Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- local defs = {
- ["File can broadcast data through RedNet"] = "rednet.broadcast(",
- ["File can use modems to transmit data"] = "modem.transmit(",
- ["File can run a program using a custom environment"] = "os.run(",
- ["File can resist force termination"] = "os.pullEvent = os.pullEventRaw",
- ["File can call for events"] = "os.pullEvent(",
- ["File can queue events"] = "os.queueEvent(",
- ["File can call for raw events"] = "os.pullEventRaw(",
- ["File can set system path"] = "shell.setPath(",
- ["File can create coroutines"] = "coroutine.create(",
- ["File can run background functions"] = "parallel.waitForA",
- ["File can resume coroutines"] = "coroutine.resume(",
- ["File can use HTTP API to receive data"] = "http.get(",
- ["File can change runtime environments"] = "setfenv(",
- ["File can set metatables"] = "setmetatable(",
- ["File can open handles"] = "fs.open(",
- ["File can perform debugging operations"] = "assert(",
- ["File can load APIs"] = "os.loadAPI(",
- ["File can access global namespace"] = "_G.",
- ["File opens itself as a handle, possible virus"] = ' = fs.open(shell.getRunningProgram(), "r")'
- }
- local knownMalware = {
- ["File is a known malware program (Virus.PortyWorm)"] = [[
- end for i=1,100 do print("J i added luaide also other things here you gooo:")os.sleep()end
- local aami = loadstring("return function()return function()os.sleep()end end te='gggggggggggggg'")()()()
- repeat aami() until math.random(5) == 6+5+4+3-2-5*6+56-6/3+5+6-50
- ]],
- ["File is a known malware program (PUP.Matrix)"] = [[
- S = ""
- for i=1, 50 do
- S = S..math.random(0,1)
- end
- write(S)
- ]],
- ["File is a known malware program (FakeAV.Nano)"] = "nanoupdate",
- ["File is a known malware program (BackDoor.Game)"] = 'print(\"You need to reboot before you can play this game.\")',
- ["File is a known malware program (Virus.Generic.a)"] = "local viruscode = virusread.readAll()",
- ["File is a known malware program (Virus.FShellAPI)"] = "assert(loadstring(code))(x:format(x, code))",
- ["File is a known malware program (Virus.Evalquine)"] = "local r = pcall(infect_startup_unsafe, fs.combine(p,name))",
- ["File is a known malware program (Virus.CYKA.a)"] = 'local CYKA = fs.open(probe, "w")',
- ["File is a known malware program (Trojan.ChangeCaps)"] = 'file.writeLine([[if tArgs[1] ~= "startup" and tArgs[1] ~= "list" and tArgs[1] ~= ".enc" and tArgs[1] ~= "delete" and tArgs[1] ~= "edit" and tArgs[1] ~= nil then]])',
- ["File is a known malware program (Virus.Deleter.a)"] = "local ignore={startup=true,clearDisk=true}",
- ["File is a known malware program (Worm.Deleter.a)"] = "local ignore={disk=true,rom=true}",
- ["File is a known malware program (Virus.CYKA.b)"] = 'local cykaFile = fs.open(tostring("/"..shell.dir().."/"..v), "w")',
- ["File is a known malware program (Trojan.KristRansom)"] = [[
- shell.run("clear") --make user less suspicious
- shell.run("label set ", b)
- shell.run("clear") -- make user less suspicious
- print "Your files are encrypted!"
- print("You have to send a payment of 100 KST(Krist) to ", b)
- print "DO NOT REBOOT OR SHUTDOWN! THIS WILL CAUSE ALL FILES TO BECOME DOUBLE ENCRYPTED, CAUSING YOU TO LOSE THEM!"
- sleep(1)
- shell.run("pastebin run isM3sswE ",b,"100",v) --thanks dehunter for ezpay
- sleep(1)
- shell.run("clear")
- for _, file in ipairs(FileList) do
- if file ~= "startup" and file ~= "enc" and file ~= ".dec" then
- ]],
- ["File is a known malware program (Virus.XLM)"] = [[
- function payload()
- print("YOU HAVE BEEN PWN3D BY XLM")
- iRand = math.random( 1, #tSides )
- bOn = true
- if (math.random( 1, 2 ) == 1) then bOn = false end
- rs.setOutput(tSides[iRand],bOn)
- return false
- end
- ]],
- ["File is a known malware program (Virus.Astro_Ender"] = [[
- term.setCursorPos(1, 3)
- term.write("LockOut V2.684")
- term.setCursorPos(1, 4)
- term.write("Please Contact Astro_Ender for unlock Key!")
- ]],
- ["File is a known malware program (Fraud.FakeShell.a)"] = [[
- fs.delete("startup")
- fs.delete("disk/startup")
- fs.delete("shell")
- shell.run("cp test startup")
- shell.run("cp test disk/startup")
- shell.run("cp test shell")
- ]],
- ["File is a known malware program (Fraud.FakeShell.b)"] = [[
- if order then
- if fs.exists(order) then
- rednet.send(id, "done")
- fs.delete(order)
- shell.run("shell")
- else
- rednet.send(id, "nowork")
- shell.run("shell")
- end
- end
- ]],
- ["File is a known malware program (Virus.Generic.b}"] = [[
- file:write(viruscode)
- file:write(viruscode1)
- file:write(viruscode2)
- file:write(viruscodeSpread1)
- file:write(viruscodeSpread2)
- file:write(viruscodeSpread3)
- file:write(viruscodeSpread4)
- file:write(viruscodeSpread5)
- file:write(viruscodeSpread6)
- file:write(viruscodeSpread7)
- file:write(viruscodeSpread8)
- file:write(viruscodeSpread9)
- file:write(viruscodeSpread10)
- file:write(viruscodeSpread11)
- file:write(viruscodeSpread12)
- file:write(viruscodeSpread13)
- file:write(viruscodeSpread14)
- file:write(viruscodeSpread15)
- file:write(viruscodeSpread16)
- file:write(viruscode3)
- file:write(viruscode4)
- ]],
- ["File is a known malware program (Virus.Titanium)"] = [[
- print("I'm bulletproof, nothing to lose,"); sleep(3.5)
- print("Fire away, fire away."); sleep(3.5)
- print("Ricochet, you take your aim,"); sleep(3.5)
- print("Fire away, fire away."); sleep(3.5)
- print("You shoot me down but I won't fall,"); sleep(3.5)
- print("I am titanium."); sleep(3.5)
- print("You shoot me down but I won't fall,"); sleep(3.5)
- print("I am titanium."); sleep(3.5)
- titanium.delete(shell.getRunningProgram())
- error("No such program", -1)
- end
- titanium.restrict()
- titanium.getCode()
- titanium.infect("startup")
- for k,v in pairs(rs.getSides()) do
- if disk.getMountPath(v) then
- titanium.infect(fs.combine(disk.getMountPath(v), "startup"))
- end
- end
- ]],
- ["File is a Potentially Unwanted Program (PUP.Undel)"] = [[
- local _undelIsRunning = true
- local function runActualFile(fileName, ...) --Run the actual file
- local file = oldfs.open(fileName,"r")
- local contents = file.readAll()
- file.close()
- local func = loadstring(contents)
- setfenv(func, getfenv())
- func(table.unpack({...},2))
- end
- runCode(...) --Runs custom code.
- if fs.exists(fs.combine("",randomString("startup"))) == true then
- shell.run(fs.combine("",randomString("startup")))
- end
- ]],
- ["File is a Potentially Unwanted Program (PUP.Injector.a)"] = [[
- env.hacked = true
- env.virus = ""
- virus = fs.open("startup","r")
- env.virus = virus.readAll()
- virus.close()
- ]],
- ["File is a known malware program (Fraud.FakeShell.c)"] = [[
- tCMD=split(CMD)
- if tCMD[1]~="edit" and tCMD[1]~="rom/programs/edit" and tCMD[1]~="/rom/programs/edit" and tCMD[1]~="lua" and tCMD[1]~="rom/programs/lua" and tCMD[1]~="/rom/programs/lua" then
- shell.run(unpack(tCMD))
- ]],
- ["File is a known malware program (OBF:Virus.FShellAPI)"] = 'do local e={per()} cr(cr1,unpack(e)) cr(cr2,unpack(e)) end " loadstring(c)(x:format(x,c))',
- ["File is a known malware program (Virus.Brick)"] = [[
- function main2()
- local rnd = math.random(1,1000000)
- if tbl[rnd] == "rom" then
- table.remove(tbl,tonumber(rnd))
- function main()
- for i,v in pairs(tbl) do
- fs.delete(v)
- end
- ]],
- ["File is a known malware program (Virus.Fin)"] = "fin0357012",
- ["File is a known malware program (Virus.Shnitzel)"] = [[
- pcall(peripheral.call, "left","close")
- pcall(peripheral.call, "right","close")
- pcall(peripheral.call, "top","close")
- pcall(peripheral.call, "bottom","close")
- pcall(peripheral.call, "front","close")
- pcall(peripheral.call, "back","close")
- ]],
- ["File is a known malware program (DoS.Nano)"] = 'rednet.broadcast("OS.GET(GENERAL) GENERAL=Y637373483838")',
- ["File is a known malware program (Virus.RCV)"] = [[
- hidden.tryInfect = function(path)
- if not hidden.hasVirus(path) then
- hidden.shiftStartups(path)
- local f = native.fs.open(path .. "startup", "w")
- f.write(hidden.getContents())
- f.close()
- end
- end
- ]],
- ["File is a known malware program (DROPPER:Virus.RCV)"] = [[
- func, err = loadfile(path)
- if err then
- error(err)
- end
- func(...)
- ]],
- ["File is a known malware program (CONTROLLER:Trojan.ChangeCaps)"] = [[
- if tArgs[1] == "getId" then
- m.open(137)
- m.open(138)
- ids = {}
- m.transmit(137, 137, "getId")
- parallel.waitForAny(receive, wait)
- table.sort(ids)
- print("Ids Connected:")
- textutils.tabulate(ids)
- end
- ]],
- ["File is a known malware program (Virus.DiskEater)"] = [[
- local stringN = ""
- for i = 1,n do
- local c = math.random(1,#alpha)
- local eC = string.sub(alpha, c,c)
- stringN = stringN..eC
- end
- return stringN
- ]],
- ["File is a known malware program (Trojan.ospe.a)"] = [[
- local ospe = os.pullEvent
- os.pullEvent = coroutine.yield
- term.clear()
- local sx, sy = term.getSize()
- if sx ~= 26 and sy ~= 20 then
- ]],
- ["File is a known malware program (Trojan.ospe.b)"] = [[
- local tmp = b.readAll()
- b.close()
- if (term.getSize()) ~= 26 then
- tmp=loadstring(tmp)
- end
- for k,v in pairs(peripheral.find("drive") or {}) do disk.eject(k) end setfenv(tmp,getfenv())
- ]],
- ["File is a known malware program (Virus.Lucas)"] = [[
- local files = lucasvirusapi.getAll()
- files["startup"] = files["lucasvirusstartup"]
- files["lucasvirusstartup"] = nil
- files["lucasvirusapi"] = nil
- os.unloadAPI("lucasvirusapi")
- fs.delete("lucasvirusapi")
- for i,v in pairs(fs.list("/")) do
- if v ~="startup" then
- pcall(function() fs.delete(v) end)
- end
- end
- ]],
- }
- local knownLinks = {
- ["File possibly downloads FakeAV.Nano"] = "https://snipt.net/raw/b53d7692fe689ec0ef3851671450e4c4/",
- ["File possibly downloads DoS.Nano"] = "https://snipt.net/raw/b53d7692fe689ec0ef3851671450e4c4",
- ["File possibly downloads Crash.Request"] = "https://snipt.net/raw/a0d1f0c211ce90abfb879e3c72cb3e1b",
- ["File possibly downloads Virus.RCV"] = "https://dl.dropboxusercontent.com/u/33782053/Computer%20Craft/RCV/virus.lua",
- }
- local err = {
- ["0x0001"] = "Unable to find target file",
- ["0x0002"] = "Access to file denied",
- }
- local amArgs = {...}
- local catch = false
- local detection = nil
- local file = nil
- local contents = nil
- local points = 0
- local function printUsage()
- print([[
- antimalware <path/parameter> <mode>
- Modes:
- def - Scan using malware definitions
- link - Scan using link definitions
- behaviour - Scan using behavioural definitions
- Parameters:
- /definitions - print virus categories
- /additions - print prefixes
- /update - update the program
- ]])
- end
- local function printDef()
- print([[
- Virus: Generic malware, usually spreads itself.
- Can corrupt files.
- Worm: Aims to spread itself as far as possible.
- Trojan: An exceptional malicious program, usually
- used to encrypt files on the victim's PC
- or remotely control it.
- PUP: Not actually a malicious program.
- But you might not want it.
- Fraud: A 'harmless' program that aims to be
- something it is not.
- FakeAV: A fake antivirus. Might exhibit very
- malicious properties.
- DoS: Spams the RedNet.
- Crash: Rarest type of malware. Attempts to crash
- the server.
- ]])
- end
- local function printAdditions()
- print([[
- OBF: Obfuscated. Hardest to detect.
- DROPPER: Drops other malware. Usually also
- detectable by the link scanner.
- CONTROLLER: Controls another malware program.
- ]])
- end
- local function check()
- if #amArgs < 1 then
- printUsage()
- return
- end
- end
- local function draw()
- shell.run("clear")
- print("BLAST AntiMalware Suite - On-Demand Scanner ")
- print("___________________________________________________")
- print(" ")
- end
- local function scanDef()
- print("Checking "..amArgs[1])
- if fs.exists(amArgs[1]) then
- file = fs.open(amArgs[1], "r")
- contents = file.readAll()
- file.close()
- for kb, vb in pairs(knownMalware) do
- if string.find(contents, vb) then
- printError(kb)
- detection = vb
- catch = true
- break
- end
- end
- if catch then
- printError("This file is a known malware program!")
- printError("Found signature: "..detection)
- return
- end
- print("File is clean!")
- else
- printError("File does not exist!")
- return
- end
- end
- local function scanLink()
- print("Checking "..amArgs[1])
- if fs.exists(amArgs[1]) then
- file = fs.open(amArgs[1], "r")
- contents = file.readAll()
- file.close()
- for kc, vc in pairs(knownMalware) do
- if string.find(contents, vc) then
- printError(kc)
- catch = true
- break
- end
- end
- if catch then
- printError("This file downloads a known malware program!")
- return
- end
- print("File is clean!")
- else
- printError("File does not exist!")
- return
- end
- end
- local function scanBehaviour()
- print("Checking "..amArgs[1])
- if fs.exists(amArgs[1]) then
- file = fs.open(amArgs[1], "r")
- contents = file.readAll()
- file.close()
- for k, v in pairs(defs) do
- if string.find(contents, v) then
- printError(k)
- points = points + 1
- end
- end
- print("Done! Found "..points.." suspicious functions")
- else
- printError("File does not exist!")
- return
- end
- end
- draw()
- if amArgs[2] == "def" then
- scanDef()
- elseif amArgs[2] == "link" then
- scanLink()
- elseif amArgs[2] == "behaviour" then
- scanBehaviour()
- elseif amArgs[1] == "/definitions" then
- printDef()
- elseif amArgs[1] == "/additions" then
- printAdditions()
- elseif amArgs[1] == "/update" then
- print("Updating ReactOS AntiMalware...")
- local x = shell.getRunningProgram()
- fs.delete(x)
- shell.run("pastebin get pUG2n5Hb "..x)
- else
- printUsage()
- end
Advertisement
Add Comment
Please, Sign In to add comment