|
2 years ago | |
---|---|---|
Makefile | 6 years ago | |
README.md | 5 years ago | |
evomalware.filenames | 5 years ago | |
evomalware.filenames.md5 | 5 years ago | |
evomalware.patterns | 2 years ago | |
evomalware.patterns.md5 | 2 years ago | |
evomalware.sh | 2 years ago | |
evomalware.suspect | 6 years ago | |
evomalware.suspect.md5 | 6 years ago | |
evomalware.whitelist | 3 years ago | |
evomalware.whitelist.md5 | 3 years ago |
EvoMalware is a BASH script which permits to identify files (PHP only ATM)
infected by malwares/virus/backdoor.
The main goal is to be used in a cron job to generate reports, but it can be
used in "one shot" mode.
The script uses 3 flat text files as databases:
There is also an "aggressive" mode which permits to find suspect files using
evomalware.suspect DB.
At each run, the script downloads the last databases.
TODO
Upstream is at https://forge.evolix.org/projects/evomalware
GitHub is a mirror.