HEX
Server: LiteSpeed
System: Linux php-prod-3.spaceapp.ru 5.15.0-151-generic #161-Ubuntu SMP Tue Jul 22 14:25:40 UTC 2025 x86_64
User: sarli3128 (1010)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: //var/imunify360/files/sigs/v1_2025-08-14T004336.228295Z/heuristic/main.yara
// import "math"
include "webshells.yara"

/*private  global rule size_limit
{
    condition:
        filesize < 1MB
        
}

private rule is_php
{
    strings:
        $str = /<\?(php|\s)/

    condition:
        (filesize < 1MB) and $str
}

private rule php_keywords_rate {
    strings:
        $keyword = /\b(this|if|return|function|else|array|false|true)\b/
        
    condition:
        is_php and math.divide(#keyword, filesize) > 0.001
}

rule php_packed
{
    strings:
        $func1 = /base64_decode\s*\(/
        $func2 = /eval\s*\(/
        $func3 = /\$[a-zA-Z0-9_]+\(/
        
    condition:
        is_php and (($func1 and $func2) or $func3) and (math.entropy(0, filesize) >= 5.00)  and not php_keywords_rate //5.81
}
*./