Vector35 / Vector35/binaryninja-api
Incorrect MLIL->HLIL lifting for obfuscated code
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 1.3k
- Forks
- 298
- Avg merge
- 5d 5h
- Merged PRs (30d)
- 19
Description
For the following code, the last instruction should be something like:
0040121c int32_t eax_4 = counter
0040121c counter = eax_4 + 1
which basically increments the counter variable by 1. However, the HLIL is wrong:
The input file is an obfuscated with junk code, and I have highlighted the relevant instructions:
BNDB:
keygenme4.exe.bndb.zip
I verified the lifting is correct till MLIL, but it becomes wrong in HLIL.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the attached keygenme4.exe.bndb.zip and compare the highlighted MLIL with the incorrect HLIL for the counter update. Trace the MLIL-to-HLIL lifting path for this obfuscated case and verify the fix by confirming that HLIL represents the increment correctly on the supplied BNDB.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp
- Domain
- reverse-engineering
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100