'#
'# Copyright (C) Binary-Offensive.com Mariusz Banach - All Rights Reserved
'# Unauthorized copying of this file, via any medium is strictly prohibited.
'#
'# This file/directory was part of Modern Initial Access and Evasion Tactics training
'# delivered by binary-offensive.com and was provided as supplemental material.
'# 
'# Authored by Mariusz Banach <mb@binary-offensive.com>, @mariuszbit / mgeeky
'#


' Base64 decoder

Function obf_BinaryToString(obf_Binary)
    Dim obf_BinaryStream
    Set obf_BinaryStream = CreateObject("ADODB.Stream")

    obf_BinaryStream.Type = 1
    obf_BinaryStream.Open
    obf_BinaryStream.Write obf_Binary
    obf_BinaryStream.Position = 0
    obf_BinaryStream.Type = 2
    obf_BinaryStream.CharSet = "Windows-1252"

    obf_BinaryToString = obf_BinaryStream.ReadText
    Set obf_BinaryStream = Nothing
End Function

Function obf_StringToBinary(obf_b)
    Dim obf_enc
    Set obf_enc = CreateObject("System.Text.ASCIIEncoding")
    obf_StringToBinary = obf_enc.GetBytes_4(obf_b)
End Function

Private Function obf_DecodeBaseText64(ByVal obf_EncodedData)
    Dim obf_XmlDom, obf_XmlNode, obf_Decoded, obf_Counter, obf_Decoded2
    Set obf_XmlDom = CreateObject("Msxml2.DOMDocument.3.0")
    Set obf_XmlNode = obf_XmlDom.createElement("obf_someInternalName")
    obf_XmlNode.DataType = "bin.base64"
    obf_XmlNode.Text = obf_EncodedData
    obf_Decoded2 = obf_BinaryToString(obf_XmlNode.NodeTypedValue)

    ' This for-loop adjusts each byte by adding +35 to evade AVs capable of
    ' base64-decoding in-the-fly
    obf_Decoded = ""
    For obf_Counter = 1 To Len(obf_Decoded2)
        obf_Decoded = obf_Decoded & Chr((Asc(Mid(obf_Decoded2, obf_Counter, 1)) + 35) Mod 256)
    Next

    obf_DecodeBaseText64 = obf_Decoded
    Exit Function
End Function

Private Function obf_DecodeBase64(ByVal obf_EncodedData)
    Dim obf_temp
    obf_temp = obf_DecodeBaseText64(obf_EncodedData)
    obf_DecodeBase64 = obf_StringToBinary(obf_temp)
End Function
