From 6549416df239db70cdb50fd8052189774349b122 Mon Sep 17 00:00:00 2001 From: Malin Date: Wed, 28 Dec 2016 20:34:42 +0100 Subject: [PATCH] Update 'malware3.pl' --- malware3.pl | 2 -- 1 file changed, 2 deletions(-) diff --git a/malware3.pl b/malware3.pl index d109c51..2c2576c 100644 --- a/malware3.pl +++ b/malware3.pl @@ -25,8 +25,6 @@ my @regexen = ( qr//is, qr/<\!\-\-\-\s+Eagle\s+Security\s+Team\-\-\-\->.+?<\!\-\-\-\s+Eagle\s+Security\s+Team\-\-\-\->/is, qr/<\?php\s+if\s+\(isset\(\$\_REQUEST\[\"([A-z0-9]{1,10})\"\]\)\s+AND\s+\$\_REQUEST\[\"([A-z0-9]{1,10})\"\]\=\=\"1\"\)\{echo\s+\"200\"\;\s+exit\;\}\s+if\(isset\(\$\_POST\[\"([A-z0-9]{1,10})\"\]\)\s+\&\&\s+isset\(\$\_POST\[\"([A-z0-9]{1,10})\"\]\)\s+\&\&\s+\$\_POST\[\"([A-z0-9]{1,10})\"\]\=\=.+?\)eval\(gzuncompress\(base64\_decode\(\$\_POST\[\"([A-z0-9]{1,10})\"\]\)\)\)\;\s+\?>/is, - qr/\*\/\s+eval\(base64\_decode\(\"aWY.+?\=\"\)\)\;\s+\/\*/is, - qr/\*\/\s+eval\(base64\_decode\(\"aWY.+?\"\)\)\;\s+\/\*/is, qr/<\?php\s+echo\"trest\"\;error\_reporting\(0\)\;.+?val\(base64\_decode\(\$kk\)\)\;\s+echo\"abrval\"\;\s+\?>/is, qr/<\?php\s+\@preg\_replace\(\$\_SERVER\[\'HTTP\_X\_([A-z0-9]{1,10})\'\]\,\s+\$\_SERVER\[\'HTTP\_X\_CURRENT\'\]\,\s+\'\'\)\;\s+\?>/is, qr/<\?php\s+\/\*\*\s+\*\s+\@version.+?\$b64\s+\=\s+\"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789\+\/\=\"\;.+?\$o3\s+\=\s+\$bits\s+\&\s+0xff\;.+?new\s+JApplication\(arrays+\(\'UID\'\s+\=>\s+\'.+?\'\)\)\;/is,