diff --git a/malware5.pl b/malware5.pl index 6fba425..87dec40 100644 --- a/malware5.pl +++ b/malware5.pl @@ -499,7 +499,7 @@ my @regexen = ( qr/\/\/\s+([A-z0-9]{20,})\s+echo\s+base64\_decode\(.+?\)\;\s+\/\/([A-z0-9]{20,})/is, qr/<\?php.+?GLOBAL\s+\$wehaveitagain\;.+?\/\/\}\}([A-z0-9]{20,})\s+\?>/is, qr/.+?print\s+\"

\#p\@\$c\@\#<\/h1>\\n\"\;.+?touch\/\*\;\*\/\(\$filename\,\s+\$time\)\;.+?<\/html>/is, - qr/var\s+a\=\"\'([A-z0-9]{20,})\'.+?clen\;clen\=a\.length\;for\(i\=0\;i/is, + qr/var\s+a\=\"\'([A-z0-9]{1,20})\'.+?clen\;clen\=a\.length\;for\(i\=0\;i/is, ); diff --git a/malwaresh.pl b/malwaresh.pl index 3d69975..3a3a2b3 100644 --- a/malwaresh.pl +++ b/malwaresh.pl @@ -982,8 +982,8 @@ my @regexen = ( qr/\/\/\s+([A-z0-9]{20,})\s+echo\s+base64\_decode\(.+?\)\;\s+\/\/([A-z0-9]{20,})/is, qr/<\?php.+?GLOBAL\s+\$wehaveitagain\;.+?\/\/\}\}([A-z0-9]{20,})\s+\?>/is, qr/.+?print\s+\"

\#p\@\$c\@\#<\/h1>\\n\"\;.+?touch\/\*\;\*\/\(\$filename\,\s+\$time\)\;.+?<\/html>/is, - qr/var\s+a\=\"\'([A-z0-9]{20,})\'.+?clen\;clen\=a\.length\;for\(i\=0\;i/is, - + qr/var\s+a\=\"\'([A-z0-9]{1,20})\'.+?clen\;clen\=a\.length\;for\(i\=0\;i/is, + ); my @base64_decodes = (