ट्रेस-सहायित VMProtect डीवर्चुअलाइज़ेशन अनुसंधान प्लेटफ़ॉर्म: संस्करण फ्रंट-एंड एक साझा Remill/LLVM बैकएंड को फ़ीड करते हैं ताकि हैंडलर को लिफ्ट किया जा सके, डेटाफ़्लो रिकवर किया जा सके, और नेटिव ऑब्जेक्ट्स उत्पन्न किए जा सकें।
ट्रेस-सहायित VMProtect डीवर्चुअलाइज़ेशन अनुसंधान: संस्करण फ्रंट-एंड (1.x गेट / 2.x टेबल / 3.x FDJ) एक साझा बैकएंड को फीड करते हैं (Remill लिफ्ट → LLVM ऑप्ट → सिमेंटिक कार्ड → डेटाफ्लो → नेटिव ऑब्जेक्ट)।
कई सुरक्षा मोड में स्व-निर्मित VMP 3.9.4 बाइनरीज़ के विरुद्ध सत्यापित। VMP 3.8.x/3.10.x संगतता प्रयोगात्मक और नमूना-निर्भर है।
यह उन VMProtect-संरक्षित बाइनरीज़ के विश्लेषण के लिए एक अनुसंधान प्लेटफ़ॉर्म है जिनका आप स्वामी हैं या जिन्हें रिवर्स इंजीनियर करने का लाइसेंस आपके पास है — यह एक सार्वभौमिक, पुश-बटन डीवर्चुअलाइज़र नहीं है:
src/
lib.rs crate root, data_dir()
pe_loader.rs PE parsing / VA reads
opcode_map.rs canonical 3.5.1 opcode -> handler map
frontend/
mod.rs VmFrontend trait (detect/fetch_stream/handler_addrs)
fetch_finder.rs movzx-byte FDJ scan + watchset/snapshot helpers
cryptor_miner.rs per-site ValueCryptor mining (branch-following)
site_emulator.rs sample-specific oracle decoders (legacy)
handler_classifier.rs handler classification via legacy patterns
classifier_legacy.rs first-bytes patterns (weak; fallback only)
v1_gate.rs VMP 1.x gate-scan front-end
v2_walker.rs VMP 2.x dispatch-table front-end
v3_fdj.rs VMP 3.x FDJ front-end
backend/
value_cryptor.rs ADD/SUB/XOR/ROL/ROR/NOT/NEG/... chains
lifter.rs iced-x86 text lift + Remill subprocess backend
llvm_pipeline.rs opt -O3 over Remill IR (real passes)
harness/
snapshot.rs Unicorn snapshots: sections+scratch mapping,
IN hooks, import stubs, watch hits, memlog,
zero-slide fast-forward
tests/
smoke.rs synthetic PE64 + hand-built fetch chain (no fixtures)
tools/ (analysis drivers; each documents its inputs)
scripts/ Triton/angr/Ghidra helpers (external deps)
# Debian/Ubuntu (LLVM 22 for optional llvm feature)
sudo apt install llvm-22-dev libclang-22-dev clang-22
cargo build --release # pure Rust (no LLVM link)
cargo build --release --features llvm # llvm-sys link check
pip install triton-library capstone pefile # python helpers
# Remill (optional lifter backend): build upstream, export REMILL_LIFT=<path>/remill-lift
# Souper (optional MBA superoptimizer): external only, wire its `souper` CLI
# to scripts/triton_handlers.py output if desired; not vendored.
Dockerfile पूर्ण env को पुनरुत्पादित करता है। CI cargo build/test --release
चलाता है (डिफ़ॉल्ट फ़ीचर, कोई LLVM लिंक नहीं, कोई व्यावसायिक फ़िक्स्चर नहीं;
नमूना-गेटेड टेस्ट स्किप होते हैं, tests/smoke.rs हमेशा चलता है)। वैकल्पिक
--features llvm लिंक चेक एक नॉन-ब्लॉकिंग CI जॉब के रूप में चलता है
(LLVM 22 चाहिए)।
| Var | Default | Meaning |
|---|---|---|
DATA_DIR | ./data | all tool artifacts |
WATCH_FILE | $DATA_DIR/watch.txt | fetch VAs to watch |
CARDS | open_cards3.json | Remill card cache file |
BIN_PATH | target binary path (tools default: ./target.exe placeholder) | target binary |
IAT_JSON | — | {api_name: iat_va} import stub map |
VMP_TEST_BIN / VMP_ORACLE | tests/fixtures/… | licensed-sample tests |
REMILL_LIFT | remill-lift-22 on PATH | Remill lift binary |
DEVIRT / FORCE_EDGE / REPO_ROOT | ./target/… / . | script-called binaries + repo root |
VMP_WORK_DIR | system temp | lift scratch |
EFLAGS / IN_RET / DLL_MAIN | — | snapshot state variants |
ret, इम्पोर्ट स्टब, IN हुक)।movzx byte [reg] स्टैटिक पैटर्न को
मात देता है — हार्डन्ड लक्ष्यों पर स्टैटिक-ओनली हिट 0% निष्पादन पर मापे गए)।opt -O3, कार्ड/डेटाफ्लो
उत्सर्जित करें, llc के साथ रीकंपाइल करें (ld -r कंपोज़ेबिलिटी सिद्ध करता है)।MIT (LICENSE देखें) निर्भरता नोट्स के साथ (विशेष रूप से Unicorn GPL-2.0)। केवल अनुसंधान/शैक्षिक उपयोग के लिए, उन बाइनरीज़ पर जिनका आप स्वामी हैं या जिनका विश्लेषण कर सकते हैं।