3 ms·
Looks like it's also relying on LLVM for disassembly? Ouch; that's an incredibly bad idea if you're trying to analyze malicious or unusual code (it's not design
by Tobba_ 9y ago
Looks like it's also relying on LLVM for disassembly? Ouch; that's an incredibly bad idea if you're trying to analyze malicious or unusual code (it's not designed for that), but I guess it's the easiest for a proof of concept like this.
Although, there's no way an AV company doesn't have its own disassembler, but those are almost always treated as trade secrets (especially the stuff that isn't in the spec / the spec is wrong). They'll probably hook it up to that before doing any real work with it themselves.
- UncleEntity 9y ago> Looks like it's also relying on LLVM for disassembly? [wild speculation here] I suspect they're using llvm to go from an ast to c(++) code since they have tooling for stuff like that. Now I have to find me a binary-blob kernel module that manufactures like to put out and see what the C code it spits out looks like -- another wasted day methinks...
- Tobba_ 9y agoYou could just ..uh.. acquire a copy of IDA that has the AMD64 decompiler. It's more mature and spits out C code of wildly varying readability, though only for one function at a time.
- bringtheaction 9y ago> proof of concept They've been working on this for 7 years they said so I don't think it counts as just a PoC.
- Karliss 9y agoIsn't it using capstone?
- Tobba_ 9y agoDoesn't look that way? https://github.com/avast-tl/retdec/blob/master/src/bin2llvmir/providers/asm_instruction.cpp#L28 https://github.com/avast-tl/retdec/blob/master/src/bin2llvmi... Capstone would probably be the best open-source choice for something like this though.
- Karliss 9y agoThere is also capstone2llvmir in https://github.com/avast-tl/retdec/tree/master/deps https://github.com/avast-tl/retdec/tree/master/deps