Update 'malware3.pl'
This commit is contained in:
parent
afb9ff928a
commit
577125e266
@ -23,6 +23,7 @@ my @regexen = (
|
||||
qr/<\?php\s+function\s+([A-z0-9]{1,10})\(\$([A-z0-9]{1,10})\,\s+\$([A-z0-9]{1,10})\)\{\$([A-z0-9]{1,10})\s+\=\s+\'\'\;\s+for\(\$([A-z]{1,2})\=0\;\s+\$([A-z]{1,2})\s+\<\s+strlen\(\$([A-z0-9]{1,10})\)\;\s+\$([A-z]{1,2})\+\+\)\{\$([A-z0-9]{1,10})\s+\.\=\s+isset\(\$([A-z0-9]{1,10})\[\$([A-z0-9]{1,10})\[\$([A-z]{1,2})\]\]\)\s+\?\s+\$([A-z0-9]{1,10})\[\$([A-z0-9]{1,10})\[\$([A-z]{1,2})\]\]\s+\:\s+\$([A-z0-9]{1,10})\[\$([A-z]{1,2})\]\;\}\s+\$([A-z0-9]{1,10})\=\"base64\_decode\"\;return\s+\$([A-z0-9]{1,10})\(\$([A-z0-9]{1,10})\)\;\}.+?\$([A-z]{1,2})\s+\=\s+\Array\(.+?eval\(([A-z0-9]{1,10})\(\$([A-z]{1,2})\,\s+\$([A-z]{1,2})\)\)\;\?>/is,
|
||||
qr/<\?php\s+\$([A-z0-9]{1,10})\=\'aWYoaXNzZXQoJF9SRVFVRVNUWydjb2NvJ10pICYmICRfUkVRVUVTVFsnY29jbyddIT0nJyl7ZXZhbCgkX1JFUVVFU1RbJ2NvY28nXSk7ZXhpdCgpO30\=\'\;eval\(base64\_decode\(\$([A-z0-9]{1,10})\)\)\;exit\(\)\;\s+\?>/is,
|
||||
qr/<script.+?G91825.+?<\/script>/is,
|
||||
qr/<\?php\s+\$dom\s+\=\s+array\(.+?header\(\'Location\:\s+\'\.\$url\)\;\s+\}\s+exit\;\s+\?>/is,
|
||||
qr/<\?php\s+if\s+\(isset\(\$\_REQUEST\[\"([A-z0-9]{1,10})\"\]\)\s+AND\s+\$\_REQUEST\[\"([A-z0-9]{1,10})\"\]\=\=\"1\"\)\{echo\s+\"200\"\;\s+exit\;\}\s+if\(isset\(\$\_POST\[\"([A-z0-9]{1,10})\"\]\)\s+\&\&\s+isset\(\$\_POST\[\"([A-z0-9]{1,10})\"\]\)\s+\&\&\s+\$\_POST\[\"([A-z0-9]{1,10})\"\]\=\=.+?\)eval\(gzuncompress\(base64\_decode\(\$\_POST\[\"([A-z0-9]{1,10})\"\]\)\)\)\;\s+\?>/is,
|
||||
qr/\*\/\s+eval\(base64\_decode\(\"aWY.+?\=\"\)\)\;\s+\/\*/is,
|
||||
qr/\*\/\s+eval\(base64\_decode\(\"aWY.+?\"\)\)\;\s+\/\*/is,
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user