I'm trying to interpret PE executable files with Node.js as a research project.
I'm disassembling the instructions with Ghidra and built out all my x86-64 registers (JSFiddle, working as far as the registry goes but instruction parsing has a long way to go), like so:
#!/bin/bash
files=`ls /mnt/c/...snip.../executable-disassembler-ghidra/node/executables`
for file in $files
do
/mnt/c/Users/...snip.../executable-disassembler-ghidra/node/ghidra/support/analyzeHeadless /mnt/c/Users/...snip.../executable-disassembler-ghidra/node/project my-project -import /mnt/c/Users/...snip.../executable-disassembler-ghidra/node/executables/$file -postScript IterateInstructionsScript.java -scriptlog /mnt/c/Users/...snip.../data/disassembled/ghidra/raw/$file.txt
done
and after a little parsing:
[
{
"source": "0040205c ADD byte ptr [EDX + 0x1] DH ",
"addressHex": "0040205c",
"addressDec": 4202588,
"instruct": "ADD byte ptr [EDX + 0x1] DH",
"instructParts": [
"ADD",
"byte",
"ptr",
"[EDX",
"+",
"0x1]",
"DH"
]
},
{
"source": "0040205f ADD byte ptr [EAX] AL ",
"addressHex": "0040205f",
"addressDec": 4202591,
"instruct": "ADD byte ptr [EAX] AL",
"instructParts": [
"ADD",
"byte",
"ptr",
"[EAX]",
"AL"
]
},
{
"source": "00402061 JO 0x0040208b ",
"addressHex": "00402061",
"addressDec": 4202593,
"instruct": "JO 0x0040208b",
"instructParts": [
"JO",
"0x0040208b"
]
},
{
"source": "00402063 SLDT dword ptr [EAX] ",
"addressHex": "00402063",
"addressDec": 4202595,
"instruct": "SLDT dword ptr [EAX]",
"instructParts": [
"SLDT",
"dword",
"ptr",
"[EAX]"
]
},
...
]
And as I follow the instructions, I interpret them and read / write values to the registry, memory, and storage:
instructionData {instruct: "ADD byte ptr [EDX + 0x1] DH", nextAddress: 4202591}
mnemonic: ADD
operandsStr: byte ptr [EDX + 0x1] DH
operandParts: (4) ["byte", "ptr", "[EDX + 0x1]", "DH"]
But I haven't parsed out the .data sections of the exes and although I'm reading the PE file format documentation, and found an NPM module that might point me to the correct .data address (maybe "base_of_data"?) in the file, I'm unsure if that's the correct way:
- There are many sections.
- I don't know if I'll need other sections than .data as I try to parse the instructions.
- I don't know whether the data addresses referenced in the assembly code are meant to be offset from the beginning of the PE file or somewhere else
Could someone explain exactly what sections I'll need, and how I can extract those sections (or just .data) with Node.js? I don't want to reinvent the wheel for every component of my project if there are trivial alternatives or easier answers.