YOU ACTUALLY OPEN 34– 330– 55 MB 500 MB cache disassembly ~50 MB decompiled — Too big to read linearly — tens of thousands of functions, most of it bundled dependency code. — The JavaScript was obfuscated before it was compiled — the malware logic stayed hidden. A milestone — not yet the summit. // … thousands of functions like this … function func_Mz_0x10000000f(a0) { r5 = Scope[0] r2 = func_r_0x10000000b r0 = new {"w": 126853, "d": "741^", "J": 166834, "m": "!Rgf", "H": 187083, "U": "*LaG", "F": 1182, "r": "Zj4P", "I": 37217, "x": " Scope[6705][2] = new {"w": 1342} r6 = new {"jGBGz": null, "hBPBb": null, "qbyOP": null, "ykkYm": null, "SeAyf": null, "yHrsY": null, "umIdy": null, "RBgqe": null} r7 = func_r_0x10000000b(r0["w"], r0["d"]) r6["jGBGz"] = (r7 + func_r_0x10000000b(r0["J"], r0["m"])) r6["hBPBb"] = func_hBPBb_0x10000000c r6["qbyOP"] = func_r_0x10000000b(r0["H"], r0["U"]) r6["ykkYm"] = func_ykkYm_0x10000000d r6["SeAyf"] = func_SeAyf_0x10000000e r6["yHrsY"] = func_r_0x10000000b(r0["F"], r0["r"]) r6["umIdy"] = func_r_0x10000000b(r0["I"], r0["x"]) r7 = func_r_0x10000000b(r0["X"], r0["p"]) r7 = (r7 + func_r_0x10000000b(r0["a"], r0["g"])) r7 = (r7 + func_r_0x10000000b(r0["h"], r0["p"])) r6["RBgqe"] = (r7 + "l") r1 = r6 r7 = r1[func_r_0x10000000b(r0["k"], r0["z"])] r6 = r7[func_r_0x10000000b(r0["b"], r0["c"])] r3 = r6("|") r4 = 0 while (true) { r7 = Number(r4) r4 = (Number(r4) + 1) r6 = r3[r7] if (!r6 === "0") { if (!r6 === "1") { if (!r6 === "2") { if (! 6 "3")