Vector35 / Vector35/binaryninja-api

Incorrect MLIL->HLIL lifting for obfuscated code

Open
#5,388 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Component: Core Core: HLIL Effort: Medium Impact: Medium
Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

For the following code, the last instruction should be something like:

0040121c          int32_t eax_4 = counter
0040121c          counter = eax_4 + 1

which basically increments the counter variable by 1. However, the HLIL is wrong:

Screenshot 2024-05-10 at 2 00 24 PM

The input file is an obfuscated with junk code, and I have highlighted the relevant instructions:

Screenshot 2024-05-10 at 2 02 15 PM

BNDB:
keygenme4.exe.bndb.zip

I verified the lifting is correct till MLIL, but it becomes wrong in HLIL.

Screenshot 2024-05-10 at 2 04 05 PM

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the attached keygenme4.exe.bndb.zip and compare the highlighted MLIL with the incorrect HLIL for the counter update. Trace the MLIL-to-HLIL lifting path for this obfuscated case and verify the fix by confirming that HLIL represents the increment correctly on the supplied BNDB.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.