| Server IP : 101.53.144.229 / Your IP : 216.73.216.104 Web Server : Apache System : Linux host.gdigitalindia.in 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64 User : digitalshiksha ( 1179) PHP Version : 5.6.40 Disable Function : eval,show_source,system,shell_exec,escapeshellarg,escapeshellcmd,proc_close,proc_open,ini_alter,dl,show_source,curl_multi_exechellcmd, ini_restore,apache_get_modules,get_cfg_var,passthru, exec ,proc_get_status,fpassthru,c999_buff_prepare,c999_sess_put,c99_buff_prepare,c99_sess_put,proc_close,ini_alter,dl,symlink,link,proc_close,ini_alter,dl,symlink,link,mail MySQL : ON | cURL : ON | WGET : ON | Perl : ON | Python : ON | Sudo : ON | Pkexec : ON Directory : /var/imunify360/files/sigs/v1/heuristic/ |
Upload File : |
// import "math"
include "webshells.yara"
/*private global rule size_limit
{
condition:
filesize < 1MB
}
private rule is_php
{
strings:
$str = /<\?(php|\s)/
condition:
(filesize < 1MB) and $str
}
private rule php_keywords_rate {
strings:
$keyword = /\b(this|if|return|function|else|array|false|true)\b/
condition:
is_php and math.divide(#keyword, filesize) > 0.001
}
rule php_packed
{
strings:
$func1 = /base64_decode\s*\(/
$func2 = /eval\s*\(/
$func3 = /\$[a-zA-Z0-9_]+\(/
condition:
is_php and (($func1 and $func2) or $func3) and (math.entropy(0, filesize) >= 5.00) and not php_keywords_rate //5.81
}
*./