From 4d5013ecf6631a8110e473ffd16f422d8cb14bf1 Mon Sep 17 00:00:00 2001 From: Palma Solutions LTD Date: Fri, 7 Sep 2018 11:52:49 +0200 Subject: [PATCH] new patterns --- malware6.pl | 10 +++++++++- malwaresh.pl | 8 ++++++++ 2 files changed, 17 insertions(+), 1 deletion(-) diff --git a/malware6.pl b/malware6.pl index 2a1a938..bbad110 100644 --- a/malware6.pl +++ b/malware6.pl @@ -288,7 +288,15 @@ my @regexen = ( qr/\@eval\(base64_decode\(\$_REQUEST\[\'c_id\'\]\)\)/is, qr/<\?php if\(\$_GET\[\'test\'\]\)\{echo \'success\';\}else\{\(\$www= \$_POST\[\'([A-z0-9_]{1,20})\'\]\) && \@preg_replace\(\'\/ad\/e\',\'@\'\.str_rot13\(\'riny\'\)\.\'\(\$www\)\', \'add\'\);\}/is, qr/<\?php \$\{\"\\x47\\x4c\\x4fB\\x41\\x4c\\x53\"\}\[.+?eval\(\$([A-z0-9]{1,20})\[\$GLOBALS\[\'([A-z0-9]{1,20})\'\]\[([0-9]{1,5})\]\]\);\s+\}\s+exit\(\);\s+\}\s+\}/is, - + qr/<\?php \/\*([A-z0-9_]{1,20})\*\/ error_reporting\(0\); \@ini_set\(\'error_log\',NULL\); \@ini_set\(\'log_errors\',0\); \@ini_set\(\'display_errors\',\'Off\'\); \@eval\( base64_decode\(\'aWYo.+?\)\); \@ini_restore\(\'error_log\'\); \@ini_restore\(\'display_errors\'\); \/\*([A-z0-9_]{1,20})\*\/ \?>/is, + qr/