|
|
总结:自定义 Lua 虚拟机 + 字节码混淆
这个脚本自定义了一个解释器来执行字节码,直接用LUA板块提供的luadec\unluac工具没法搞的,发现这个要比那个复杂的多;
貌似就是lua版块说的“简单异或/减法混淆”加密的,而且V10里面也不是标准的Lua 字节码,就是不知道先恢复那个;
那个字节码也太长了,我应该用正则表达式换行下再发
- local _pv = function(_t, _k) local _o = {} for _i = 1, #_t do _o[_i] = string.char(((_t[_i] - (_k + _i) * 3) % 256) % 256) end return table.concat(_o) end
-
- return (function()
- local v0=tonumber
- local v1=string.byte
- local v2=string.char
- local v3=string.sub
- local v4=table.concat
- local v5=math.ldexp
- local v6=math.floor
- local v7=select
- local v8=unpack or table.unpack
- local v9=type
- local va=rawget
- local vb=rawset
- local vc=setmetatable
- local vd=pcall
- local ve=error
- local vf=getfenv
- local vg=setfenv
- local vh=(vc and vc({}, {__mode="k"}) or {})
- local function v10(v11,v12,...)
- local v13=1
- local v14
- do local _t={}
- local _s=v3(v11,5)
- local _p=1 local _n=#_s
- while _p<=_n do
- local _h=v0(v3(_s,_p,_p+1),16)
- _t[#_t+1]=v2(_h)
- _p=_p+2
- end
- v14=v4(_t)
- end
- v11=v14
- local function v15()local b=v1(v11,v13)v13=v13+1 return b end
- local function v16()local a,b=v1(v11,v13,v13+1)v13=v13+2 return b*256+a end
- local function v17()local a,b,c,d=v1(v11,v13,v13+3)v13=v13+4 return d*16777216+c*65536+b*256+a end
- local function v18()
- local lo=v17()local hi=v17()
- local sign=1
- local mantissa=(hi%1048576)*4294967296+lo
- local exp=v6(hi/1048576)%2048
- if v6(hi/2147483648)%2==1 then sign=-1 end
- if exp==0 then if mantissa==0 then return sign*0 else exp=1 end
- elseif exp==2047 then return mantissa==0 and sign*(1/0)or 0/0 end
- return v5(sign,exp-1023)*(1+mantissa/4503599627370496)end
- local function v19()
- local n=v17()if n==0 then return""end
- local _s=v13 v13=v13+n
- local t={}for i=1,n do
- t[i]=v2((v1(v11,_s+i-1)-175-i*7)%256)
- end return v4(t)end
- local function v20()
- local _u=v15()local _p=v15()local _va=v15()local _ms=v15()
- local _inst={}
- local _ni=v17()
- for _i=1,_ni do
- local _raw=v17()
- _raw=(_raw-615)%4294967296
- local _op=_raw%64
- local _a=v6(_raw/64)%256
- local _c=v6(_raw/16384)%512
- local _b=v6(_raw/8388608)%512
- local _bx=v6(_raw/16384)%262144
- local _sbx=_bx-131071
- _inst[_i]={_op,_a,_b,_c,_bx,_sbx}
- end
- local _consts={}
- local _nc=v17()
- for _i=1,_nc do
- local _t=v15()
- if _t==0 then _consts[_i-1]=nil
- elseif _t==1 then _consts[_i-1]=v15()~=0
- elseif _t==2 then _consts[_i-1]=v18()
- elseif _t==3 then _consts[_i-1]=v19()
- end end
- local _protos={}
- local _np=v17()
- for _i=1,_np do
- local _sz=v17()
- _protos[_i-1]=v20()
- end
- return{_inst,_protos,_u,_consts,_p,_va,_ms}
- end
- local function v21(v22,v23,v24)
- local _inst=v22[1]
- local _protos=v22[2]
- local _nupvals=v22[3]
- local _consts=v22[4]
- local _nparams=v22[5]
- local _vararg=v22[6]
- local _stacksz=v22[7]
- local _envref={v24}
- local _self
- _self=function(...)
- local _undo={}
- local _seen={}
- local _vm_getfenv
- local _vm_setfenv
- local function _patch(_tbl,_key,_val)
- if v9(_tbl)~="table" then return end
- local _mark=_seen[_tbl]
- if not _mark then _mark={} _seen[_tbl]=_mark end
- if _mark[_key] then return end
- local _old=va(_tbl,_key)
- _undo[#_undo+1]={_tbl,_key,_old}
- vb(_tbl,_key,_val)
- _mark[_key]=true
- end
- local function _resolvetbl(_tbl,_key)
- if v9(_tbl)~="table" then return nil end
- local _val=va(_tbl,_key)
- if v9(_val)=="table" then return _val end
- local _ok,_res=vd(function() return _tbl[_key] end)
- if _ok and v9(_res)=="table" then return _res end
- return nil
- end
- local function _patchenv(_tbl)
- if v9(_tbl)~="table" then return end
- _patch(_tbl,"getfenv",_vm_getfenv)
- _patch(_tbl,"setfenv",_vm_setfenv)
- local _g=_resolvetbl(_tbl,"GLOBAL")
- if v9(_g)=="table" then
- _patch(_g,"getfenv",_vm_getfenv)
- _patch(_g,"setfenv",_vm_setfenv)
- end
- local _gg=_resolvetbl(_tbl,"_G")
- if v9(_gg)=="table" and _gg~=_g then
- _patch(_gg,"getfenv",_vm_getfenv)
- _patch(_gg,"setfenv",_vm_setfenv)
- end
- end
- local function _restoreenv()
- for _i=#_undo,1,-1 do
- local _r=_undo[_i]
- vb(_r[1],_r[2],_r[3])
- end
- end
- _vm_getfenv=function(_f)
- if _f==nil then _f=1 end
- if _f==1 then return _envref[1] end
- local _tf=v9(_f)
- if _tf=="function" then
- local _cell=vh[_f]
- if _cell then return _cell[1] end
- end
- if _tf=="number" and _f>1 and vf then return vf(_f+1) end
- if vf then return vf(_f) end
- return nil
- end
- _vm_setfenv=function(_f,_e)
- if _f==nil then _f=1 end
- local _tf=v9(_f)
- if _f==1 then
- _envref[1]=_e
- _patchenv(_e)
- if vg then vd(vg,_self,_e) end
- return _self
- end
- if _tf=="function" then
- local _cell=vh[_f]
- if _cell then
- _cell[1]=_e
- _patchenv(_e)
- if vg then vd(vg,_f,_e) end
- return _f
- end
- end
- if _tf=="number" and _f>1 and vg then return vg(_f+1,_e) end
- if vg then return vg(_f,_e) end
- return _f
- end
- _patchenv(_envref[1])
- local _call_args={...}
- local _call_nargs=v7("#",...)
- local function _exec()
- local _stk={}
- local _top=-1
- local _pc=1
- local _upvs=v23 or{}
- local _args=_call_args
- local _nargs=_call_nargs
- local _varargs={}
- local _openupvs={}
- local function _pack(...) return {n=v7("#",...),...} end
- local function _getreg(_idx)
- local _cell=_openupvs[_idx]
- if _cell then return _cell[1] end
- return _stk[_idx]
- end
- local function _setreg(_idx,_val)
- _stk[_idx]=_val
- local _cell=_openupvs[_idx]
- if _cell then _cell[1]=_val end
- return _val
- end
- for _i=0,_nparams-1 do _stk[_i]=_args[_i+1]end
- if _vararg>=2 then for _i=_nparams,_nargs-1 do _varargs[_i-_nparams]=_args[_i+1]end end
- local _nvargs=_nargs-_nparams
- if _nvargs<0 then _nvargs=0 end
- local function _rk(v)if v>=256 then return _consts[v-256]else return _getreg(v)end end
- while true do
- local _i=_inst[_pc]
- local _op=_i[1]
- local _a=_i[2]
- local _b=_i[3]
- local _c=_i[4]
- local _bx=_i[5]
- local _sbx=_i[6]
- if _op<19 then
- if _op<9 then
- if _op<4 then
- if _op<2 then
- if _op==0 then
- _getreg(_a)[_rk(_b)]=_rk(_c)
- end
- if _op==1 then
- _setreg(_a,_getreg(_b))
- end
- else
- if _op==2 then
- for _j=_a,_b do _setreg(_j,nil) end
- end
- if _op==3 then
- for _ck,_ in pairs(_openupvs)do if _ck>=_a then _openupvs[_ck]=nil end end
- end
- end
- else
- if _op<6 then
- if _op==4 then
- _setreg(_a,_getreg(_b)[_rk(_c)])
- end
- if _op==5 then
- local _cp=_protos[_bx]
- local _nups=_cp[3]
- local _ups={}
- _setreg(_a,v21(_cp,_ups,_envref[1]))
- for _j=1,_nups do
- _pc=_pc+1
- local _pi=_inst[_pc]
- if _pi[1]==1 then
- local _reg=_pi[3]
- if not _openupvs[_reg]then _openupvs[_reg]={_stk[_reg]}end
- _ups[_j-1]=_openupvs[_reg]
- else _ups[_j-1]=_upvs[_pi[3]]end
- end
- end
- else
- if _op<7 then
- if _op==6 then
- _setreg(_a,_consts[_bx])
- end
- else
- if _op==7 then
- _pc=_pc+_sbx
- end
- if _op==8 then
- if vb and v9(_envref[1])=="table" then
- vb(_envref[1],_consts[_bx],_getreg(_a))
- else
- _envref[1][_consts[_bx]]=_getreg(_a)
- end
- end
- end
- end
- end
- else
- if _op<14 then
- if _op<11 then
- if _op==9 then
- _setreg(_a,_rk(_b)+_rk(_c))
- end
- if _op==10 then
- if _b==0 then
- local _nret=_top-_a+1
- if _nret<0 then _nret=0 end
- local _r={}for _j=1,_nret do _r[_j]=_getreg(_a+_j-1)end return v8(_r,1,_nret)
- elseif _b==1 then return
- else
- local _nret=_b-1
- local _r={}for _j=1,_nret do _r[_j]=_getreg(_a+_j-1)end return v8(_r,1,_nret)
- end
- end
- else
- if _op<12 then
- if _op==11 then
- local _selfobj=_getreg(_b)
- _setreg(_a+1,_selfobj)
- _setreg(_a,_selfobj[_rk(_c)])
- end
- else
- if _op==12 then
- if(_rk(_b)==_rk(_c))~=(_a~=0)then _pc=_pc+1 end
- end
- if _op==13 then
- _setreg(_a,not _getreg(_b))
- end
- end
- end
- else
- if _op<16 then
- if _op==14 then
- local _fn=_getreg(_a)
- local _args2={}
- local _argc=0
- if _b==0 then
- _argc=_top-_a
- if _argc<0 then _argc=0 end
- for _j=1,_argc do _args2[_j]=_getreg(_a+_j)end
- else
- _argc=_b-1
- for _j=1,_argc do _args2[_j]=_getreg(_a+_j)end
- end
- return _fn(v8(_args2,1,_argc))
- end
- if _op==15 then
- _setreg(_a,#_getreg(_b))
- end
- else
- if _op<17 then
- if _op==16 then
- if(_rk(_b)<=_rk(_c))~=(_a~=0)then _pc=_pc+1 end
- end
- else
- if _op==17 then
- local _fn=_getreg(_a)
- local _args2={}
- local _argc=0
- if _b==0 then
- _argc=_top-_a
- if _argc<0 then _argc=0 end
- for _j=1,_argc do _args2[_j]=_getreg(_a+_j)end
- elseif _b>1 then
- _argc=_b-1
- for _j=1,_argc do _args2[_j]=_getreg(_a+_j)end
- end
- local _senv=_envref[1]
- local _rets=_pack(_fn(v8(_args2,1,_argc)))
- if _fn~=_vm_setfenv and _fn~=_vm_getfenv then _envref[1]=_senv end
- if _c==0 then
- _top=_a+_rets.n-1
- for _j=1,_rets.n do _setreg(_a+_j-1,_rets[_j])end
- elseif _c>1 then for _j=1,_c-1 do _setreg(_a+_j-1,_rets[_j])end end
- end
- if _op==18 then
- local _tbl=_getreg(_a)
- local _off=(_c-1)*50
- if _b==0 then
- for _j=1,_top-_a do _tbl[_off+_j]=_getreg(_a+_j)end
- else
- for _j=1,_b do _tbl[_off+_j]=_getreg(_a+_j)end
- end
- end
- end
- end
- end
- end
- else
- if _op<28 then
- if _op<23 then
- if _op<21 then
- if _op==19 then
- if(_rk(_b)<_rk(_c))~=(_a~=0)then _pc=_pc+1 end
- end
- if _op==20 then
- if(not not _getreg(_b))==(_c==0)then _pc=_pc+1
- else _setreg(_a,_getreg(_b))end
- end
- else
- if _op==21 then
- local _step=_getreg(_a+2)
- local _idx=_getreg(_a)+_step
- _setreg(_a,_idx)
- if _step>0 then
- if _idx<=_getreg(_a+1)then _pc=_pc+_sbx _setreg(_a+3,_idx)end
- else
- if _idx>=_getreg(_a+1)then _pc=_pc+_sbx _setreg(_a+3,_idx)end
- end
- end
- if _op==22 then
- _setreg(_a,-_getreg(_b))
- end
- end
- else
- if _op<25 then
- if _op==23 then
- _upvs[_b][1]=_getreg(_a)
- end
- if _op==24 then
- _setreg(_a,_upvs[_b][1])
- end
- else
- if _op<26 then
- if _op==25 then
- _setreg(_a,_rk(_b)%_rk(_c))
- end
- else
- if _op==26 then
- local _buf=_getreg(_b)
- for _j=_b+1,_c do _buf=_buf.._getreg(_j)end
- _setreg(_a,_buf)
- end
- if _op==27 then
- _setreg(_a,_b~=0)
- if _c~=0 then _pc=_pc+1 end
- end
- end
- end
- end
- else
- if _op<33 then
- if _op<30 then
- if _op==28 then
- _setreg(_a,_getreg(_a)-_getreg(_a+2))
- _pc=_pc+_sbx
- end
- if _op==29 then
- _setreg(_a,_envref[1][_consts[_bx]])
- end
- else
- if _op<31 then
- if _op==30 then
- local _rets={_getreg(_a)(_getreg(_a+1),_getreg(_a+2))}
- for _j=1,_c do _setreg(_a+2+_j,_rets[_j])end
- if _rets[1]~=nil then _setreg(_a+2,_rets[1])else _pc=_pc+1 end
- end
- else
- if _op==31 then
- _setreg(_a,{})
- end
- if _op==32 then
- _setreg(_a,_rk(_b)*_rk(_c))
- end
- end
- end
- else
- if _op<35 then
- if _op==33 then
- _setreg(_a,_rk(_b)-_rk(_c))
- end
- if _op==34 then
- _setreg(_a,_rk(_b)^_rk(_c))
- end
- else
- if _op<36 then
- if _op==35 then
- if _b==0 then
- _top=_a+_nvargs-1
- for _j=0,_nvargs-1 do _setreg(_a+_j,_varargs[_j])end
- else
- for _j=0,_b-2 do _setreg(_a+_j,_varargs[_j])end
- end
- end
- else
- if _op==36 then
- _setreg(_a,_rk(_b)/_rk(_c))
- end
- if _op==37 then
- if(not not _getreg(_a))==(_c==0)then _pc=_pc+1 end
- end
- end
- end
- end
- end
- end
- _pc=_pc+1
- end
- end
- local _ret={vd(_exec)}
- _restoreenv()
- if not _ret[1] then ve(_ret[2],0) end
- return v8(_ret,2,#_ret)
- end
- if vg then vd(vg,_self,_envref[1]) end
- vh[_self]=_envref
- return _self
- end
- local _proto=v20()
- return v21(_proto,nil,v12)(...)
- end
- return v10("DST!0000020A390000008A020001C4020000EC020000A7828080C4820000ABC2C00004830000EB0241012D43010084830000F842800106038002460300016D830100ADC301003943000186030001AD030200ED43020079430001C6030001ED8302002DC40200B9430001060400012D0403006D440300F9430001460400016D840300ADC4030039440001F9428002460300036D030400AD430400ED8304002DC404006D840100AD040500394300036D430500AC4300006802800168020002680200010484050044C405006D040600A8048002F8430002EA020000EC820000EF420600ECC20000EF820600710280001B00000003060000002931363440400305000000292D3034460306000000FD09130D132503020000001F2C03070000002922383137475602000000000000F03F020000000000005F40020000000000001440020000000000005C40020000000000002840020000000000005A40020000000000001C40020000000000406140020000000000003740020000000000405B40020000000000002240020000000000805B40020000000000406040020000000000206040020000000000405D40020000000000C05F40020000000000002A400306000000281E3B3E374D030200000015040312000000052B0844401B55505A594F7A6B816B9894900316000000171F2D3233424C4654616B7A6F8377889496A89AA8B70312000000182236393B3E3F49575C5B6C787A8C7E8C9B04000000B1000000000200080D00000006030000440300002B43C0016D830000A80380003883800172C34000E80380012C0400006802000178430002F10200017102800004000000030600000029313634404003060000001C2C3638334D0308000000DE1822F045360B1003040000001D30392D010000003D0000000101000406000000C4020000AB42C000FF02000028030000B8428001710280000200000003050000002A1E26373703060000001F2B3730444D0000000014020000030100040D000000C4020000EC020000680200007F0200007F0280007F020001B8C20001CC4200006E4200804203800031030001F102000171028000010000000305000000262025373E01000000C20100000400000B4F00000084020000BF02000078820001734240006E8200807F020000738240006E42008082028000710200016D820000ADC20000FF028000F60200012DC30000C3020280A803000004440000EB0341033F0480002B0481037F04000148048203F883000181828102BC42FD7FAD820000EDC200003F038001360380016DC3000003430280FF038001EB43010328048000844400006B044104ABC44003EB444103C884820478840001C1028203FC02FD7F048301002DC301006D030200AD43020041438101EBC200010C4300006E42008042038000310300012D8302006D030200ADC30200414381016BC30001A8030001FF030000788380018C4300006E420080C2038000B1030001AB0300027302C3026E42008002048000F10300010444030028048002F8830001B34200036E0200800244000002048000F1030001710280000E00000003040000002A3634300306000000293136344040030000000002000000000000F03F03040000001925253D020000000000000040030200000015040305000000012B3342400303000000032C280305000000FF2B28304A0303000000FD22380304000000FF2B2A3A0003080000002A2C373F44424E4E000000008E010000000200062200000004030000EB4240010C4300006E02008071028000EB8240000C0300006E820180EBC240000C0300006EC20080EB824000F20241016BC34000F8428001EB424100F282410168038000ADC30100F8420002EB024200EB424201F282420172C3420078030001F842000004430300EB824301280380006DC30300AD030400F882000267820086710280001100000003080000000A252922414B4C4B030B0000001F30312C454D4559615E69030E0000001C293342374B3F5A595E6A627375030700000029282D3931424403030000002922380309000000F72B2D38254D415B5303070000000922381E3D424E0315000000171F2D3233424C4654616B7A6F8377918BA4A3ADAD030A000000192C313B414745556268030D0000001F2B3A30404D4F59675E706877030F000000F9252539393E29544F5C61516B7E7D030B000000FD22381E3D424E354F6261030F00000022263236373D3F5A595E6A716B7E7D030600000029313634404003040000001D30392D03070000001523303A493E5203000000000000000008010000000200081900000004030000EB4240010C4300006E02008071028000EB824000F2C2400168038000AD030100F8420002EB424100B38241016E820180F242410072C3C100ED0302002D44020078030002F84200006EC20080EB824000F28242016D030100F8428001710280000B00000003080000000A252922414B4C4B030B0000001F30312C454D4559615E690309000000F72B2D38254D415B5303070000000922381E3D424E030C000000182236393B3E3F49635E686703120000000922380D374B4E505348676C78538D8892910003040000001D30392D0314000000233023453A474B4A275463706B7A847E899CA19A030000000003080000000922380D47424C4B00000000",(getfenv and getfenv()or _ENV),transfer_set)
- end)()
复制代码
|
|