@@ -170,21 +170,14 @@ def _decoded_literal_xor_calls(content: str) -> list[tuple[int, str]]:
170170 for function in function_pattern .finditer (content ):
171171 body = function .group ("body" )
172172 key_match = key_pattern .search (body )
173- if (
174- key_match is None
175- or "bytes(" not in body
176- or "^" not in body
177- or ".decode(" not in body
178- ):
173+ if key_match is None or "bytes(" not in body or "^" not in body or ".decode(" not in body :
179174 continue
180175 key = codecs .decode (key_match .group ("key" ), "unicode_escape" ).encode ("latin1" )
181176 call_pattern = re .compile (
182177 rf"\b{ re .escape (function .group ('name' ))} \(\s*\[(?P<values>[\d,\s]+)\]\s*\)"
183178 )
184179 for call in call_pattern .finditer (content ):
185- values = [
186- int (value ) for value in call .group ("values" ).split ("," ) if value .strip ()
187- ]
180+ values = [int (value ) for value in call .group ("values" ).split ("," ) if value .strip ()]
188181 if not values or any (value > 255 for value in values ):
189182 continue
190183 try :
@@ -196,6 +189,8 @@ def _decoded_literal_xor_calls(content: str) -> list[tuple[int, str]]:
196189 continue
197190 decoded .append ((get_line_number (content , call .start ()), command ))
198191 return decoded
192+
193+
199194SC3_PATTERNS = [
200195 (r"exec\s*\(\s*(?:base64\.)?b64decode\s*\(" , 0.95 ),
201196 (r"eval\s*\(\s*(?:base64\.)?b64decode\s*\(" , 0.95 ),
0 commit comments