diff --git a/malware6.pl b/malware6.pl index e8236dd..7fd921b 100644 --- a/malware6.pl +++ b/malware6.pl @@ -227,6 +227,7 @@ my @regexen = ( qr/<\?\s+if\(!empty\(\$_SERVER\[\'HTTP_USER_AGENT\'\]\)\) \{.+?move_uploaded_file\(\$_FILES\[.+?fotTKL\(\$gaza_text,\$gaza_text1,\$dir\);\s+\?>/is, qr/<\?php \$([A-z0-9_]{1,20}) = array\(.+?array\(\'ba\' ,\'se\' ,\'64\' ,\'_d\' ,\'ec\' ,\'od\' ,\'e\'\); \$([A-z0-9_]{1,20}) = array\(\'gzun\', \'comp\', \'ress\'\) ;\$([A-z0-9_]{1,20}) = .+?eval.+?\) \) \) \) ; \?>/is, qr/<\?php \$([A-z0-9_]{1,20}) = \'s\'\.chr\(116\)\.\'rrev\';\$([A-z0-9_]{1,20}) = array\(\'.+?\);eval\(\$([A-z0-9_]{1,20})\(\$([A-z0-9_]{1,20})\(\$([A-z0-9_]{1,20})\(\'\',\$([A-z0-9_]{1,20})\)\)\)\); \?>/is, + qr/\/\*([A-z0-9]{1,6})\*\/\s+\@include \"\\([A-z0-9]{1,6})\\([A-z0-9]{1,6})\\([A-z0-9]{1,6}).+?([A-z0-9]{1,6})\\([A-z0-9]{1,6})\";\s+\/\*([A-z0-9]{1,6})\*\//is, diff --git a/malwaresh.pl b/malwaresh.pl index 53d1ac4..9b84406 100644 --- a/malwaresh.pl +++ b/malwaresh.pl @@ -1215,6 +1215,7 @@ my @regexen = ( qr/<\?\s+if\(!empty\(\$_SERVER\[\'HTTP_USER_AGENT\'\]\)\) \{.+?move_uploaded_file\(\$_FILES\[.+?fotTKL\(\$gaza_text,\$gaza_text1,\$dir\);\s+\?>/is, qr/<\?php \$([A-z0-9_]{1,20}) = array\(.+?array\(\'ba\' ,\'se\' ,\'64\' ,\'_d\' ,\'ec\' ,\'od\' ,\'e\'\); \$([A-z0-9_]{1,20}) = array\(\'gzun\', \'comp\', \'ress\'\) ;\$([A-z0-9_]{1,20}) = .+?eval.+?\) \) \) \) ; \?>/is, qr/<\?php \$([A-z0-9_]{1,20}) = \'s\'\.chr\(116\)\.\'rrev\';\$([A-z0-9_]{1,20}) = array\(\'.+?\);eval\(\$([A-z0-9_]{1,20})\(\$([A-z0-9_]{1,20})\(\$([A-z0-9_]{1,20})\(\'\',\$([A-z0-9_]{1,20})\)\)\)\); \?>/is, + qr/\/\*([A-z0-9]{1,6})\*\/\s+\@include \"\\([A-z0-9]{1,6})\\([A-z0-9]{1,6})\\([A-z0-9]{1,6}).+?([A-z0-9]{1,6})\\([A-z0-9]{1,6})\";\s+\/\*([A-z0-9]{1,6})\*\//is,