def niceHex(num):
hexnum = hex(num)
return hexnum[: len(hexnum) - 1]
def stringOffset(loc):
global lastStr
str = idc.get_bytes(idc.get_operand_value(loc, 0), 128)
if str.startswith("Py"):
lastStr = str
def eaxMov(loc, run = False):
global lastStr
print "@", niceHex(loc), " | ", idc.generate_disasm_line(loc, 0), " [eax -> ", lastStr, "]"
if run:
idc.set_name(idc.get_operand_value(loc, 0), lastStr)
lastStr = ""
locs = list(idautils.FuncItems(here()))
for loc in locs:
isEaxMov = idc.print_insn_mnem(loc) == "mov" and idc.get_operand_type(loc, 0) == 2
isStringOffset = idc.print_insn_mnem(loc) == "push" and idc.get_operand_type(loc, 0) == 5
if isStringOffset:
stringOffset(loc)
if isEaxMov:
eaxMov(loc, False)
Comments