diff --git a/malware5.pl b/malware5.pl index cd88bb7..539ca2d 100644 --- a/malware5.pl +++ b/malware5.pl @@ -453,6 +453,7 @@ my @regexen = ( qr/<\?\s+eval\(gzinflate\(str\_rot13\(base64\_decode\(.+?\)\)\)\)\;\s+\?>/is, qr/<\?php.+?\?>([A-z0-9]{1,20})\%([A-z0-9]{1,20})\%.+?\$([A-z0-9]{1,20})\=\$([A-z0-9]{1,20})\-1\;\s+\?>/is, qr/<\?php.+?\$([A-z0-9]{1,20})\=\(([0-9]{1,5})\-([0-9]{1,5})\)\;\s+\$([A-z0-9]{1,20})\=\$([A-z0-9]{1,20})\-1\;\s+\?>/is, + qr/<\?php\s+if\(\@isset\(\$\_SERVER\[HTTP\_.+?\]\)\)\{\@eval\(base64\_decode\(\$\_SERVER\[.+?\]\)\)\;\}exit\;\?>.+?sites\/libasset\.php/is, ); diff --git a/malwaresh.pl b/malwaresh.pl index 816b931..92c2004 100644 --- a/malwaresh.pl +++ b/malwaresh.pl @@ -936,6 +936,7 @@ my @regexen = ( qr/<\?php\s+Error\_Reporting\(E\_ALL.+?