diff --git a/malware4.pl b/malware4.pl index a2fef64..310f2ef 100644 --- a/malware4.pl +++ b/malware4.pl @@ -106,6 +106,8 @@ my @regexen = ( qr/include\_once\s+\"3732787075626C69635F68746D6C\.htm\"\;/is, qr/bgeteam\s+<\?php\s+error\_reporting\(0\)\;\s+if\(isset\(\$\_GET\[bge\]\)\).+?else\{echo\"\"\;\}\}\}\s+\?>/is, qr/<\?php\s+\$k=\"ass\"\.\"ert\"\;\s+\$k\(\$\{\"\_PO\"\.\"ST\"\}\s+\[\'wei\'\]\)\;\?>/is, + qr/<\?php\s+function\s+result\(\$data\)\s+\{\s+\$result\=implode\(.+?\$result\=preg\_replace\(.+?if\(isset\(\$\_COOKIE\[\'google\'\]\)\).+?echo\(result\(array\(.+?\?>/is, + qr/<\?php.+?\$e19\s+\=.+?include\_once\(\$H26\)\;\s+\?>/is, );