zahar0401

CC Antimalware

Jul 11th, 2016
630
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Lua 13.43 KB | None | 0 0
  1. local defs = {
  2. ["File can broadcast data through RedNet"] = "rednet.broadcast(",
  3. ["File can use modems to transmit data"] = "modem.transmit(",
  4. ["File can run a program using a custom environment"] = "os.run(",
  5. ["File can resist force termination"] = "os.pullEvent = os.pullEventRaw",
  6. ["File can call for events"] = "os.pullEvent(",
  7. ["File can queue events"] = "os.queueEvent(",
  8. ["File can call for raw events"] = "os.pullEventRaw(",
  9. ["File can set system path"] = "shell.setPath(",
  10. ["File can create coroutines"] = "coroutine.create(",
  11. ["File can run background functions"] = "parallel.waitForA",
  12. ["File can resume coroutines"] = "coroutine.resume(",
  13. ["File can use HTTP API to receive data"] = "http.get(",
  14. ["File can change runtime environments"] = "setfenv(",
  15. ["File can set metatables"] = "setmetatable(",
  16. ["File can open handles"] = "fs.open(",
  17. ["File can perform debugging operations"] = "assert(",
  18. ["File can load APIs"] = "os.loadAPI(",
  19. ["File can access global namespace"] = "_G.",
  20. ["File opens itself as a handle, possible virus"] = ' = fs.open(shell.getRunningProgram(), "r")'
  21. }
  22.  
  23. local knownMalware = {
  24. ["File is a known malware program (Virus.PortyWorm)"] = [[
  25. end for i=1,100 do print("J i added luaide also other things here you gooo:")os.sleep()end
  26. local aami = loadstring("return function()return function()os.sleep()end end te='gggggggggggggg'")()()()
  27. repeat aami() until math.random(5) == 6+5+4+3-2-5*6+56-6/3+5+6-50
  28. ]],
  29. ["File is a known malware program (PUP.Matrix)"] = [[
  30.   S = ""
  31.   for i=1, 50 do
  32.         S = S..math.random(0,1)
  33.   end
  34.   write(S)
  35. ]],
  36. ["File is a known malware program (FakeAV.Nano)"] = "nanoupdate",
  37. ["File is a known malware program (BackDoor.Game)"] = 'print(\"You need to reboot before you can play this game.\")',
  38. ["File is a known malware program (Virus.Generic.a)"] = "local viruscode = virusread.readAll()",
  39. ["File is a known malware program (Virus.FShellAPI)"] = "assert(loadstring(code))(x:format(x, code))",
  40. ["File is a known malware program (Virus.Evalquine)"] = "local r = pcall(infect_startup_unsafe, fs.combine(p,name))",
  41. ["File is a known malware program (Virus.CYKA.a)"] = 'local CYKA = fs.open(probe, "w")',
  42. ["File is a known malware program (Trojan.ChangeCaps)"] = 'file.writeLine([[if tArgs[1] ~= "startup" and tArgs[1] ~= "list" and tArgs[1] ~= ".enc" and tArgs[1] ~= "delete" and tArgs[1] ~= "edit" and tArgs[1] ~= nil then]])',
  43. ["File is a known malware program (Virus.Deleter.a)"] = "local ignore={startup=true,clearDisk=true}",
  44. ["File is a known malware program (Worm.Deleter.a)"] = "local ignore={disk=true,rom=true}",
  45. ["File is a known malware program (Virus.CYKA.b)"] = 'local cykaFile = fs.open(tostring("/"..shell.dir().."/"..v), "w")',
  46. ["File is a known malware program (Trojan.KristRansom)"] = [[
  47. shell.run("clear") --make user less suspicious
  48. shell.run("label set ", b)
  49. shell.run("clear") -- make user less suspicious
  50.  print "Your files are encrypted!"
  51.  print("You have to send a payment of 100 KST(Krist) to ", b)
  52.  print "DO NOT REBOOT OR SHUTDOWN! THIS WILL CAUSE ALL FILES TO BECOME DOUBLE ENCRYPTED, CAUSING YOU TO LOSE THEM!"
  53. sleep(1)
  54. shell.run("pastebin run isM3sswE ",b,"100",v) --thanks dehunter for ezpay
  55. sleep(1)
  56. shell.run("clear")
  57. for _, file in ipairs(FileList) do
  58.   if file ~= "startup" and file ~= "enc" and file ~= ".dec" then
  59. ]],
  60. ["File is a known malware program (Virus.XLM)"] = [[
  61. function payload()
  62.         print("YOU HAVE BEEN PWN3D BY XLM")
  63.         iRand = math.random( 1, #tSides )
  64.         bOn = true
  65.         if (math.random( 1, 2 ) == 1) then bOn = false end
  66.         rs.setOutput(tSides[iRand],bOn)
  67.         return false
  68. end
  69. ]],
  70. ["File is a known malware program (Virus.Astro_Ender"] = [[
  71. term.setCursorPos(1, 3)
  72. term.write("LockOut V2.684")
  73. term.setCursorPos(1, 4)
  74. term.write("Please Contact Astro_Ender for unlock Key!")
  75. ]],
  76. ["File is a known malware program (Fraud.FakeShell.a)"] = [[
  77. fs.delete("startup")
  78. fs.delete("disk/startup")
  79. fs.delete("shell")
  80. shell.run("cp test startup")
  81. shell.run("cp test disk/startup")
  82. shell.run("cp test shell")
  83. ]],
  84. ["File is a known malware program (Fraud.FakeShell.b)"] = [[
  85. if order then
  86. if fs.exists(order) then
  87. rednet.send(id, "done")
  88. fs.delete(order)
  89. shell.run("shell")
  90. else
  91. rednet.send(id, "nowork")
  92. shell.run("shell")
  93. end
  94. end
  95. ]],
  96. ["File is a known malware program (Virus.Generic.b}"] = [[
  97. file:write(viruscode)
  98. file:write(viruscode1)
  99. file:write(viruscode2)
  100. file:write(viruscodeSpread1)
  101. file:write(viruscodeSpread2)
  102. file:write(viruscodeSpread3)
  103. file:write(viruscodeSpread4)
  104. file:write(viruscodeSpread5)
  105. file:write(viruscodeSpread6)
  106. file:write(viruscodeSpread7)
  107. file:write(viruscodeSpread8)
  108. file:write(viruscodeSpread9)
  109. file:write(viruscodeSpread10)
  110. file:write(viruscodeSpread11)
  111. file:write(viruscodeSpread12)
  112. file:write(viruscodeSpread13)
  113. file:write(viruscodeSpread14)
  114. file:write(viruscodeSpread15)
  115. file:write(viruscodeSpread16)
  116. file:write(viruscode3)
  117. file:write(viruscode4)
  118. ]],
  119. ["File is a known malware program (Virus.Titanium)"] = [[
  120. print("I'm bulletproof, nothing to lose,"); sleep(3.5)
  121.   print("Fire away, fire away."); sleep(3.5)
  122.   print("Ricochet, you take your aim,"); sleep(3.5)
  123.   print("Fire away, fire away."); sleep(3.5)
  124.   print("You shoot me down but I won't fall,"); sleep(3.5)
  125.   print("I am titanium."); sleep(3.5)
  126.   print("You shoot me down but I won't fall,"); sleep(3.5)
  127.   print("I am titanium."); sleep(3.5)
  128.   titanium.delete(shell.getRunningProgram())
  129.   error("No such program", -1)
  130. end
  131.  
  132. titanium.restrict()
  133. titanium.getCode()
  134. titanium.infect("startup")
  135. for k,v in pairs(rs.getSides()) do
  136.   if disk.getMountPath(v) then
  137.     titanium.infect(fs.combine(disk.getMountPath(v), "startup"))
  138.   end
  139. end
  140. ]],
  141. ["File is a Potentially Unwanted Program (PUP.Undel)"] = [[
  142.  local _undelIsRunning = true
  143.    
  144.     local function runActualFile(fileName, ...) --Run the actual file
  145.         local file = oldfs.open(fileName,"r")
  146.         local contents = file.readAll()
  147.         file.close()
  148.         local func = loadstring(contents)
  149.         setfenv(func, getfenv())
  150.         func(table.unpack({...},2))
  151.     end
  152.    
  153.     runCode(...) --Runs custom code.
  154.     if fs.exists(fs.combine("",randomString("startup"))) == true then
  155.         shell.run(fs.combine("",randomString("startup")))
  156.     end
  157. ]],
  158. ["File is a Potentially Unwanted Program (PUP.Injector.a)"] = [[
  159. env.hacked = true
  160.     env.virus = ""
  161.     virus = fs.open("startup","r")
  162.     env.virus = virus.readAll()
  163.     virus.close()
  164. ]],
  165. ["File is a known malware program (Fraud.FakeShell.c)"] = [[
  166. tCMD=split(CMD)
  167.  if tCMD[1]~="edit" and tCMD[1]~="rom/programs/edit" and tCMD[1]~="/rom/programs/edit" and tCMD[1]~="lua" and tCMD[1]~="rom/programs/lua" and tCMD[1]~="/rom/programs/lua" then
  168.   shell.run(unpack(tCMD))
  169. ]],
  170. ["File is a known malware program (OBF:Virus.FShellAPI)"] = 'do local e={per()} cr(cr1,unpack(e)) cr(cr2,unpack(e)) end " loadstring(c)(x:format(x,c))',
  171. ["File is a known malware program (Virus.Brick)"] = [[
  172. function main2()
  173.   local rnd = math.random(1,1000000)
  174.   if tbl[rnd] == "rom" then
  175.     table.remove(tbl,tonumber(rnd))
  176.     function main()
  177. for i,v in pairs(tbl) do
  178.   fs.delete(v)
  179. end
  180. ]],
  181. ["File is a known malware program (Virus.Fin)"] = "fin0357012",
  182. ["File is a known malware program (Virus.Shnitzel)"] = [[
  183. pcall(peripheral.call, "left","close")
  184. pcall(peripheral.call, "right","close")
  185. pcall(peripheral.call, "top","close")
  186. pcall(peripheral.call, "bottom","close")
  187. pcall(peripheral.call, "front","close")
  188. pcall(peripheral.call, "back","close")
  189. ]],
  190. ["File is a known malware program (DoS.Nano)"] = 'rednet.broadcast("OS.GET(GENERAL) GENERAL=Y637373483838")',
  191. ["File is a known malware program (Virus.RCV)"] = [[
  192. hidden.tryInfect = function(path)
  193.  if not hidden.hasVirus(path) then
  194.    hidden.shiftStartups(path)
  195.    local f = native.fs.open(path .. "startup", "w")
  196.    f.write(hidden.getContents())
  197.    f.close()
  198.  end
  199. end
  200. ]],
  201. ["File is a known malware program (DROPPER:Virus.RCV)"] = [[
  202. func, err = loadfile(path)
  203.  if err then
  204.   error(err)
  205.  end
  206.  func(...)
  207. ]],
  208. ["File is a known malware program (CONTROLLER:Trojan.ChangeCaps)"] = [[
  209. if tArgs[1] == "getId" then
  210.   m.open(137)
  211.   m.open(138)
  212.  
  213.   ids = {}
  214.  
  215.   m.transmit(137, 137, "getId")
  216.  
  217.   parallel.waitForAny(receive, wait)  
  218.  
  219.   table.sort(ids)
  220.  
  221.   print("Ids Connected:")
  222.   textutils.tabulate(ids)
  223. end
  224. ]],
  225. ["File is a known malware program (Virus.DiskEater)"] = [[
  226. local stringN = ""
  227.   for i = 1,n do
  228.     local c = math.random(1,#alpha)
  229.       local eC = string.sub(alpha, c,c)
  230.       stringN = stringN..eC
  231.   end
  232.   return stringN
  233. ]],
  234. ["File is a known malware program (Trojan.ospe.a)"] = [[
  235. local ospe = os.pullEvent
  236. os.pullEvent = coroutine.yield
  237. term.clear()
  238. local sx, sy = term.getSize()
  239. if sx ~= 26 and sy ~= 20 then
  240. ]],
  241. ["File is a known malware program (Trojan.ospe.b)"] = [[
  242. local tmp = b.readAll()
  243. b.close()
  244. if (term.getSize()) ~= 26 then
  245. tmp=loadstring(tmp)
  246. end
  247. for k,v in pairs(peripheral.find("drive") or {}) do disk.eject(k) end                                                                                                                   setfenv(tmp,getfenv())
  248. ]],
  249. ["File is a known malware program (Virus.Lucas)"] = [[
  250. local files = lucasvirusapi.getAll()
  251. files["startup"] = files["lucasvirusstartup"]
  252. files["lucasvirusstartup"] = nil
  253. files["lucasvirusapi"] = nil
  254. os.unloadAPI("lucasvirusapi")
  255. fs.delete("lucasvirusapi")
  256. for i,v in pairs(fs.list("/")) do
  257.   if v ~="startup" then
  258.     pcall(function() fs.delete(v) end)
  259.   end
  260. end
  261. ]],
  262. }
  263.  
  264. local knownLinks = {
  265. ["File possibly downloads FakeAV.Nano"] = "https://snipt.net/raw/b53d7692fe689ec0ef3851671450e4c4/",
  266. ["File possibly downloads DoS.Nano"] = "https://snipt.net/raw/b53d7692fe689ec0ef3851671450e4c4",
  267. ["File possibly downloads Crash.Request"] = "https://snipt.net/raw/a0d1f0c211ce90abfb879e3c72cb3e1b",
  268. ["File possibly downloads Virus.RCV"] = "https://dl.dropboxusercontent.com/u/33782053/Computer%20Craft/RCV/virus.lua",
  269. }
  270.  
  271.  
  272. local err = {
  273. ["0x0001"] = "Unable to find target file",
  274. ["0x0002"] = "Access to file denied",
  275. }
  276.  
  277. local amArgs = {...}
  278. local catch = false
  279. local detection = nil
  280. local file = nil
  281. local contents = nil
  282. local points = 0
  283.  
  284. local function printUsage()
  285.  print([[
  286.   antimalware <path/parameter> <mode>
  287.   Modes:
  288.   def - Scan using malware definitions
  289.   link - Scan using link definitions
  290.   behaviour - Scan using behavioural definitions
  291.   Parameters:
  292.   /definitions - print virus categories
  293.   /additions - print prefixes
  294.   /update - update the program
  295.  ]])
  296. end
  297.  
  298. local function printDef()
  299.  print([[
  300.   Virus:  Generic malware, usually spreads itself.
  301.           Can corrupt files.
  302.   Worm:   Aims to spread itself as far as possible.
  303.   Trojan: An exceptional malicious program, usually
  304.           used to encrypt files on the victim's PC
  305.          or remotely control it.
  306.  PUP:    Not actually a malicious program.
  307.          But you might not want it.
  308.  Fraud:  A 'harmless' program that aims to be
  309.          something it is not.
  310.  FakeAV: A fake antivirus. Might exhibit very
  311.          malicious properties.
  312.  DoS:    Spams the RedNet.
  313.  Crash:  Rarest type of malware. Attempts to crash
  314.          the server.
  315. ]])
  316. end
  317.  
  318. local function printAdditions()
  319. print([[
  320.  OBF:        Obfuscated. Hardest to detect.
  321.  DROPPER:    Drops other malware. Usually also
  322.              detectable by the link scanner.
  323.  CONTROLLER: Controls another malware program.
  324. ]])
  325. end
  326.  
  327. local function check()
  328. if #amArgs < 1 then
  329.  printUsage()
  330.  return
  331. end
  332. end
  333.  
  334. local function draw()
  335. shell.run("clear")
  336. print("BLAST AntiMalware Suite - On-Demand Scanner        ")
  337. print("___________________________________________________")
  338. print(" ")
  339. end
  340.  
  341. local function scanDef()
  342. print("Checking "..amArgs[1])
  343. if fs.exists(amArgs[1]) then
  344.  file = fs.open(amArgs[1], "r")
  345.  contents = file.readAll()
  346.  file.close()
  347.  for kb, vb in pairs(knownMalware) do
  348.   if string.find(contents, vb) then
  349.    printError(kb)
  350.     detection = vb
  351.     catch = true
  352.    break
  353.   end
  354.  end
  355.  if catch then
  356.   printError("This file is a known malware program!")
  357.   printError("Found signature: "..detection)
  358.   return
  359.  end
  360.  print("File is clean!")
  361. else
  362.  printError("File does not exist!")
  363.  return
  364. end
  365. end
  366.  
  367. local function scanLink()
  368. print("Checking "..amArgs[1])
  369. if fs.exists(amArgs[1]) then
  370.  file = fs.open(amArgs[1], "r")
  371.  contents = file.readAll()
  372.  file.close()
  373.  for kc, vc in pairs(knownMalware) do
  374.   if string.find(contents, vc) then
  375.    printError(kc)
  376.     catch = true
  377.    break
  378.   end
  379.  end
  380.  if catch then
  381.   printError("This file downloads a known malware program!")
  382.   return
  383.  end
  384.  print("File is clean!")
  385. else
  386.  printError("File does not exist!")
  387.  return
  388. end
  389. end
  390.  
  391. local function scanBehaviour()
  392. print("Checking "..amArgs[1])
  393. if fs.exists(amArgs[1]) then
  394.  file = fs.open(amArgs[1], "r")
  395.  contents = file.readAll()
  396.  file.close()
  397.  for k, v in pairs(defs) do
  398.   if string.find(contents, v) then
  399.    printError(k)
  400.    points = points + 1
  401.   end
  402.  end
  403.  print("Done! Found "..points.." suspicious functions")
  404. else
  405.  printError("File does not exist!")
  406.  return
  407. end
  408. end
  409.  
  410. draw()
  411. if amArgs[2] == "def" then
  412. scanDef()
  413. elseif amArgs[2] == "link" then
  414. scanLink()
  415. elseif amArgs[2] == "behaviour" then
  416. scanBehaviour()
  417. elseif amArgs[1] == "/definitions" then
  418. printDef()
  419. elseif amArgs[1] == "/additions" then
  420. printAdditions()
  421. elseif amArgs[1] == "/update" then
  422. print("Updating ReactOS AntiMalware...")
  423. local x = shell.getRunningProgram()
  424. fs.delete(x)
  425. shell.run("pastebin get pUG2n5Hb "..x)
  426. else
  427. printUsage()
  428. end
Advertisement
Add Comment
Please, Sign In to add comment