mirror of
https://github.com/OALabs/hashdb
synced 2026-06-08 12:05:11 +00:00
ed39b03997
the new test string is longer and more complex to cut down on false collisions
37 lines
1.6 KiB
Python
37 lines
1.6 KiB
Python
#!/usr/bin/env python
|
|
########################################################################
|
|
# Copyright 2012 Mandiant
|
|
# Copyright 2014 FireEye
|
|
#
|
|
# Mandiant licenses this file to you under the Apache License, Version
|
|
# 2.0 (the "License"); you may not use this file except in compliance with the
|
|
# License. You may obtain a copy of the License at:
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
|
# implied. See the License for the specific language governing
|
|
# permissions and limitations under the License.
|
|
#
|
|
# Reference:
|
|
# https://github.com/mandiant/flare-ida/blob/master/shellcode_hashes/make_sc_hash_db.py
|
|
#
|
|
########################################################################
|
|
|
|
DESCRIPTION = "SHIFT and XOR with 0x82F63B78"
|
|
TYPE = 'unsigned_int'
|
|
TEST_1 = 1838188878
|
|
|
|
|
|
def hash(data):
|
|
val = 0
|
|
for i in data:
|
|
v1 = ((((i | 0x20) ^ val) >> 1) ^ (0x82F63B78 * (((i | 0x20) ^ val) & 1))) & 0xffffffff
|
|
v2 = ((((v1 >> 1) ^ (0x82F63B78 * (v1 & 1))) >> 1) ^ (0x82F63B78 * (((v1 >> 1) ^ (0x78 * (v1 & 1))) & 1))) & 0xffffffff
|
|
v3 = ((((v2 >> 1) ^ (0x82F63B78 * (v2 & 1))) >> 1) ^ (0x82F63B78 * (((v2 >> 1) ^ (0x78 * (v2 & 1))) & 1))) & 0xffffffff
|
|
v4 = ((((v3 >> 1) ^ (0x82F63B78 * (v3 & 1))) >> 1) ^ (0x82F63B78 * (((v3 >> 1) ^ (0x78 * (v3 & 1))) & 1))) & 0xffffffff
|
|
val = ((v4 >> 1) ^ (0x82F63B78 * (v4 & 1))) & 0xffffffff
|
|
return val ^ 0xBC
|