{
  "id": 12732,
  "title": "What are meanings of the sections of given bytes and asm files?",
  "url": "/competitions/malware-classification/discussion/12732",
  "author_name": "",
  "post_date": "2015-03-08T21:58:03.627Z",
  "votes": 1,
  "comment_count": 5,
  "views": 3037,
  "content": "<p>I am not very familiar to bytes and asm file representations. As I understand, asm file includes the&nbsp;disassembler output given the bytes representation of the particular file.</p>\n<p>Beside this what are the meanings of the particular sections of these files?</p>\n<p>My understanding is;</p>\n<p>for bytes files left most column is like line counter (maybe the memory location of that segment) and the remaining columns are the hexadecimal representation of the binary content of that file.</p>\n<p>in asm files there are assembly codes of the binary files but also we have lots of repetitions of such rows</p>\n<p>.data:0063800D D7 db 0D7h ; &#215;</p>\n<p>what is the meaning of such rows and how the asm files are structured in particular?</p>",
  "messages": [
    {
      "id": "65730",
      "postDate": "03/08/2015 21:58:03",
      "content": "<p>I am not very familiar to bytes and asm file representations. As I understand, asm file includes the&nbsp;disassembler output given the bytes representation of the particular file.</p>\n<p>Beside this what are the meanings of the particular sections of these files?</p>\n<p>My understanding is;</p>\n<p>for bytes files left most column is like line counter (maybe the memory location of that segment) and the remaining columns are the hexadecimal representation of the binary content of that file.</p>\n<p>in asm files there are assembly codes of the binary files but also we have lots of repetitions of such rows</p>\n<p>.data:0063800D D7 db 0D7h ; &#215;</p>\n<p>what is the meaning of such rows and how the asm files are structured in particular?</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "65749",
      "postDate": "03/09/2015 04:30:30",
      "content": "<p>.text: Code <br>.data: Initialized data<br>.bss: Uninitialized data<br>.rdata: Const/read-only (and initialized) data<br>.edata: Export descriptors<br>.idata: Import descriptors</p>\n<p>from&nbsp;<a href=\"http://stackoverflow.com/questions/19012300/whats-the-difference-between-rdata-and-idata-segments\">here</a>&nbsp;: )</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "69258",
      "postDate": "04/01/2015 03:54:34",
      "content": "<p>In the same context, Could some one explain what do the Hexa code representation in the .bytes files mean?</p>\n<p>For example how should I interpret the line below?</p>\n<p>00401000 56 8D 44 24 08 50 8B F1 E8 1C 1B 00 00 C7 06 08</p>\n\n<p>Thanks</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "69294",
      "postDate": "04/01/2015 10:12:28",
      "content": "<p>[quote=MalNuggets;69258]</p>\n<p>For example how should I interpret the line below?</p>\n<p>00401000 56 8D 44 24 08 50 8B F1 E8 1C 1B 00 00 C7 06 08</p>\n<p>[/quote]</p>\n<p>I was taught by an alien tribe to read this and it means:</p>\n<p>&quot; There are 99 little bugs in my code, take one down, patch it around,</p>\n<p>&nbsp; &nbsp;Now There are &nbsp;1,124,002,124 little bugs in my code, take one down, patch it around!</p>\n<p>... Now There are 189,114,022,934... &quot;</p>\n<p>Kidding aside, I do not think you need to interpret this as something that has &quot;meaning&quot;, but as a bag of words or something. For example, does &quot;F1&quot; or &quot;8B&quot; appears in all Classes&nbsp;or mostly&nbsp;in class_1 virus?</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "69325",
      "postDate": "04/01/2015 15:36:56",
      "content": "<p>@MalNuggets&nbsp;:</p>\n<p>00401000h is often the code section base of&nbsp;the PE EXE (32bit) module.</p>\n<p>you need the main entry point to get the instructions.</p>\n<p>for that you have the .asm files.</p>\n<p>So look at 00401000h in the corresponding .asm file,</p>\n<p>there you find the instructions.</p>\n<p>if 00401000h is a code label address, then these bytes</p>\n<p>00401000 56 8D 44 24 08 50 8B F1 E8 1C 1B 00 00 C7 06 08</p>\n<p>00401010 00 00</p>\n<p>would be in x86 (32bit) instructions:</p>\n<p>56&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;push esi&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;; push ESI register onto stack</p>\n<p>8D442408 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;lea eax,[esp+8]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;; assign EAX register with ESP register + 8</p>\n<p>50&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;push eax&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp; &nbsp;; push EAX register onto stack</p>\n<p>8BF1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp; mov esi,ecx&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;;&nbsp;assign ESI register with ECX register</p>\n<p>E81C1B0000&nbsp;&nbsp; call function@00411139h&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ; call sub function</p>\n<p>C70608000000&nbsp; mov DWORD PTR [esi],00000008h ; assign memory @ address mode [esi] with 8</p>\n<p>...</p>\n<p>if 00401000h is not a code label address, IDA may have recognized them as data:</p>\n<p>56 db 56h</p>\n<p>8D db 8Dh</p>\n<p>44 db 44h</p>\n<p>...</p>\n<p>then the bytes can mean anything, so for example it can be any datatype of any size</p>\n<p>you can imagine (int, float, double,&nbsp;textstrings, ...), so for example bytes, words, dwords</p>\n<p>if such bytes are referenced, as for example as 00411139h in case above, that</p>\n<p>is another code label.</p>\n<p>it also could be a jumptable, then each dword of them contains another virtual address</p>\n<p>of a code Label.</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "69674",
      "postDate": "04/04/2015 22:08:31",
      "content": "<p>Thank you @m and @&#924;&#945;&#961;&#953;&#959;&#962; &#924;&#953;&#967;&#945;&#951;&#955;&#953;&#948;&#951;&#962; KazAnova for the information.</p>",
      "rawMarkdown": "",
      "votes": null
    }
  ],
  "comments": [
    {
      "id": 65749,
      "author_name": "jiweiliu",
      "author_url": "",
      "post_date": "03/09/2015 04:30:30",
      "content": "<p>.text: Code <br>.data: Initialized data<br>.bss: Uninitialized data<br>.rdata: Const/read-only (and initialized) data<br>.edata: Export descriptors<br>.idata: Import descriptors</p>\n<p>from&nbsp;<a href=\"http://stackoverflow.com/questions/19012300/whats-the-difference-between-rdata-and-idata-segments\">here</a>&nbsp;: )</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 69258,
      "author_name": "malnuggets",
      "author_url": "",
      "post_date": "04/01/2015 03:54:34",
      "content": "<p>In the same context, Could some one explain what do the Hexa code representation in the .bytes files mean?</p>\n<p>For example how should I interpret the line below?</p>\n<p>00401000 56 8D 44 24 08 50 8B F1 E8 1C 1B 00 00 C7 06 08</p>\n\n<p>Thanks</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 69294,
      "author_name": "kazanova",
      "author_url": "",
      "post_date": "04/01/2015 10:12:28",
      "content": "<p>[quote=MalNuggets;69258]</p>\n<p>For example how should I interpret the line below?</p>\n<p>00401000 56 8D 44 24 08 50 8B F1 E8 1C 1B 00 00 C7 06 08</p>\n<p>[/quote]</p>\n<p>I was taught by an alien tribe to read this and it means:</p>\n<p>&quot; There are 99 little bugs in my code, take one down, patch it around,</p>\n<p>&nbsp; &nbsp;Now There are &nbsp;1,124,002,124 little bugs in my code, take one down, patch it around!</p>\n<p>... Now There are 189,114,022,934... &quot;</p>\n<p>Kidding aside, I do not think you need to interpret this as something that has &quot;meaning&quot;, but as a bag of words or something. For example, does &quot;F1&quot; or &quot;8B&quot; appears in all Classes&nbsp;or mostly&nbsp;in class_1 virus?</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 69325,
      "author_name": "",
      "author_url": "",
      "post_date": "04/01/2015 15:36:56",
      "content": "<p>@MalNuggets&nbsp;:</p>\n<p>00401000h is often the code section base of&nbsp;the PE EXE (32bit) module.</p>\n<p>you need the main entry point to get the instructions.</p>\n<p>for that you have the .asm files.</p>\n<p>So look at 00401000h in the corresponding .asm file,</p>\n<p>there you find the instructions.</p>\n<p>if 00401000h is a code label address, then these bytes</p>\n<p>00401000 56 8D 44 24 08 50 8B F1 E8 1C 1B 00 00 C7 06 08</p>\n<p>00401010 00 00</p>\n<p>would be in x86 (32bit) instructions:</p>\n<p>56&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;push esi&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;; push ESI register onto stack</p>\n<p>8D442408 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;lea eax,[esp+8]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;; assign EAX register with ESP register + 8</p>\n<p>50&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;push eax&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp; &nbsp;; push EAX register onto stack</p>\n<p>8BF1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp; mov esi,ecx&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;;&nbsp;assign ESI register with ECX register</p>\n<p>E81C1B0000&nbsp;&nbsp; call function@00411139h&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ; call sub function</p>\n<p>C70608000000&nbsp; mov DWORD PTR [esi],00000008h ; assign memory @ address mode [esi] with 8</p>\n<p>...</p>\n<p>if 00401000h is not a code label address, IDA may have recognized them as data:</p>\n<p>56 db 56h</p>\n<p>8D db 8Dh</p>\n<p>44 db 44h</p>\n<p>...</p>\n<p>then the bytes can mean anything, so for example it can be any datatype of any size</p>\n<p>you can imagine (int, float, double,&nbsp;textstrings, ...), so for example bytes, words, dwords</p>\n<p>if such bytes are referenced, as for example as 00411139h in case above, that</p>\n<p>is another code label.</p>\n<p>it also could be a jumptable, then each dword of them contains another virtual address</p>\n<p>of a code Label.</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 69674,
      "author_name": "malnuggets",
      "author_url": "",
      "post_date": "04/04/2015 22:08:31",
      "content": "<p>Thank you @m and @&#924;&#945;&#961;&#953;&#959;&#962; &#924;&#953;&#967;&#945;&#951;&#955;&#953;&#948;&#951;&#962; KazAnova for the information.</p>",
      "votes": null,
      "replies": []
    }
  ],
  "raw_markdown_by_id": {
    "65730": "",
    "65749": "",
    "69258": "",
    "69294": "",
    "69325": "",
    "69674": ""
  },
  "source": "meta"
}