import re
import os

os.chdir(r"d:\DISK-D\na3papki\land-2")

for f in ["js/min.js", "js/loader.js"]:
    print("=====", f, "=====")
    text = open(f, "r", encoding="utf-8", errors="replace").read()
    print("len", len(text))
    patterns = [
        "root/root", "root1", "root2", "cb-lb", "checkbox", "Verify",
        "One more", "innerHTML", "appendChild", "createElement", "loader",
        "tochks", "challenge", "turnstile", "ctp-", "Verify you", "human",
        "addEventListener", "getElementById", "#content", "cb-c", "cb-i",
        "success", "verifying", "config.js", "config.php", "main-wrapper",
        "branding", "terms", "vrf", "wn", "content", "createScript",
        "fetch(", "XMLHttpRequest", ".html", "click", "onchange",
        "powershell", "codeforcopy", "await",
    ]
    for p in patterns:
        idxs = []
        start = 0
        low = text.lower()
        pl = p.lower()
        while True:
            i = low.find(pl, start)
            if i < 0:
                break
            idxs.append(i)
            start = i + len(p)
            if len(idxs) >= 6:
                break
        if not idxs:
            print(f"[{p}] not found")
            continue
        for i in idxs:
            snip = text[max(0, i - 60) : i + 100].replace("\n", " ").replace("\r", " ")
            print(f"[{p}] @{i}: ...{snip}...")

    lit = re.findall(r"['\"]([^'\"]{4,160})['\"]", text)
    print("--- unique interesting literals ---")
    seen = set()
    for s in lit:
        if re.search(
            r"root|html|css|cb-|check|verify|human|step|turnstile|ctp|loader|config|content|branding|terms|success|spinner|vrf|tochk|iframe|script|One more|Cloudflare|checkbox|main-wrap|createElement|innerHTML|append|body|head|fetch|get\(|load",
            s,
            re.I,
        ):
            if s not in seen:
                seen.add(s)
                print(repr(s)[:220])
                if len(seen) >= 150:
                    break

    # Try to resolve string array for min.js style
    m = re.search(r"function _0x33de\(\)\{const _0x\w+=\[(.*?)\];_0x33de=function", text, re.S)
    if not m:
        m = re.search(r"function _0x401a\(\)\{const _0x\w+=\[(.*?)\];_0x401a=function", text, re.S)
    if not m:
        # alternate patterns
        m = re.search(r"function (_0x\w+)\(\)\{(?:const|var) _0x\w+=\[(.*?)\];\1=function", text, re.S)
        arr_body = m.group(2) if m else None
    else:
        arr_body = m.group(1)
    if arr_body:
        arr = re.findall(r"'((?:\\'|[^'])*)'|\"((?:\\\"|[^\"])*)\"", arr_body)
        vals = [(a or b).encode("utf-8").decode("unicode_escape") for a, b in arr]
        print(f"--- string array ({len(vals)} entries), filtered ---")
        for v in vals:
            if re.search(
                r"root|html|css|cb|check|verify|human|step|content|brand|term|success|spinner|vrf|tochk|iframe|script|cloud|loader|config|inner|append|create|body|fetch|click|input|checkbox|main-|One more|window|powershell|code",
                v,
                re.I,
            ):
                print(repr(v)[:300])
    else:
        print("--- no string array matched ---")
        # dump first 500 chars of decoded-looking contiguous ASCII after array start
        m2 = re.search(r"function (_0x\w+)\(\)", text)
        print("first fn", m2.group(1) if m2 else None)
