-
Notifications
You must be signed in to change notification settings - Fork 342
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
obfuscator: 未知变种 寻求来源后适配 #96
Comments
这个样本有obfuscator的影子,但是从各方面看都不像是obfuscator某个版本分支的修改:
在已有的obfuscator插件中适配这个样本不太现实。 |
佬这个样本呢,https://note.ms/ysvn |
这个和第一个有点类似,在结构上稍微有点区别,倒是和 #98 的差不多(主要的混淆逻辑基本一致) |
可以找找最近是不是出了新的代码混淆工具 |
感觉之前就见过这种类型,印象中不太像是最近出的,我找找看吧
发自我的iPhone
…------------------ 原始邮件 ------------------
发件人: echo094 ***@***.***>
发送时间: 2024年6月14日 22:49
收件人: echo094/decode-js ***@***.***>
抄送: xiaodan01 ***@***.***>, Author ***@***.***>
主题: Re: [echo094/decode-js] 看起来像ob类型的,但是解不了 (Issue #96)
可以找找最近是不是出了新的代码混淆工具
—
Reply to this email directly, view it on GitHub, or unsubscribe.
You are receiving this because you authored the thread.Message ID: ***@***.***>
|
这几个issue中的代码大部分是同一个作者,应该是他自用的混淆工具 增加索引 Env("酷我音乐"); NAME = "中国联通";
VALY = ["zgltck"];
VER = "1.1.6";
CK = "";
LOGS = 0;
usid = 0;
Notify = 1;
let helloword_0x5c6195 = require("fs");
let helloword_0x1a9fab = require("uuid").v4;
DCFHOST = process.env.DCFHOST;
dcfkey = encodeURIComponent(process.env.dcfkey);
IP = "";
IPCITY = ""; |
我下载了最新的代码,好像还是解不开 |
因为没有适配呢,这种私有混淆工具,你跟不上他的更新速度 |
Open
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
https://note.ms/epso
Sent from PPHub
The text was updated successfully, but these errors were encountered: