查看: 2|回复: 0

[破解] lua虚拟机解密思路分享

[复制链接]

22

主题

0

回帖

107

积分

管理员

积分
107
发表于 1 小时前 | 显示全部楼层 |阅读模式
总结:自定义 Lua 虚拟机 + 字节码混淆
这个脚本自定义了一个解释器来执行字节码,直接用LUA板块提供的luadec\unluac工具没法搞的,发现这个要比那个复杂的多;
貌似就是lua版块说的“简单异或/减法混淆”加密的,而且V10里面也不是标准的Lua 字节码,就是不知道先恢复那个;


那个字节码也太长了,我应该用正则表达式换行下再发

  1. local _pv = function(_t, _k) local _o = {} for _i = 1, #_t do _o[_i] = string.char(((_t[_i] - (_k + _i) * 3) % 256) % 256) end return table.concat(_o) end

  2. return (function()
  3. local v0=tonumber
  4. local v1=string.byte
  5. local v2=string.char
  6. local v3=string.sub
  7. local v4=table.concat
  8. local v5=math.ldexp
  9. local v6=math.floor
  10. local v7=select
  11. local v8=unpack or table.unpack
  12. local v9=type
  13. local va=rawget
  14. local vb=rawset
  15. local vc=setmetatable
  16. local vd=pcall
  17. local ve=error
  18. local vf=getfenv
  19. local vg=setfenv
  20. local vh=(vc and vc({}, {__mode="k"}) or {})
  21. local function v10(v11,v12,...)
  22. local v13=1
  23. local v14
  24. do local _t={}
  25. local _s=v3(v11,5)
  26. local _p=1 local _n=#_s
  27. while _p<=_n do
  28. local _h=v0(v3(_s,_p,_p+1),16)
  29. _t[#_t+1]=v2(_h)
  30. _p=_p+2
  31. end
  32. v14=v4(_t)
  33. end
  34. v11=v14
  35. local function v15()local b=v1(v11,v13)v13=v13+1 return b end
  36. local function v16()local a,b=v1(v11,v13,v13+1)v13=v13+2 return b*256+a end
  37. local function v17()local a,b,c,d=v1(v11,v13,v13+3)v13=v13+4 return d*16777216+c*65536+b*256+a end
  38. local function v18()
  39. local lo=v17()local hi=v17()
  40. local sign=1
  41. local mantissa=(hi%1048576)*4294967296+lo
  42. local exp=v6(hi/1048576)%2048
  43. if v6(hi/2147483648)%2==1 then sign=-1 end
  44. if exp==0 then if mantissa==0 then return sign*0 else exp=1 end
  45. elseif exp==2047 then return mantissa==0 and sign*(1/0)or 0/0 end
  46. return v5(sign,exp-1023)*(1+mantissa/4503599627370496)end
  47. local function v19()
  48. local n=v17()if n==0 then return""end
  49. local _s=v13 v13=v13+n
  50. local t={}for i=1,n do
  51. t[i]=v2((v1(v11,_s+i-1)-175-i*7)%256)
  52. end return v4(t)end
  53. local function v20()
  54. local _u=v15()local _p=v15()local _va=v15()local _ms=v15()
  55. local _inst={}
  56. local _ni=v17()
  57. for _i=1,_ni do
  58. local _raw=v17()
  59. _raw=(_raw-615)%4294967296
  60. local _op=_raw%64
  61. local _a=v6(_raw/64)%256
  62. local _c=v6(_raw/16384)%512
  63. local _b=v6(_raw/8388608)%512
  64. local _bx=v6(_raw/16384)%262144
  65. local _sbx=_bx-131071
  66. _inst[_i]={_op,_a,_b,_c,_bx,_sbx}
  67. end
  68. local _consts={}
  69. local _nc=v17()
  70. for _i=1,_nc do
  71. local _t=v15()
  72. if _t==0 then _consts[_i-1]=nil
  73. elseif _t==1 then _consts[_i-1]=v15()~=0
  74. elseif _t==2 then _consts[_i-1]=v18()
  75. elseif _t==3 then _consts[_i-1]=v19()
  76. end end
  77. local _protos={}
  78. local _np=v17()
  79. for _i=1,_np do
  80. local _sz=v17()
  81. _protos[_i-1]=v20()
  82. end
  83. return{_inst,_protos,_u,_consts,_p,_va,_ms}
  84. end
  85. local function v21(v22,v23,v24)
  86. local _inst=v22[1]
  87. local _protos=v22[2]
  88. local _nupvals=v22[3]
  89. local _consts=v22[4]
  90. local _nparams=v22[5]
  91. local _vararg=v22[6]
  92. local _stacksz=v22[7]
  93. local _envref={v24}
  94. local _self
  95. _self=function(...)
  96. local _undo={}
  97. local _seen={}
  98. local _vm_getfenv
  99. local _vm_setfenv
  100. local function _patch(_tbl,_key,_val)
  101. if v9(_tbl)~="table" then return end
  102. local _mark=_seen[_tbl]
  103. if not _mark then _mark={} _seen[_tbl]=_mark end
  104. if _mark[_key] then return end
  105. local _old=va(_tbl,_key)
  106. _undo[#_undo+1]={_tbl,_key,_old}
  107. vb(_tbl,_key,_val)
  108. _mark[_key]=true
  109. end
  110. local function _resolvetbl(_tbl,_key)
  111. if v9(_tbl)~="table" then return nil end
  112. local _val=va(_tbl,_key)
  113. if v9(_val)=="table" then return _val end
  114. local _ok,_res=vd(function() return _tbl[_key] end)
  115. if _ok and v9(_res)=="table" then return _res end
  116. return nil
  117. end
  118. local function _patchenv(_tbl)
  119. if v9(_tbl)~="table" then return end
  120. _patch(_tbl,"getfenv",_vm_getfenv)
  121. _patch(_tbl,"setfenv",_vm_setfenv)
  122. local _g=_resolvetbl(_tbl,"GLOBAL")
  123. if v9(_g)=="table" then
  124.   _patch(_g,"getfenv",_vm_getfenv)
  125.   _patch(_g,"setfenv",_vm_setfenv)
  126. end
  127. local _gg=_resolvetbl(_tbl,"_G")
  128. if v9(_gg)=="table" and _gg~=_g then
  129.   _patch(_gg,"getfenv",_vm_getfenv)
  130.   _patch(_gg,"setfenv",_vm_setfenv)
  131. end
  132. end
  133. local function _restoreenv()
  134. for _i=#_undo,1,-1 do
  135. local _r=_undo[_i]
  136. vb(_r[1],_r[2],_r[3])
  137. end
  138. end
  139. _vm_getfenv=function(_f)
  140. if _f==nil then _f=1 end
  141. if _f==1 then return _envref[1] end
  142. local _tf=v9(_f)
  143. if _tf=="function" then
  144.   local _cell=vh[_f]
  145.   if _cell then return _cell[1] end
  146. end
  147. if _tf=="number" and _f>1 and vf then return vf(_f+1) end
  148. if vf then return vf(_f) end
  149. return nil
  150. end
  151. _vm_setfenv=function(_f,_e)
  152. if _f==nil then _f=1 end
  153. local _tf=v9(_f)
  154. if _f==1 then
  155.   _envref[1]=_e
  156.   _patchenv(_e)
  157.   if vg then vd(vg,_self,_e) end
  158.   return _self
  159. end
  160. if _tf=="function" then
  161.   local _cell=vh[_f]
  162.   if _cell then
  163.     _cell[1]=_e
  164.     _patchenv(_e)
  165.     if vg then vd(vg,_f,_e) end
  166.     return _f
  167.   end
  168. end
  169. if _tf=="number" and _f>1 and vg then return vg(_f+1,_e) end
  170. if vg then return vg(_f,_e) end
  171. return _f
  172. end
  173. _patchenv(_envref[1])
  174. local _call_args={...}
  175. local _call_nargs=v7("#",...)
  176. local function _exec()
  177. local _stk={}
  178. local _top=-1
  179. local _pc=1
  180. local _upvs=v23 or{}
  181. local _args=_call_args
  182. local _nargs=_call_nargs
  183. local _varargs={}
  184. local _openupvs={}
  185. local function _pack(...) return {n=v7("#",...),...} end
  186. local function _getreg(_idx)
  187. local _cell=_openupvs[_idx]
  188. if _cell then return _cell[1] end
  189. return _stk[_idx]
  190. end
  191. local function _setreg(_idx,_val)
  192. _stk[_idx]=_val
  193. local _cell=_openupvs[_idx]
  194. if _cell then _cell[1]=_val end
  195. return _val
  196. end
  197. for _i=0,_nparams-1 do _stk[_i]=_args[_i+1]end
  198. if _vararg>=2 then for _i=_nparams,_nargs-1 do _varargs[_i-_nparams]=_args[_i+1]end end
  199. local _nvargs=_nargs-_nparams
  200. if _nvargs<0 then _nvargs=0 end
  201. local function _rk(v)if v>=256 then return _consts[v-256]else return _getreg(v)end end
  202. while true do
  203. local _i=_inst[_pc]
  204. local _op=_i[1]
  205. local _a=_i[2]
  206. local _b=_i[3]
  207. local _c=_i[4]
  208. local _bx=_i[5]
  209. local _sbx=_i[6]
  210. if _op<19 then
  211.   if _op<9 then
  212.     if _op<4 then
  213.       if _op<2 then
  214.         if _op==0 then
  215.           _getreg(_a)[_rk(_b)]=_rk(_c)
  216.         end
  217.         if _op==1 then
  218.           _setreg(_a,_getreg(_b))
  219.         end
  220.       else
  221.         if _op==2 then
  222.           for _j=_a,_b do _setreg(_j,nil) end
  223.         end
  224.         if _op==3 then
  225.           for _ck,_ in pairs(_openupvs)do if _ck>=_a then _openupvs[_ck]=nil end end
  226.         end
  227.       end
  228.     else
  229.       if _op<6 then
  230.         if _op==4 then
  231.           _setreg(_a,_getreg(_b)[_rk(_c)])
  232.         end
  233.         if _op==5 then
  234.           local _cp=_protos[_bx]
  235.           local _nups=_cp[3]
  236.           local _ups={}
  237.           _setreg(_a,v21(_cp,_ups,_envref[1]))
  238.           for _j=1,_nups do
  239.             _pc=_pc+1
  240.             local _pi=_inst[_pc]
  241.             if _pi[1]==1 then
  242.               local _reg=_pi[3]
  243.               if not _openupvs[_reg]then _openupvs[_reg]={_stk[_reg]}end
  244.               _ups[_j-1]=_openupvs[_reg]
  245.             else _ups[_j-1]=_upvs[_pi[3]]end
  246.           end
  247.         end
  248.       else
  249.         if _op<7 then
  250.           if _op==6 then
  251.             _setreg(_a,_consts[_bx])
  252.           end
  253.         else
  254.           if _op==7 then
  255.             _pc=_pc+_sbx
  256.           end
  257.           if _op==8 then
  258.             if vb and v9(_envref[1])=="table" then
  259.               vb(_envref[1],_consts[_bx],_getreg(_a))
  260.             else
  261.               _envref[1][_consts[_bx]]=_getreg(_a)
  262.             end
  263.           end
  264.         end
  265.       end
  266.     end
  267.   else
  268.     if _op<14 then
  269.       if _op<11 then
  270.         if _op==9 then
  271.           _setreg(_a,_rk(_b)+_rk(_c))
  272.         end
  273.         if _op==10 then
  274.           if _b==0 then
  275.             local _nret=_top-_a+1
  276.             if _nret<0 then _nret=0 end
  277.             local _r={}for _j=1,_nret do _r[_j]=_getreg(_a+_j-1)end return v8(_r,1,_nret)
  278.           elseif _b==1 then return
  279.           else
  280.             local _nret=_b-1
  281.             local _r={}for _j=1,_nret do _r[_j]=_getreg(_a+_j-1)end return v8(_r,1,_nret)
  282.           end
  283.         end
  284.       else
  285.         if _op<12 then
  286.           if _op==11 then
  287.             local _selfobj=_getreg(_b)
  288.             _setreg(_a+1,_selfobj)
  289.             _setreg(_a,_selfobj[_rk(_c)])
  290.           end
  291.         else
  292.           if _op==12 then
  293.             if(_rk(_b)==_rk(_c))~=(_a~=0)then _pc=_pc+1 end
  294.           end
  295.           if _op==13 then
  296.             _setreg(_a,not _getreg(_b))
  297.           end
  298.         end
  299.       end
  300.     else
  301.       if _op<16 then
  302.         if _op==14 then
  303.           local _fn=_getreg(_a)
  304.           local _args2={}
  305.           local _argc=0
  306.           if _b==0 then
  307.             _argc=_top-_a
  308.             if _argc<0 then _argc=0 end
  309.             for _j=1,_argc do _args2[_j]=_getreg(_a+_j)end
  310.           else
  311.             _argc=_b-1
  312.             for _j=1,_argc do _args2[_j]=_getreg(_a+_j)end
  313.           end
  314.           return _fn(v8(_args2,1,_argc))
  315.         end
  316.         if _op==15 then
  317.           _setreg(_a,#_getreg(_b))
  318.         end
  319.       else
  320.         if _op<17 then
  321.           if _op==16 then
  322.             if(_rk(_b)<=_rk(_c))~=(_a~=0)then _pc=_pc+1 end
  323.           end
  324.         else
  325.           if _op==17 then
  326.             local _fn=_getreg(_a)
  327.             local _args2={}
  328.             local _argc=0
  329.             if _b==0 then
  330.               _argc=_top-_a
  331.               if _argc<0 then _argc=0 end
  332.               for _j=1,_argc do _args2[_j]=_getreg(_a+_j)end
  333.             elseif _b>1 then
  334.               _argc=_b-1
  335.               for _j=1,_argc do _args2[_j]=_getreg(_a+_j)end
  336.             end
  337.             local _senv=_envref[1]
  338.             local _rets=_pack(_fn(v8(_args2,1,_argc)))
  339.             if _fn~=_vm_setfenv and _fn~=_vm_getfenv then _envref[1]=_senv end
  340.             if _c==0 then
  341.               _top=_a+_rets.n-1
  342.               for _j=1,_rets.n do _setreg(_a+_j-1,_rets[_j])end
  343.             elseif _c>1 then for _j=1,_c-1 do _setreg(_a+_j-1,_rets[_j])end end
  344.           end
  345.           if _op==18 then
  346.             local _tbl=_getreg(_a)
  347.             local _off=(_c-1)*50
  348.             if _b==0 then
  349.               for _j=1,_top-_a do _tbl[_off+_j]=_getreg(_a+_j)end
  350.             else
  351.               for _j=1,_b do _tbl[_off+_j]=_getreg(_a+_j)end
  352.             end
  353.           end
  354.         end
  355.       end
  356.     end
  357.   end
  358. else
  359.   if _op<28 then
  360.     if _op<23 then
  361.       if _op<21 then
  362.         if _op==19 then
  363.           if(_rk(_b)<_rk(_c))~=(_a~=0)then _pc=_pc+1 end
  364.         end
  365.         if _op==20 then
  366.           if(not not _getreg(_b))==(_c==0)then _pc=_pc+1
  367.           else _setreg(_a,_getreg(_b))end
  368.         end
  369.       else
  370.         if _op==21 then
  371.           local _step=_getreg(_a+2)
  372.           local _idx=_getreg(_a)+_step
  373.           _setreg(_a,_idx)
  374.           if _step>0 then
  375.             if _idx<=_getreg(_a+1)then _pc=_pc+_sbx _setreg(_a+3,_idx)end
  376.           else
  377.             if _idx>=_getreg(_a+1)then _pc=_pc+_sbx _setreg(_a+3,_idx)end
  378.           end
  379.         end
  380.         if _op==22 then
  381.           _setreg(_a,-_getreg(_b))
  382.         end
  383.       end
  384.     else
  385.       if _op<25 then
  386.         if _op==23 then
  387.           _upvs[_b][1]=_getreg(_a)
  388.         end
  389.         if _op==24 then
  390.           _setreg(_a,_upvs[_b][1])
  391.         end
  392.       else
  393.         if _op<26 then
  394.           if _op==25 then
  395.             _setreg(_a,_rk(_b)%_rk(_c))
  396.           end
  397.         else
  398.           if _op==26 then
  399.             local _buf=_getreg(_b)
  400.             for _j=_b+1,_c do _buf=_buf.._getreg(_j)end
  401.             _setreg(_a,_buf)
  402.           end
  403.           if _op==27 then
  404.             _setreg(_a,_b~=0)
  405.             if _c~=0 then _pc=_pc+1 end
  406.           end
  407.         end
  408.       end
  409.     end
  410.   else
  411.     if _op<33 then
  412.       if _op<30 then
  413.         if _op==28 then
  414.           _setreg(_a,_getreg(_a)-_getreg(_a+2))
  415.           _pc=_pc+_sbx
  416.         end
  417.         if _op==29 then
  418.           _setreg(_a,_envref[1][_consts[_bx]])
  419.         end
  420.       else
  421.         if _op<31 then
  422.           if _op==30 then
  423.             local _rets={_getreg(_a)(_getreg(_a+1),_getreg(_a+2))}
  424.             for _j=1,_c do _setreg(_a+2+_j,_rets[_j])end
  425.             if _rets[1]~=nil then _setreg(_a+2,_rets[1])else _pc=_pc+1 end
  426.           end
  427.         else
  428.           if _op==31 then
  429.             _setreg(_a,{})
  430.           end
  431.           if _op==32 then
  432.             _setreg(_a,_rk(_b)*_rk(_c))
  433.           end
  434.         end
  435.       end
  436.     else
  437.       if _op<35 then
  438.         if _op==33 then
  439.           _setreg(_a,_rk(_b)-_rk(_c))
  440.         end
  441.         if _op==34 then
  442.           _setreg(_a,_rk(_b)^_rk(_c))
  443.         end
  444.       else
  445.         if _op<36 then
  446.           if _op==35 then
  447.             if _b==0 then
  448.               _top=_a+_nvargs-1
  449.               for _j=0,_nvargs-1 do _setreg(_a+_j,_varargs[_j])end
  450.             else
  451.               for _j=0,_b-2 do _setreg(_a+_j,_varargs[_j])end
  452.             end
  453.           end
  454.         else
  455.           if _op==36 then
  456.             _setreg(_a,_rk(_b)/_rk(_c))
  457.           end
  458.           if _op==37 then
  459.             if(not not _getreg(_a))==(_c==0)then _pc=_pc+1 end
  460.           end
  461.         end
  462.       end
  463.     end
  464.   end
  465. end
  466. _pc=_pc+1
  467. end
  468. end
  469. local _ret={vd(_exec)}
  470. _restoreenv()
  471. if not _ret[1] then ve(_ret[2],0) end
  472. return v8(_ret,2,#_ret)
  473. end
  474. if vg then vd(vg,_self,_envref[1]) end
  475. vh[_self]=_envref
  476. return _self
  477. end
  478. local _proto=v20()
  479. return v21(_proto,nil,v12)(...)
  480. end
  481. return v10("DST!0000020A390000008A020001C4020000EC020000A7828080C4820000ABC2C00004830000EB0241012D43010084830000F842800106038002460300016D830100ADC301003943000186030001AD030200ED43020079430001C6030001ED8302002DC40200B9430001060400012D0403006D440300F9430001460400016D840300ADC4030039440001F9428002460300036D030400AD430400ED8304002DC404006D840100AD040500394300036D430500AC4300006802800168020002680200010484050044C405006D040600A8048002F8430002EA020000EC820000EF420600ECC20000EF820600710280001B00000003060000002931363440400305000000292D3034460306000000FD09130D132503020000001F2C03070000002922383137475602000000000000F03F020000000000005F40020000000000001440020000000000005C40020000000000002840020000000000005A40020000000000001C40020000000000406140020000000000003740020000000000405B40020000000000002240020000000000805B40020000000000406040020000000000206040020000000000405D40020000000000C05F40020000000000002A400306000000281E3B3E374D030200000015040312000000052B0844401B55505A594F7A6B816B9894900316000000171F2D3233424C4654616B7A6F8377889496A89AA8B70312000000182236393B3E3F49575C5B6C787A8C7E8C9B04000000B1000000000200080D00000006030000440300002B43C0016D830000A80380003883800172C34000E80380012C0400006802000178430002F10200017102800004000000030600000029313634404003060000001C2C3638334D0308000000DE1822F045360B1003040000001D30392D010000003D0000000101000406000000C4020000AB42C000FF02000028030000B8428001710280000200000003050000002A1E26373703060000001F2B3730444D0000000014020000030100040D000000C4020000EC020000680200007F0200007F0280007F020001B8C20001CC4200006E4200804203800031030001F102000171028000010000000305000000262025373E01000000C20100000400000B4F00000084020000BF02000078820001734240006E8200807F020000738240006E42008082028000710200016D820000ADC20000FF028000F60200012DC30000C3020280A803000004440000EB0341033F0480002B0481037F04000148048203F883000181828102BC42FD7FAD820000EDC200003F038001360380016DC3000003430280FF038001EB43010328048000844400006B044104ABC44003EB444103C884820478840001C1028203FC02FD7F048301002DC301006D030200AD43020041438101EBC200010C4300006E42008042038000310300012D8302006D030200ADC30200414381016BC30001A8030001FF030000788380018C4300006E420080C2038000B1030001AB0300027302C3026E42008002048000F10300010444030028048002F8830001B34200036E0200800244000002048000F1030001710280000E00000003040000002A3634300306000000293136344040030000000002000000000000F03F03040000001925253D020000000000000040030200000015040305000000012B3342400303000000032C280305000000FF2B28304A0303000000FD22380304000000FF2B2A3A0003080000002A2C373F44424E4E000000008E010000000200062200000004030000EB4240010C4300006E02008071028000EB8240000C0300006E820180EBC240000C0300006EC20080EB824000F20241016BC34000F8428001EB424100F282410168038000ADC30100F8420002EB024200EB424201F282420172C3420078030001F842000004430300EB824301280380006DC30300AD030400F882000267820086710280001100000003080000000A252922414B4C4B030B0000001F30312C454D4559615E69030E0000001C293342374B3F5A595E6A627375030700000029282D3931424403030000002922380309000000F72B2D38254D415B5303070000000922381E3D424E0315000000171F2D3233424C4654616B7A6F8377918BA4A3ADAD030A000000192C313B414745556268030D0000001F2B3A30404D4F59675E706877030F000000F9252539393E29544F5C61516B7E7D030B000000FD22381E3D424E354F6261030F00000022263236373D3F5A595E6A716B7E7D030600000029313634404003040000001D30392D03070000001523303A493E5203000000000000000008010000000200081900000004030000EB4240010C4300006E02008071028000EB824000F2C2400168038000AD030100F8420002EB424100B38241016E820180F242410072C3C100ED0302002D44020078030002F84200006EC20080EB824000F28242016D030100F8428001710280000B00000003080000000A252922414B4C4B030B0000001F30312C454D4559615E690309000000F72B2D38254D415B5303070000000922381E3D424E030C000000182236393B3E3F49635E686703120000000922380D374B4E505348676C78538D8892910003040000001D30392D0314000000233023453A474B4A275463706B7A847E899CA19A030000000003080000000922380D47424C4B00000000",(getfenv and getfenv()or _ENV),transfer_set)
  482. end)()
复制代码

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|香港:C14889B

在本版发帖
关注公众号
返回顶部