-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathcmbb_groundtruth.txt
3 lines (3 loc) · 1009 Bytes
/
cmbb_groundtruth.txt
1
2
3
trigger|mov rax, DS:[rip + 0x203a8e]#mov rax, DS:[rax]#mov rax, DS:[rax]#cmp DS:[rbp + 0xfffffffffffffff0], rax#jnz 0xd
encode|mov rax, DS:[rbp + 0xfffffffffffffff0]#mov eax, DS:[rax]#mov edi, eax#call 0xffffffffffffff1c#push rbp#mov rbp, rsp#sub rsp, 0x20#mov DS:[rbp + 0xffffffffffffffec], edi#mov eax, DS:[rbp + 0xffffffffffffffec]#cdqe rax#mov rax, DS:[8*rax + 0x604060]#mov DS:[rbp + 0xfffffffffffffff8], rax#mov rax, DS:[rbp + 0xfffffffffffffff8]#call rax
recover|rdtscp#mov DS:[rbp + 0xffffffffffffffcc], eax#mov DS:[rbp + 0xffffffffffffffc8], edx#mov eax, DS:[rbp + 0xffffffffffffffcc]#mov edx, DS:[rbp + 0xffffffffffffffc8]#sal rdx, 0x20#or rax, rdx#mov r12, rax#mov edi, ebx#call 0xfffffffffffffdcf#push rbp#mov rbp, rsp#sub rax, 0x20#mov DS:[rbp + 0xffffffffffffffec], edi#mov eax, DS:[rbp + 0xffffffffffffffec]#cdqe rax#mov rax, DS:[8*rax + 0x604060]#mov DS:[rbp + 0xfffffffffffffff8], rax#mov rax, DS:[rbp + 0xfffffffffffffff8]#call rax#push rbp#mov rbp, rsp#NOP#pop rbp#ret#NOP#leave#ret#rdtscp