Our honeybot catch up again new malware, which is very simple but clever. First look this looks nothing, because there are many PHP style comments in code.



If we remove comment’s away, then code look’s like:


Final if we put this more readable, this is Assert POST:


Final Decoded haozi.php


PHP Post payload will be evaluated as PHP code by assert() function.

Final words

Use Malware Expert – Signatures detect this malware from files for FREE!

Websites that using Malware Expert – ModSecurity rules are protected against this kind attacks.