EtwpValidatePayloadFilter
INT64 __fastcall EtwpValidatePayloadFilter(
const _GUID *ProviderGuid,
_AGGREGATED_PAYLOAD_FILTER *PayloadFilter,
UINT64 Size){
__int16 v5;
int PredicateCount;
__int64 EachEventTableOffset;
int v8;
int v9;
unsigned __int64 EachEventTableLength;
__int64 PayloadDecoderTableOffset;
int v12;
unsigned int PayloadDecoderTableLength;
__int64 EventFilterTableOffset;
int v15;
unsigned int EventFilterTableLength;
int UNICODEStringTableOffset;
int v18;
unsigned int UNICODEStringTableLength;
int v20;
unsigned int v21;
int v22;
char *v23;
_WORD *v24;
char *v25;
unsigned int v26;
unsigned int v27;
_EVENT_PAYLOAD_PREDICATE *PredicateTable;
int v29;
__int64 v30;
unsigned int v31;
char *v32;
unsigned int v33;
unsigned int v34;
unsigned int v35;
unsigned int v36;
unsigned int v37;
__int64 FieldIndex;
int v39;
char *v40;
int v41;
char *v42;
char *v43;
__int64 v44;
char *v45;
int v46;
char *v47;
char *v48;
int v49;
int v51;
int v52;
int v53;
char *v54;
int ANSIStringTableLength;
char *v56;
char *v57;
unsigned int v58;
unsigned int v59;
_WORD *v60;
char *v61;
__int64 ANSIStringTableOffset;
__int64 v63;
int v64;
int v65;
if( (unsigned int)Size >= 0x50 && PayloadFilter->Size == (_DWORD)Size && (unsigned int)Size <= 0x1000 )
{
v5 = *(_WORD *)PayloadFilter;
if( (v5 & 0xFFF) == 2662 && (v5 & 0xF000) == 4096 )
{
PredicateCount = PayloadFilter->PredicateCount;
if( (unsigned __int16)PredicateCount <= 0xAAu
&& !PayloadFilter->Reserved
&& *(_QWORD *)&ProviderGuid->Data1 == *(_QWORD *)&PayloadFilter->ProviderGuid.Data1
&& *(_QWORD *)ProviderGuid->Data4 == *(_QWORD *)PayloadFilter->ProviderGuid.Data4 )
{
EachEventTableOffset = PayloadFilter->EachEventTableOffset;
v8 = 24 * PredicateCount + 56;
v9 = PayloadFilter->PredicateCount;
if( (_DWORD)EachEventTableOffset == v8 )
{
EachEventTableLength = PayloadFilter->EachEventTableLength;
PayloadDecoderTableOffset = PayloadFilter->PayloadDecoderTableOffset;
v12 = EachEventTableLength + v8;
if( (_DWORD)PayloadDecoderTableOffset == v12 )
{
PayloadDecoderTableLength = PayloadFilter->PayloadDecoderTableLength;
EventFilterTableOffset = PayloadFilter->EventFilterTableOffset;
v15 = PayloadDecoderTableLength + v12;
if( (_DWORD)EventFilterTableOffset == v15 )
{
EventFilterTableLength = PayloadFilter->EventFilterTableLength;
UNICODEStringTableOffset = PayloadFilter->UNICODEStringTableOffset;
v18 = EventFilterTableLength + v15;
if( UNICODEStringTableOffset == v18 )
{
UNICODEStringTableLength = PayloadFilter->UNICODEStringTableLength;
v20 = UNICODEStringTableLength + v18;
if( PayloadFilter->ANSIStringTableOffset == v20 )
{
ANSIStringTableLength = PayloadFilter->ANSIStringTableLength;
if( (_DWORD)Size == ANSIStringTableLength + v20
&& EachEventTableLength == 12 * (EachEventTableLength / 0xC)
&& (PayloadDecoderTableLength & 3) == 0
&& (EventFilterTableLength & 3) == 0
&& (UNICODEStringTableLength & 1) == 0
&& (EachEventTableOffset & 3) == 0
&& (PayloadDecoderTableOffset & 3) == 0
&& (EventFilterTableOffset & 3) == 0
&& (UNICODEStringTableOffset & 3) == 0 )
{
v21 = PayloadDecoderTableLength >> 2;
v22 = 0;
v52 = 0;
v23 = (char *)PayloadFilter + PayloadDecoderTableOffset;
v51 = 0;
v24 = (_WORD *)((char *)PayloadFilter + EventFilterTableOffset);
v64 = 0;
v25 = (char *)PayloadFilter + EachEventTableOffset;
v65 = 0;
v26 = EventFilterTableLength >> 2;
v27 = UNICODEStringTableLength >> 1;
PredicateTable = PayloadFilter->PredicateTable;
v58 = (unsigned int)EachEventTableLength / 0xC;
v56 = (char *)PayloadFilter + PayloadFilter->UNICODEStringTableOffset;
ANSIStringTableOffset = PayloadFilter->ANSIStringTableOffset;
v29 = 0;
v59 = v27;
v57 = (char *)PayloadFilter + ANSIStringTableOffset;
v61 = v23;
v30 = 0i64;
v60 = v24;
v53 = 0;
if( (unsigned int)EachEventTableLength / 0xC )
{
while( 1 )
{
v63 = v30 | (1i64 << (*(_WORD *)v25 % 0x3Fu));
if( *((unsigned __int16 *)v25 + 2) != v29 )
break;
v31 = *((unsigned __int16 *)v25 + 3);
if( v31 > v21 - v29 )
break;
v29 += v31;
v32 = v23;
v33 = 0;
v54 = v23;
if( *((_WORD *)v25 + 3) )
{
while( *((_WORD *)v23 + 1) < 0x40u
&& (unsigned __int8)v23[1] < 0x40u
&& (unsigned __int8)*v23 < 0x40u
&& (*v23 & 0xFu) < 9 )
{
v23 += 4;
++v33;
v61 = v23;
if( v33 >= v31 )
goto LABEL_33;
}
return 3221225485i64;
}
LABEL_33:
if( *((unsigned __int16 *)v25 + 4) != v51 )
break;
v34 = *((unsigned __int16 *)v25 + 5);
if( v34 > v26 - v51 )
break;
v22 = v34 + v51;
v51 += v34;
v35 = 0;
if( *((_WORD *)v25 + 5) )
{
while( (*v24 & 0xFCu) <= 0x20 )
{
if( (unsigned __int16)v24[1] != v52 )
break;
v36 = (unsigned __int8)*v24 >> 2;
if( v36 > v9 - v52 )
break;
v52 += v36;
v37 = 0;
if( v36 )
{
while( 1 )
{
FieldIndex = PredicateTable->FieldIndex;
if( (unsigned int)FieldIndex >= v21
|| (unsigned __int16)FieldIndex >= (unsigned __int16)v31
|| (unsigned __int16)FieldIndex > (unsigned __int8)v25[3] )
{
return 3221225485i64;
}
v39 = (v32[4 * FieldIndex] & 0xF) - 3;
if( !v39 )
break;
if( v39 == 1 )
{
if( PredicateTable->Value[0] != v64 || PredicateTable->Value[1] )
return 3221225485i64;
v40 = v56;
v41 = v64;
v42 = (char *)PayloadFilter
+ PayloadFilter->UNICODEStringTableOffset
+ (unsigned __int64)PayloadFilter->UNICODEStringTableLength;
v9 = PayloadFilter->PredicateCount;
if( *(_WORD *)v56 )
{
do
{
if( v40 >= v42 - 2 )
break;
v40 += 2;
}
while( *(_WORD *)v40 );
v9 = PayloadFilter->PredicateCount;
v41 = v64;
}
v43 = v40 + 2;
if( v43 > v42 )
return 3221225485i64;
v44 = (v43 - v56) >> 1;
v56 = v43;
v64 = v44 + v41;
LABEL_61:
v32 = v54;
}
++v37;
++PredicateTable;
if( v37 >= v36 )
goto LABEL_63;
}
if( PredicateTable->Value[0] != v65 || PredicateTable->Value[1] )
return 3221225485i64;
v45 = v57;
v46 = v65;
v47 = (char *)PayloadFilter
+ ANSIStringTableOffset
+ (unsigned __int16)ANSIStringTableLength;
if( *v57 )
{
do
{
if( v45 >= v47 - 1 )
break;
++v45;
}
while( *v45 );
v46 = v65;
}
v48 = v45 + 1;
if( v48 > v47 )
return 3221225485i64;
v49 = (_DWORD)v48 - (_DWORD)v57;
v57 = v48;
v65 = v49 + v46;
goto LABEL_61;
}
LABEL_63:
++v35;
v24 = v60 + 2;
v60 += 2;
if( v35 >= v34 )
{
v23 = v61;
v22 = v51;
goto LABEL_65;
}
}
return 3221225485i64;
}
LABEL_65:
v25 += 12;
v30 = v63;
if( ++v53 >= v58 )
{
v27 = v59;
goto LABEL_67;
}
}
}
else
{
LABEL_67:
if( v30 == PayloadFilter->HashedEventIdBitmap
&& v52 == v9
&& v29 == v21
&& v22 == v26
&& v64 == v27
&& v65 == ANSIStringTableLength )
{
return 0i64;
}
}
}
}
}
}
}
}
}
}
}
return 3221225485i64;
}Referenced by:
EtwpAllocatePayloadFilterData