diff --git a/malware5.pl b/malware5.pl index 1088a02..0354184 100644 --- a/malware5.pl +++ b/malware5.pl @@ -335,6 +335,8 @@ my @regexen = ( qr/<\?php\s+\$([A-z0-9]{1,20}).+?strtoupper.+?isset\(.+?eval\(.+?\[\'([A-z0-9]{1,20})\'\].+?\?>/is, qr/<\?php\s+\$.+?\'gzu\'.+?array\(.+?eval\(.+?\?>/is, qr/<\?php\s+\$.+?\'bas\'.+?array\(.+?eval\(.+?\?>/is, + qr/<\?php\s+\@eval\(base64\_decode\(([A-z0-9]{20,})\)\)\;\?>/is, + ); diff --git a/malwaresh.pl b/malwaresh.pl index 72012a8..b1b5253 100644 --- a/malwaresh.pl +++ b/malwaresh.pl @@ -816,6 +816,7 @@ my @regexen = ( qr/<\?php\s+\$([A-z0-9]{1,20}).+?strtoupper.+?isset\(.+?eval\(.+?\[\'([A-z0-9]{1,20})\'\].+?\?>/is, qr/<\?php\s+\$.+?\'gzu\'.+?array\(.+?eval\(.+?\?>/is, qr/<\?php\s+\$.+?\'bas\'.+?array\(.+?eval\(.+?\?>/is, + qr/<\?php\s+\@eval\(base64\_decode\(([A-z0-9]{20,})\)\)\;\?>/is, );