gwillem / magento-malware-scanner

Scanner, signatures and the largest collection of Magento malware
GNU General Public License v3.0
680 stars 153 forks source link

Add Rarog/Flashpoint Rule #198

Closed jonashrem closed 6 years ago

jonashrem commented 6 years ago

As far as I see, those are not included yet.

See here https://www.flashpoint-intel.com/blog/compromised-magento-sites-delivering-malware/ and https://www.flashpoint-intel.com/wp-content/uploads/2018/04/rarog_yara_rule.txt

for details.

I'm not sure about the best way to convert this to regex here, so I didn't create a pull request.

gwillem commented 6 years ago

Thanks! Have added a burner domain (with about 1K occurrences). The rest was already covered or not found in the wild (anymore).