forked from HumanSecurity/obfuscation-detector
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathcffStorageObject.js
More file actions
59 lines (54 loc) · 1.75 KB
/
Copy pathcffStorageObject.js
File metadata and controls
59 lines (54 loc) · 1.75 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
/**
* @module cffStorageObject
*
* Label: `cff_storage_object`
*
* Product extra (javascript-obfuscator control-flow flattening). Not a replacements-family name.
* Objects whose keys look like generated 5-letter identifiers and whose values are mostly
* single-return operator/call shells or literals.
*/
import {isCffStorageObject} from './sharedDetectionMethods.js';
const name = 'cff_storage_object';
/**
* Detects javascript-obfuscator-style control-flow flattening storage objects.
*
* ## Algorithm
* 1. Scan every `ObjectExpression` in the AST.
* 2. Delegate to `isCffStorageObject`:
* - majority of keys match `/^[A-Za-z]{5}$/`;
* - majority of values are Literals or single-return Function/ArrowExpression shells.
* 3. Deliberately **does not** match “any object of small helper functions” (e.g. `{add:(a,b)=>a+b}`).
*
* ## Example (true positive)
* ```js
* const sto = {
* AbCde: function (x, y) { return x === y; },
* FgHij: function (x, y) { return x + y; },
* KlMno: 'ok',
* };
* ```
*
* ## True negatives
* - `{ add: (a, b) => a + b }` (readable keys).
* - 5-letter keys with multi-statement bodies / DOM methods.
* - Empty object.
*
* ## Reduced-mode priority
* - `prioritizeOver`: none.
* - Suppressed by `obfuscator_io` when that composite also fires.
*
* @param {ASTNode[]} flatTree - Flattened AST from flAST.
* @returns {boolean} True when at least one matching object exists.
*/
function detectCffStorageObject(flatTree) {
return (flatTree[0].typeMap.ObjectExpression || []).some(isCffStorageObject);
}
/**
* @type {{name: string, prioritizeOver: string[], detect: Function}}
*/
const detector = {
name,
prioritizeOver: [],
detect: detectCffStorageObject,
};
export {detector, detectCffStorageObject};