Sponsor:

Server and Web Integrator
Link:
Kloxo-MR logo
6.5.0 or 7.0.0
Click for "How to install"
Donation/Sponsorship:
Kloxo-MR is open-source.
Donate and or Sponsorship always welcome.
Click to:
Click Here
Please login or register. 2017-11-07, 20:04:00

Author Topic: How to decode malware script  (Read 1770 times)

0 Members and 1 Guest are viewing this topic.

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 3,944
  • Karma: +1/-0
    • View Profile
How to decode malware script
« on: 2015-10-02, 22:03:49 »
How to decode it - I need to know which functions does it use ?

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,381
  • Karma: +112/-9
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: How to decode malware script
« Reply #1 on: 2015-10-03, 01:51:30 »
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 3,944
  • Karma: +1/-0
    • View Profile
Re: How to decode malware script
« Reply #2 on: 2015-10-03, 19:41:54 »
I need base64 also for my scripts.

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,381
  • Karma: +112/-9
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: How to decode malware script
« Reply #3 on: 2015-10-03, 21:00:37 »
1. Locate file50.php to /tmp dir
2. Change 'eval(kcwhde($eypbq, $wdaxiwg));' to 'print(kcwhde($eypbq, $wdaxiwg));'
3. Run 'php /tmp/file50.php > /tmp/file50.src'
4. Investigate /tmp/file50.src'.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 3,944
  • Karma: +1/-0
    • View Profile
Re: How to decode malware script
« Reply #4 on: 2015-10-05, 13:24:44 »
Got it ;)

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 3,944
  • Karma: +1/-0
    • View Profile
Re: How to decode malware script
« Reply #5 on: 2015-10-05, 13:38:15 »
What about such ?

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 3,944
  • Karma: +1/-0
    • View Profile
Re: How to decode malware script
« Reply #6 on: 2015-10-05, 13:52:55 »
Another one:

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 3,944
  • Karma: +1/-0
    • View Profile

 


MRatWork Affiliates:    BIGRAF(R) Inc.    House of LMAR    EFARgrafix
Click Here

Page created in 0.038 seconds with 18 queries.

web stats analysis
 
Mirror created by MasterkinG32.CoM