From dc991c192fedee7c9698e74cde935f0583abd2bd Mon Sep 17 00:00:00 2001 From: Malin Date: Sat, 22 Apr 2017 11:34:38 +0200 Subject: [PATCH] Update 'malware4.pl' --- malware4.pl | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/malware4.pl b/malware4.pl index 40be72c..f299248 100644 --- a/malware4.pl +++ b/malware4.pl @@ -84,7 +84,7 @@ my @regexen = ( qr/\/\*edition\:1\.6\*\/.+?\;eval\(gzuncompress\(base64\_decode\(\$([A-z0-9]{1,20})\)\)\)\;/is, qr/<\?php\s+\$([A-z0-9]{1,20})\=.+?\$([A-z0-9]{1,20})\=call\_user\_func\(.+?\)\;\s+\$([A-z0-9]{1,20})\=call\_user\_func\(.+?\)\;\s+eval\(\$([A-z0-9]{1,20})\)\;/is, qr/<\?php\s+\$([A-z0-9]{1,20})\=\".+?\"\;\$([A-z0-9]{1,20})\=call\_user\_func\(\$.+?\)\;\$([A-z0-9]{1,20})\=call\_user\_func\(\$.+?\)\;eval\(\$([A-z0-9]{1,20})\)\;/is, - + qr/var\s+\_0xaae8\=\[\"\"\,\".+?\"\]\;document\[\_0xaae8\[5\]\]\(\_0xaae8\[4\]\[\_0xaae8\[3\]\]\(\_0xaae8\[0\]\)\[\_0xaae8\[2\]\]\(\)\[\_0xaae8\[1\]\]\(\_0xaae8\[0\]\)\)/is, ); my @base64_decodes = (