{
  "id": 12443,
  "title": "Getting the binary file from the hex dump",
  "url": "/competitions/malware-classification/discussion/12443",
  "author_name": "",
  "post_date": "2015-02-08T09:53:31.747Z",
  "votes": 1,
  "comment_count": 5,
  "views": 3184,
  "content": "<p>Have anyone tried getting the binary from the hex dump?</p>",
  "messages": [
    {
      "id": "63773",
      "postDate": "02/08/2015 09:53:31",
      "content": "<p>Have anyone tried getting the binary from the hex dump?</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "63782",
      "postDate": "02/08/2015 20:30:38",
      "content": "<p>I'm not much of an expert myself, but from what an actual one told me, this is not possible without header files (which are not provided here).</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "64384",
      "postDate": "02/17/2015 06:15:28",
      "content": "<p>Here.</p>\n<p><code>cat 0A32eTdBKayjCWhZqDOQ.bytes | sed 's/^\\([0-9]*\\) //' &gt; new.bytes<br>eric@glamdring:~/workspace/microsoft-malware-kaggle/sampleData$ head new.bytes <br>56 8D 44 24 08 50 8B F1 E8 1C 1B 00 00 C7 06 08<br>BB 42 00 8B C6 5E C2 04 00 CC CC CC CC CC CC CC</code></p>\n<p><code>eric@glamdring:~/workspace/microsoft-malware-kaggle/sampleData$ cat new.bytes | xxd -r -p &gt; test.bin</code></p>\n<p><code><br>eric@glamdring:~/workspace/microsoft-malware-kaggle/sampleData$ cat test.bin | xxd | head<br>0000000: 568d 4424 0850 8bf1 e81c 1b00 00c7 0608 V.D$.P..........<br>0000010: bb42 008b c65e c204 00cc cccc cccc cccc .B...^..........<br></code></p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "64409",
      "postDate": "02/17/2015 17:56:06",
      "content": "<p>That's definitely going into my snippets collection. &nbsp;hex2bin with sed :)</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "64425",
      "postDate": "02/17/2015 20:59:22",
      "content": "<p>This will convert the bytes to binary</p>\n<p>eric@glamdring$ ls *.bytes | sed 's/\\.bytes//' | awk '{print &quot;cat &quot;$1&quot;.bytes | sed '&quot;'&quot;'s/^\\([0-9]*\\) //'&quot;'&quot;' | xxd -r -p &gt; &quot;$1&quot;.naive.bin&quot;}' &gt; naivebin.jobs</p>\n<p>eric@glamdring$ parallel -P 5 ::: &lt; naivebin.jobs</p>\n<p>PE headers are still missing, so I don't think much can be done with them in this form. Being able to actually execute the malware would have opened up some interesting options. If anybody cracks that problem it would be cool.</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "67363",
      "postDate": "03/20/2015 04:38:48",
      "content": "<p>$&nbsp; xxd -r 0A32eTdBKayjCWhZqDOQ.bytes &gt; test.bin</p>",
      "rawMarkdown": "",
      "votes": null
    }
  ],
  "comments": [
    {
      "id": 63782,
      "author_name": "konradb",
      "author_url": "",
      "post_date": "02/08/2015 20:30:38",
      "content": "<p>I'm not much of an expert myself, but from what an actual one told me, this is not possible without header files (which are not provided here).</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 64384,
      "author_name": "ericwhyne",
      "author_url": "",
      "post_date": "02/17/2015 06:15:28",
      "content": "<p>Here.</p>\n<p><code>cat 0A32eTdBKayjCWhZqDOQ.bytes | sed 's/^\\([0-9]*\\) //' &gt; new.bytes<br>eric@glamdring:~/workspace/microsoft-malware-kaggle/sampleData$ head new.bytes <br>56 8D 44 24 08 50 8B F1 E8 1C 1B 00 00 C7 06 08<br>BB 42 00 8B C6 5E C2 04 00 CC CC CC CC CC CC CC</code></p>\n<p><code>eric@glamdring:~/workspace/microsoft-malware-kaggle/sampleData$ cat new.bytes | xxd -r -p &gt; test.bin</code></p>\n<p><code><br>eric@glamdring:~/workspace/microsoft-malware-kaggle/sampleData$ cat test.bin | xxd | head<br>0000000: 568d 4424 0850 8bf1 e81c 1b00 00c7 0608 V.D$.P..........<br>0000010: bb42 008b c65e c204 00cc cccc cccc cccc .B...^..........<br></code></p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 64409,
      "author_name": "robertfontaine1",
      "author_url": "",
      "post_date": "02/17/2015 17:56:06",
      "content": "<p>That's definitely going into my snippets collection. &nbsp;hex2bin with sed :)</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 64425,
      "author_name": "ericwhyne",
      "author_url": "",
      "post_date": "02/17/2015 20:59:22",
      "content": "<p>This will convert the bytes to binary</p>\n<p>eric@glamdring$ ls *.bytes | sed 's/\\.bytes//' | awk '{print &quot;cat &quot;$1&quot;.bytes | sed '&quot;'&quot;'s/^\\([0-9]*\\) //'&quot;'&quot;' | xxd -r -p &gt; &quot;$1&quot;.naive.bin&quot;}' &gt; naivebin.jobs</p>\n<p>eric@glamdring$ parallel -P 5 ::: &lt; naivebin.jobs</p>\n<p>PE headers are still missing, so I don't think much can be done with them in this form. Being able to actually execute the malware would have opened up some interesting options. If anybody cracks that problem it would be cool.</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 67363,
      "author_name": "nizhiqiang",
      "author_url": "",
      "post_date": "03/20/2015 04:38:48",
      "content": "<p>$&nbsp; xxd -r 0A32eTdBKayjCWhZqDOQ.bytes &gt; test.bin</p>",
      "votes": null,
      "replies": []
    }
  ],
  "raw_markdown_by_id": {
    "63773": "",
    "63782": "",
    "64384": "",
    "64409": "",
    "64425": "",
    "67363": ""
  },
  "source": "meta"
}