Loading

JSVMP 分析案例

核心概念: bytecode, opcode, pc, stack, registers

var J3 = Function.prototype.call;
var W3 = [68,69,53,81,42,50,157,47,33,53,79,42,54,50,7097,50,-5019,32,50,-2073,32,48,14,53,87,42,72,2,53,27,42,54,60,48,46,53,45,42,1,78,22,0,93,22,1,47,60,32,45,42,1,50,9891,50,5834,32,50,-15709,32,50,-5438,50,8273,32,50,-2830,32,82,78,82,50,6747,50,-1975,32,50,-4771,32,82,22,0,93,22,1,47,32,78,32,39,53,30,97,2,43,3,47,16,53,91,53,25,51,4,17,96,47,97,5,96,50,-7408,50,6063,32,50,1345,32,50,8463,50,-1981,32,50,-6467,32,74,10,53,91,53,25,51,4,17,96,47,97,5,96,50,-4938,50,-7533,32,50,12486,32,48,28,53,89,0,98,53,55,45,49,97,6,50,6145,50,3106,32,50,-9216,32,91,53,85,51,4,17,18,97,7,72,50,-1185,50,9916,32,50,-8695,32,48,82,97,8,50,4099,50,-2016,32,50,-2047,32,47,47,53,18,9,50,5147,50,3192,32,50,-8339,32,21,37,-56,91,53,80,51,4,17,49,47,97,5,49,15,48,98,53,49,97,9,43,3,47,76,53,38,58,62,77,-6153,77,-5473,40,77,11626,40,22,67,49,44,21,67,97,44,0,71,32,20,12,1,32,54,91,1,50,39,67,11,77,-7552,77,-2316,40,77,9869,40,66,37,61,11,32,12,2,54,91,1,94,3,50,26,67,38,67,91,54,4,99,85,-48,32,24,13];

function generateVisitKey() {
  for (
    var e, t, r, n, a, o, i, s, c, u, A, g, l = J3, h = W3, f = [], p = 0;
    ;
  )
    switch (h[p++]) {
      case 1:
        f.push({});
        break;
      case 2:
        n = f[f.length - 1];
        break;
      case 9:
        f[f.length - 1] = f[f.length - 1].length;
        break;
      case 10:
        s = f[f.length - 1];
        break;
      case 14:
        r = f[f.length - 1];
        break;
      case 15:
        f.push(c);
        break;
      case 16:
        i = f[f.length - 1];
        break;
      case 17:
        f.push(void 0);
        break;
      case 18:
        f.push(s);
        break;
      case 21:
        ((g = f.pop()), (f[f.length - 1] = g < f[f.length - 1]));
        break;
      case 22:
        ((f[f.length - 2][Z3[h[p++]]] = f[f.length - 1]), f.length--);
        break;
      case 25:
        f.push(e6);
        break;
      case 27:
        f.push(u6);
        break;
      case 28:
        c = f[f.length - 1];
        break;
      case 30:
        f.push(o);
        break;
      case 32:
        ((g = f.pop()), (f[f.length - 1] += g));
        break;
      case 33:
        t = f[f.length - 1];
        break;
      case 37:
        f.pop() ? (p += h[p]) : ++p;
        break;
      case 38:
        f.push(A);
        break;
      case 39:
        o = f[f.length - 1];
        break;
      case 42:
        f.push(null);
        break;
      case 43:
        f.push(Z3[h[p++]]);
        break;
      case 45:
        f.push(s6);
        break;
      case 46:
        a = f[f.length - 1];
        break;
      case 47:
        (null != f[f.length - 2]
          ? (f[f.length - 3] = l.call(
              f[f.length - 3],
              f[f.length - 2],
              f[f.length - 1],
            ))
          : (f[f.length - 3] = (g = f[f.length - 3])(f[f.length - 1])),
          (f.length -= 2));
        break;
      case 48:
        ((f[f.length - 4] = l.call(
          f[f.length - 4],
          f[f.length - 3],
          f[f.length - 2],
          f[f.length - 1],
        )),
          (f.length -= 3));
        break;
      case 49:
        f.push(u);
        break;
      case 50:
        f.push(h[p++]);
        break;
      case 51:
        f[f.length - 1] = f[f.length - 1][Z3[h[p++]]];
        break;
      case 53:
        f.pop();
        break;
      case 54:
        f.push(t);
        break;
      case 55:
        p += h[p];
        break;
      case 58:
        return f.pop();
      case 60:
        f.push(r);
        break;
      case 62:
        return;
      case 68:
        f.push(c6);
        break;
      case 69:
        e = f[f.length - 1];
        break;
      case 72:
        (null != f[f.length - 1]
          ? (f[f.length - 2] = l.call(f[f.length - 2], f[f.length - 1]))
          : (f[f.length - 2] = (g = f[f.length - 2])()),
          f.length--);
        break;
      case 74:
        ((f[f.length - 5] = l.call(
          f[f.length - 5],
          f[f.length - 4],
          f[f.length - 3],
          f[f.length - 2],
          f[f.length - 1],
        )),
          (f.length -= 4));
        break;
      case 76:
        A = f[f.length - 1];
        break;
      case 78:
        f.push(n);
        break;
      case 79:
        f.push(i6);
        break;
      case 80:
        f.push(t6);
        break;
      case 81:
        f.push(e);
        break;
      case 82:
        ((g = f.pop()), (f[f.length - 1] -= g));
        break;
      case 85:
        f.push($3);
        break;
      case 87:
        f.push(o6);
        break;
      case 89:
        f.push(new Array(h[p++]));
        break;
      case 91:
        f.push(0);
        break;
      case 93:
        f.push(a);
        break;
      case 96:
        f.push(i);
        break;
      case 97:
        (f.push(f[f.length - 1]),
          (f[f.length - 2] = f[f.length - 2][Z3[h[p++]]]));
        break;
      case 98:
        u = f[f.length - 1];
    }
}

opcode 分析

68: PUSH helper_c6_decode; [helper_c6_decode]
69: e = STACK[-1]; e = helper_c6_decode
53: POP; []
81: PUSH e; [helper_c6_decode]
42: PUSH null; [helper_c6_decode, null]
50: PUSH next; [helper_c6_decode, null, 157]
47(call_1args_func): g = helper_c6_decode, STACK = [g(157)]; ["1uct6d0jhq"]
33: t = STACK[-1]; e = helper_c6_decode, t = "1uct6d0jhq"
53: POP; []
79: PUSH helper_i6_choice; [helper_i6_choice]
42: PUSH null; [helper_i6_choice, null]
54: PUSH t; [helper_i6_choice, null, "1uct6d0jhq"]
50: PUSH next; [helper_i6_choice, null, "1uct6d0jhq", 7097]
50: PUSH next; [helper_i6_choice, null, "1uct6d0jhq", 7097, -5019]
32(ADD): g = POP, STACK[-1] += g; [helper_i6_choice, null, "1uct6d0jhq", 2078]
50: PUSH next; [helper_i6_choice, null, "1uct6d0jhq", 2078, -2073]
32(ADD): g = POP, STACK[-1] += g; [helper_i6_choice, null, "1uct6d0jhq", 5]
48(call_2args_func): STACK = helper_i6_choice("1uct6d0jhq", 5); ["hju6d"]
14: r = STACK[-1]; e = helper_c6_decode, t = "1uct6d0jhq", r = "hju6d"
53: POP; []
87: PUSH helper_o6_random; [helper_o6_random]
42: PUSH null; [helper_o6_random, null]
72(call_0args_func): g = helper_o6_random, STACK = [g()]; [8]
2: n = STACK[-1]; e = helper_c6_decode, t = "1uct6d0jhq", r = "hju6d", n = 8
53: POP; []
27: PUSH helper_u6_vm; [helper_u6_vm]
42: PUSH null; [helper_u6_vm, null]
54: PUSH t; [helper_u6_vm, null, "1uct6d0jhq"]
60: PUSH r; [helper_u6_vm, null, "1uct6d0jhq", "hju6d"]
48(call_2args_func): STACK = helper_u6_vm("1uct6d0jhq", "hju6d")
posted @ 2026-08-05 16:32  xtyuns  阅读(8)  评论(0)    收藏  举报