📜 ⬆️ ⬇️

FBI, CIA and Obama against PHP script

A report was published on the virus with which the “Russian hackers,” according to the US intelligence, hacked the American elections. The virus (more precisely, its unique signature) looks like this:

rule PAS_TOOL_PHP_WEB_KIT { meta: description = "PAS TOOL PHP WEB KIT FOUND" strings: $php = "<?php" $base64decode = /\='base'\.\(\d+\*\d+\)\.'_de'\.'code'/ $strreplace = "(str_replace(" $md5 = ".substr(md5(strrev(" $gzinflate = "gzinflate" $cookie = "_COOKIE" $isset = "isset" condition: (filesize > 20KB and filesize < 22KB) and #cookie == 2 and #isset == 3 and all of them } 

I do not even know how to comment on this, of course, unique and uniquely identifiable as a Russian code.

')

Source: https://habr.com/ru/post/318792/


All Articles