From ff6e3ef0259f933a7c61c3816035b9ae42d66d42 Mon Sep 17 00:00:00 2001 From: jvoisin Date: Thu, 21 May 2015 11:28:51 +0200 Subject: Speed up a rule --- malwares.yara | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/malwares.yara b/malwares.yara index 07c72d9..792c0d2 100644 --- a/malwares.yara +++ b/malwares.yara @@ -54,7 +54,7 @@ private rule CloudFlareBypass rule ObfuscatedPhp { strings: - $vars = /\$_{2,}/ // $__ is rarely used in legitimate scripts + $vars = /\$__*/ // $__ is rarely used in legitimate scripts $eval = /[;}][\t ]*@?(eval|preg_replace|system|exec)\(/ // ;eval( <- this is dodgy $align = /(\$\w+=[^;]*)*;\$\w+=@?\$\w+\(/ //b374k $oneliner = /<\?php\s*\n*\r*\s*(eval|preg_replace|system|exec)\(/ -- cgit v1.3