Skip to content

Commit 3adfd30

Browse files
authored
Merge pull request #378 from ruppde/fix-from-discord
Update gen_webshells.yar
2 parents a27a0de + cc1fa71 commit 3adfd30

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

yara/gen_webshells.yar

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1016,7 +1016,7 @@ rule WEBSHELL_PHP_OBFUSC
10161016
reference = "Internal Research"
10171017
score = 75
10181018
date = "2021/01/12"
1019-
modified = "2025-07-09"
1019+
modified = "2025-09-22"
10201020
hash = "eec9ac58a1e763f5ea0f7fa249f1fe752047fa60"
10211021
hash = "181a71c99a4ae13ebd5c94bfc41f9ec534acf61cd33ef5bce5fb2a6f48b65bf4"
10221022
hash = "76d4e67e13c21662c4b30aab701ce9cdecc8698696979e504c288f20de92aee7"
@@ -1040,6 +1040,8 @@ rule WEBSHELL_PHP_OBFUSC
10401040
$gfp11 = "(eval (getenv \"EPROLOG\")))"
10411041
$gfp12 = "ZmlsZV9nZXRfY29udGVudHMoJ2h0dHA6Ly9saWNlbnNlLm9wZW5jYXJ0LWFwaS5jb20vbGljZW5zZS5waHA/b3JkZXJ"
10421042
$gfp13 = "assert(\\\""
1043+
$gfp14 = "PhutilUTF8TestCase"
1044+
$gfp15 = "chr(195).chr(128) => 'A'," // 3d413ceb54e929d6af2e64ebb8df7ba2452a7aac876dddcf6336c3445e7bcc91, wordpress formatter.php
10431045
10441046
//strings from private rule capa_php_old_safe
10451047
$php_short = "<?" wide ascii

0 commit comments

Comments
 (0)