summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorjvoisin2015-06-30 15:25:10 +0200
committerjvoisin2015-06-30 15:25:10 +0200
commitc2797613ef8a31d23381229cb0cdecc1f0a17f4d (patch)
tree9fe5689bc3331a547157a80361c3c098a2243411
parentc066a4fd993ace9c279ce95d7f60645f5c4a505a (diff)
Replace the $__ rule with the $___ one.
-rw-r--r--malwares.yara2
1 files changed, 1 insertions, 1 deletions
diff --git a/malwares.yara b/malwares.yara
index c421956..3081e15 100644
--- a/malwares.yara
+++ b/malwares.yara
@@ -54,7 +54,7 @@ private rule CloudFlareBypass
54rule ObfuscatedPhp 54rule ObfuscatedPhp
55{ 55{
56 strings: 56 strings:
57 $vars = /\$__+/ // $__ is rarely used in legitimate scripts 57 $vars = /\$___+/ // $__ is rarely used in legitimate scripts
58 $eval = /[;}][\t ]*@?(eval|preg_replace|system|exec)\(/ // ;eval( <- this is dodgy 58 $eval = /[;}][\t ]*@?(eval|preg_replace|system|exec)\(/ // ;eval( <- this is dodgy
59 $align = /(\$\w+=[^;]*)*;\$\w+=@?\$\w+\(/ //b374k 59 $align = /(\$\w+=[^;]*)*;\$\w+=@?\$\w+\(/ //b374k
60 $oneliner = /<\?php\s*\n*\r*\s*(eval|preg_replace|system|exec)\(/ 60 $oneliner = /<\?php\s*\n*\r*\s*(eval|preg_replace|system|exec)\(/