From d8ad70a5c5bc621289d6d38c64525bb2b8dca9c0 Mon Sep 17 00:00:00 2001 From: jvoisin Date: Fri, 22 May 2015 09:43:31 +0200 Subject: Fix a mistake --- malwares.yara | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/malwares.yara b/malwares.yara index deb5f5f..25ba196 100644 --- a/malwares.yara +++ b/malwares.yara @@ -54,7 +54,7 @@ private rule CloudFlareBypass rule ObfuscatedPhp { strings: - $vars = /\$__*/ // $__ is rarely used in legitimate scripts + $vars = /\$__+/ // $__ is rarely used in legitimate scripts $eval = /[;}][\t ]*@?(eval|preg_replace|system|exec)\(/ // ;eval( <- this is dodgy $align = /(\$\w+=[^;]*)*;\$\w+=@?\$\w+\(/ //b374k $oneliner = /<\?php\s*\n*\r*\s*(eval|preg_replace|system|exec)\(/ -- cgit v1.3