Old backdoor, new obfuscation

39 points
1/20/1970
a year ago
by kencausey

Comments


yarg

Surely this sort of crap is heuristically detectable?

    def opaque_fct_6_guXM09JTqW(opaque_fct_6_guXM09JTqW_0, opaque_fct_6_guXM09JTqW_1, opaque_fct_6_guXM09JTqW_2, opaque_fct_6_guXM09JTqW_3, opaque_fct_6_guXM09JTqW_4):
        if (opaque_fct_6_guXM09JTqW_1 > opaque_fct_6_guXM09JTqW_0):
            return True
        if (opaque_fct_6_guXM09JTqW_4 <= opaque_fct_6_guXM09JTqW_1):
            return True
        ...
        if (opaque_fct_6_guXM09JTqW_0 <= opaque_fct_6_guXM09JTqW_1):
            return True
        if (opaque_fct_6_guXM09JTqW_0 >= opaque_fct_6_guXM09JTqW_1):
            return False
a year ago