1;\s*\?>", +"\/\*.*([a-zA-Z0-9]{6}).*\*\/(.*)\/\*\/.*([a-zA-Z0-9]{6}).*\*\/", +"\/\*63aef4\*\/(.*)\/\*\/63aef4\*\/", +"<\?PHP\s*\/\/Authentication(.*)eval\(gzinflate\(base64_decode\((.*)8A\'\)\)\);\s*\?>", +"<\?\s*error_reporting\(0\);\W\w=\(isset\(\W_SERVER\[\"HTTP_HOST\"\]\)(.*)curl_exec\(\W\w\w\);curl_close\(\W\w\w\);eval\(\W\w\);\};die\(\);\s*\?>", +"RewriteCond\s*\%\{HTTP_USER_AGENT\}\s*android\s*\[NC\,OR\](.*)\.php\s*\[L\,R\=302\]", +"<\?php(.*)if\(isset\(\W_REQUEST\[\'(.*)eval\((.*)exit\(\);\s*\}\s*if\(isset\(\W_REQUEST\[\'(.*)fopen\((.*)fwrite\((.*)fclose\((.*)exit\(\);\s*\}\s*\?>", +"<\!\-\-1c1c7d\-\->(.*)<\!\-\-\/1c1c7d\-\->", +"