From 1c4d711daf1f01a2eaee5dc528932441105caf4f Mon Sep 17 00:00:00 2001 From: Malin Date: Thu, 29 Dec 2016 20:31:15 +0100 Subject: [PATCH] Update 'malware3.pl' --- malware3.pl | 1 + 1 file changed, 1 insertion(+) diff --git a/malware3.pl b/malware3.pl index 984a8ea..c053750 100644 --- a/malware3.pl +++ b/malware3.pl @@ -23,6 +23,7 @@ my @regexen = ( qr/<\?php\s+function\s+([A-z0-9]{1,10})\(\$([A-z0-9]{1,10})\,\s+\$([A-z0-9]{1,10})\)\{\$([A-z0-9]{1,10})\s+\=\s+\'\'\;\s+for\(\$([A-z]{1,2})\=0\;\s+\$([A-z]{1,2})\s+\<\s+strlen\(\$([A-z0-9]{1,10})\)\;\s+\$([A-z]{1,2})\+\+\)\{\$([A-z0-9]{1,10})\s+\.\=\s+isset\(\$([A-z0-9]{1,10})\[\$([A-z0-9]{1,10})\[\$([A-z]{1,2})\]\]\)\s+\?\s+\$([A-z0-9]{1,10})\[\$([A-z0-9]{1,10})\[\$([A-z]{1,2})\]\]\s+\:\s+\$([A-z0-9]{1,10})\[\$([A-z]{1,2})\]\;\}\s+\$([A-z0-9]{1,10})\=\"base64\_decode\"\;return\s+\$([A-z0-9]{1,10})\(\$([A-z0-9]{1,10})\)\;\}.+?\$([A-z]{1,2})\s+\=\s+\Array\(.+?eval\(([A-z0-9]{1,10})\(\$([A-z]{1,2})\,\s+\$([A-z]{1,2})\)\)\;\?>/is, qr/<\?php\s+\$([A-z0-9]{1,10})\=\'aWYoaXNzZXQoJF9SRVFVRVNUWydjb2NvJ10pICYmICRfUkVRVUVTVFsnY29jbyddIT0nJyl7ZXZhbCgkX1JFUVVFU1RbJ2NvY28nXSk7ZXhpdCgpO30\=\'\;eval\(base64\_decode\(\$([A-z0-9]{1,10})\)\)\;exit\(\)\;\s+\?>/is, qr//is, + qr/<\?php\s+if\(isset\(\$\_GET\[\'test\'\]\)\)\{echo\s+\'success\'\;\}else\{isset\(\$\_POST\[\'([A-z0-9]{1,10})\'\]\)\s+\&\&\s+\(\$www\=\s+\$\_POST\[\'([A-z0-9]{1,10})\'\]\)\s+\&\&\s+\@preg\_replace\(\'\/ad\/e\'\,\'\@\'\.str\_rot13\(\'riny\'\)\.\'\(\$www\)\'\,\s+\'add\'\)\;\}\?>/is, qr/<\?php\s+\$([A-z0-9]{1,20}).+?\$([A-z0-9]{1,20})\s+\=\s+implode\(array\_map\(.+?\$([A-z0-9]{1,20})\=strtolower\(\$\_SERVER\[.+?\$([A-z0-9]{1,20})\-1\;\s+\?>/is, qr/<\!\-\-\-\s+Eagle\s+Security\s+Team\-\-\-\->.+?<\!\-\-\-\s+Eagle\s+Security\s+Team\-\-\-\->/is, qr/<\?php\s+echo\"trest\"\;error\_reporting\(0\)\;.+?val\(base64\_decode\(\$kk\)\)\;\s+echo\"abrval\"\;\s+\?>/is,