24 lines
1.1 KiB
Java
24 lines
1.1 KiB
Java
// Emits the opaque direct callee reached by corpus-reachable AI VM Handler(2).
|
|||
|
|
// Run through Ghidra headless analysis; the original PE remains read only.
|
||
|
|
import ghidra.app.decompiler.DecompInterface;
|
||
|
|
import ghidra.app.script.GhidraScript;
|
||
|
|
import ghidra.program.model.address.Address;
|
||
|
|
import ghidra.program.model.listing.Function;
|
||
|
|
|
||
|
|
public class ExportAiVmHandler2Callee extends GhidraScript {
|
||
|
|
private static final long ADDRESS = 0x100059f0L;
|
||
|
|
|
||
|
|
@Override
|
||
|
|
public void run() throws Exception {
|
||
|
|
Address address = currentProgram.getAddressFactory().getDefaultAddressSpace()
|
||
|
|
.getAddress(ADDRESS);
|
||
|
|
Function function = currentProgram.getFunctionManager().getFunctionAt(address);
|
||
|
|
println("===== AI VM Handler(2) direct callee =====");
|
||
|
|
if (function == null) { println("missing"); return; }
|
||
|
|
DecompInterface decompiler = new DecompInterface();
|
||
|
|
decompiler.openProgram(currentProgram);
|
||
|
|
println(decompiler.decompileFunction(function, 60, monitor).getDecompiledFunction().getC());
|
||
|
|
decompiler.dispose();
|
||
|
|
}
|
||
|
|
}
|