can1357/NoVmp

Function classification problems

leecher1337 opened this issue · 0 comments

Some functions could not be detected with the current analyzer. Here is a list of the combinations that weren't detected and what they should have supposedly been:

VPOPV*

[!] Warning: Failed to clasify the instruction:
000000000155CB48: mov rcx, qword ptr [r11]
FFFFFFFFFFFFFFFF: loadc dil, 104
000000000155CB9C: mov qword ptr [rsp + rdi], rcx
FFFFFFFFFFFFFFFF: loadc ebx, 19303
00000000014E4B32: movsxd rbx, ebx
00000000014E4B35: add rsi, rbx

[!] Warning: Failed to clasify the instruction:
000000000156F003: mov rdx, qword ptr [r11]
000000000156F011: mov rdi, qword ptr ss:[rdx]
000000000156F015: mov qword ptr [r11], rdi
FFFFFFFFFFFFFFFF: loadc ecx, 4294643413
00000000015982C9: movsxd rcx, ecx
00000000015982CC: add rsi, rcx

VADDU*

[!] Warning: Failed to clasify the instruction:
000000000154FBFF: mov r10, qword ptr [r11]
000000000154FC08: mov rbx, qword ptr [r11 + 8]
000000000154FC13: add r10, rbx
000000000154FC16: mov qword ptr [r11 + 8], r10
000000000154FC1D: pushfq
000000000154FC1E: pop qword ptr [r11]
FFFFFFFFFFFFFFFF: loadc edi, 4294336794
00000000014E1809: movsxd rdi, edi
00000000014E6011: add rsi, rdi

VSHRU*

[!] Warning: Failed to clasify the instruction:
00000000015616AF: mov rdx, qword ptr [r11]
00000000015616B5: mov cl, byte ptr [r11 + 8]
00000000015616B9: sub r11, 6
00000000015616C0: shr rdx, cl
00000000015616C6: mov qword ptr [r11 + 8], rdx
00000000015616CA: pushfq
00000000015616D3: pop qword ptr [r11]
FFFFFFFFFFFFFFFF: loadc ecx, 70933
00000000014B8461: movsxd rcx, ecx
00000000014B846B: add rsi, rcx

VPUSHC*

[!] Warning: Failed to clasify the instruction:
FFFFFFFFFFFFFFFF: loadc rcx, 18446744073709551615
00000000015A8770: sub r11, 8
00000000015A877F: mov qword ptr [r11], rcx
FFFFFFFFFFFFFFFF: loadc ebx, 4294358120
000000000151FA1B: movsxd rbx, ebx
000000000151FA27: add rsi, rbx

[!] Warning: Failed to clasify the instruction:
FFFFFFFFFFFFFFFF: loadc bl, 112
00000000015FA838: mov rax, qword ptr [rsp + rbx]
00000000015FA848: sub r11, 8
00000000015FA84F: mov qword ptr [r11], rax
FFFFFFFFFFFFFFFF: loadc r10d, 4294899004
000000000158A477: movsxd r10, r10d
000000000158A47A: add rsi, r10

[!] Warning: Failed to clasify the instruction:
00000000015EDFE9: mov rax, r11
00000000015EDFF3: sub r11, 8
00000000015EDFFA: mov qword ptr [r11], rax
FFFFFFFFFFFFFFFF: loadc edx, 4294447130
000000000150DE1D: movsxd rdx, edx
000000000150DE25: add rsi, rdx

VNORU*

[!] Warning: Failed to clasify the instruction:
00000000014DCCB4: mov rdi, qword ptr [r11]
00000000014DCCC2: mov r10, qword ptr [r11 + 8]
00000000014DCCC6: not rdi
00000000014DCCCE: not r10
00000000014DCCD5: and rdi, r10
00000000014DCCD8: mov qword ptr [r11 + 8], rdi
00000000014DCCE0: pushfq
00000000014DCCF0: pop qword ptr [r11]
FFFFFFFFFFFFFFFF: loadc r10d, 168336
0000000001563336: movsxd r10, r10d
0000000001563344: add rsi, r10

VNANDU*

[!] Warning: Failed to clasify the instruction:
00000000015E8959: mov rcx, qword ptr [r11]
00000000015E8962: mov rdi, qword ptr [r11 + 8]
00000000015E8970: not rcx
00000000015E8978: not rdi
00000000015E8981: or rcx, rdi
00000000015E8987: mov qword ptr [r11 + 8], rcx
0000000001581D90: pushfq
0000000001581D99: pop qword ptr [r11]
FFFFFFFFFFFFFFFF: loadc eax, 4294128860
00000000015F072C: movsxd rax, eax
00000000015F072F: add rsi, rax

Unknown

[!] Warning: Failed to clasify the instruction:
0000000001542312: movabs rbx, 0
0000000001542323: shrd esi, ebx, 0x4e
0000000001542327: or sil, cl
000000000154232A: lea rsi, [rip - 7]
FFFFFFFFFFFFFFFF: loadc edi, 24373215
00000000015EBA66: movsxd rdi, edi
00000000015EBA71: add rsi, rdi

[!] Warning: Failed to clasify the instruction:
00000000014BA360: add rbx, 8
0000000001542312: movabs rbx, 0
0000000001542323: shrd esi, ebx, 0x4e
0000000001542327: or sil, cl
000000000154232A: lea rsi, [rip - 7]
FFFFFFFFFFFFFFFF: loadc edi, 774888035
00000000015EBA66: movsxd rdi, edi
00000000015EBA71: add rsi, rdi