Update 'malware4.pl'

This commit is contained in:
Malin 2017-01-19 21:09:21 +01:00
parent 5e6a19b826
commit ef075ea2e2

View File

@ -43,6 +43,7 @@ my @regexen = (
qr/<\?\s+\$([A-z0-9]{1,3})\[1\]\=\"([A-z0-9]{1,20})\.html\"\;\$([A-z0-9]{1,3})\[1\]\=.+?file\_put\_contents\(\$fileaddr\,gzuncompress\(base64\_decode\(\$([A-z0-9]{1,3})\[\$([A-z0-9]{1,3})\]\)\)\)\;\}\s+unlink\(\$scr\.\"\.php\"\)\;\s+\?>/is,
qr/<\?php\s+\$GLOBALS\[\'([A-z0-9]{1,20})\'\]\s+\=\s+\$\_SERVER\;\s+function\s+([A-z0-9]{1,20})\(\$([A-z0-9]{1,20})\).+?exit\(\$\{([A-z0-9]{1,20})\(\"lie\=\=\?\"\)\}\)\;\s+\}/is,
qr/eval\(base64\_decode\(\"aWY.+?include.+?eval\(base64\_decode\(\"aWY.+?include.+?ephp\"\;/is
qr/<\?php\s+\/\*\s+ionCube24\s+encoder\s+\*\/\s+global\s+\$g\;\s+eval\(base64\_decode\(file\_get\_contents\(\_\_FILE\_\_\,null\,null\,.+?\_\_halt\_compiler\(\).+?\Z/is,
);
my @base64_decodes = (