如何解读并反混淆这段Javascript代码?求技术指导
Let’s break down this code to assess its validity and walk through how to deobfuscate it.
Is This Code "Normal"?
Short answer: No, this is intentionally obfuscated code. Normal production JavaScript uses meaningful variable names, readable logic, and avoids random-looking strings like the ones here. This code is designed to hide its true functionality—common in malicious scripts, adware, or code meant to bypass detection tools.
Step-by-Step Deobfuscation Walkthrough
To unpack this, we need to focus on the core components driving the obfuscation:
1. Identify the Decoding Core (rAu)
The rAu function is the key to everything here. Every scrambled string in the code is passed through rAu, which is almost certainly a decoding function (e.g., uses character substitution, XOR, Base64, or a custom shift algorithm to turn gibberish into readable text/code).
var Xvu = rAu('gazotrlsxhccbvqodpeijnrtnfcuymtowusrk').substr(0, Yzx);
This line decodes the gibberish string, then takes the firstYzxcharacters to get a method name stored inXvu.var qVB = rAu[Xvu];qVBis then set to the method on therAuobject matching that decoded name—likely a function that executes or further processes decoded code.
2. Decode the Intermediate Code (xYm)
The messy string stored in xYm is decoded via rAu(xYm), turning it into a snippet of executable JavaScript. This snippet is then passed to qVB to create the Ywu function:
var Ywu = qVB(cxT, rAu(xYm));
qVB here is probably a wrapper for the native Function constructor, which converts string code into a callable function.
3. Unpack the Final Payload
The last giant scrambled string passed to rAu is the final payload. When Ywu(rAu(...)) runs, it executes the fully decoded version of this payload—this is where the code’s true behavior (malicious or otherwise) lives.
Practical Steps to Deobfuscate It
If you want to safely unpack this code:
- First, get the full definition of
rAu: The code snippet you provided referencesrAubut doesn’t include its implementation. You’ll need to pull this from the complete code to proceed. - Test the decoding function: Use
rAuto decode small strings first (like the one used to getXvu) to understand how it works (e.g., does it shift characters, use a lookup table, or XOR with a key?). - Decode intermediate strings: Run
rAu(xYm)to see what code is being passed toqVB—this will reveal how the final payload is processed. - Execute in a safe environment: Never run unknown obfuscated code on your main machine. Use a sandboxed environment (like a disposable VM, isolated browser tab, or Node.js sandbox) to decode and test the final payload.
Critical Warning
Obfuscated code like this is almost always hiding something. It could be malicious (e.g., data theft, browser hijacking) or unwanted (e.g., aggressive ad injection). Proceed with extreme caution, and only analyze it in a secure, isolated environment.
内容的提问来源于stack exchange,提问作者Obada Diab

