Vector35 / Vector35/binaryninja-api

Incorrect stack variable tracking in x86 Windows PE

Open
#7,382 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Component: Core Effort: Medium Impact: Medium Scenario: Malware
Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

Binary: numeric mirror sees sharply

Image

We can see that volumeSerialNumber appears to have been obtained but never used again, and down a little bit there is a call

sub_4091c8(&ebp_1[-5], 8)

In which ebp_1[-5] is actually the volumeSerialNumber. I do not know what exactly is causing the issue, but it is likely related to stack pointer/variable tracking

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by examining the reported x86 Windows PE binary, numeric mirror sees sharply, and the stack-variable tracking around sub_4091c8(&ebp_1[-5], 8). Confirm why ebp_1[-5] is not associated with volumeSerialNumber; done means the decompilation correctly tracks that variable and its later use.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.