{
  "id": 12818,
  "title": "Visualize malware patterns",
  "url": "/competitions/malware-classification/discussion/12818",
  "author_name": "",
  "post_date": "2015-03-15T15:09:05.760Z",
  "votes": 51,
  "comment_count": 30,
  "views": 11390,
  "content": "<p>Hi there, I'd like to share some fun I had mining this data. Believe it or not. Malware has very fine texture patterns or even signature from the authors! Check the attached two figures and tell me it is not intentional? &nbsp;:} You can easily draw them by treating bytes as pixel intensities.&nbsp;</p>\n<p>Please share your thoughts on how to further exploit it. Thank you very much!</p>",
  "messages": [
    {
      "id": "66237",
      "postDate": "03/15/2015 15:09:05",
      "content": "<p>Hi there, I'd like to share some fun I had mining this data. Believe it or not. Malware has very fine texture patterns or even signature from the authors! Check the attached two figures and tell me it is not intentional? &nbsp;:} You can easily draw them by treating bytes as pixel intensities.&nbsp;</p>\n<p>Please share your thoughts on how to further exploit it. Thank you very much!</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "66238",
      "postDate": "03/15/2015 15:19:46",
      "content": "<p>So amazing....</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "66243",
      "postDate": "03/15/2015 16:07:56",
      "content": "<p>The level of mining ability of this one is over the roof!&nbsp;</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "66264",
      "postDate": "03/15/2015 20:08:58",
      "content": "<p>Great insight!&nbsp;</p>\n<p>BTW - it may be an explaination, why bytes count are so strong features!</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "66265",
      "postDate": "03/15/2015 20:09:20",
      "content": "<p>I have to admit that I searched the internet to see if this wasn't some sort of April's fool equivalent hehehe.</p>\n<p>Here's another two examples</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "66285",
      "postDate": "03/15/2015 21:16:54",
      "content": "<p>Very nice!</p>\n<p>This remember to</p>\n<p>http://en.wikipedia.org/wiki/Arecibo_message</p>\n<p>Perhaps this viruses are some kind of alien messages :-)</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "66289",
      "postDate": "03/15/2015 21:45:10",
      "content": "<p>[quote=NxGTR;66265]</p>\n<p>I have to admit that I searched the internet to see if this wasn't some sort of April's fool equivalent hehehe.</p>\n<p>Here's another two examples</p>\n<p>[/quote]</p>\n<p>And another two. seems &quot;Ramnit&quot; has most weird ones :P</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "66290",
      "postDate": "03/15/2015 21:50:12",
      "content": "<p><br>the found symbol in 5764RnJYTirWq1utgdkN picture&nbsp;could be the Huawei Logo&nbsp; http://en.wikipedia.org/wiki/Huawei<br>I do not think that this telecommunication company produces malware.</p>\n<p>in&nbsp; 8ZImDglPqC9RSok2WxQ1&nbsp;&nbsp; (DIB color 32bit per pixel with width 1196)&nbsp; or (1byte per pixel grayscale width 720) <br>you find&nbsp;a famous comapny name&nbsp;which searches here for the malware creators...<br>I do not think that these logos are any hint to the authors of the malware.</p>\n<p>In 8xZW7jgeCML04hIw3tOB (grayacale color and width 300) also a famous company name,</p>\n<p>(as in&nbsp; posted NxrC3kQvsl5AZ4WtowHD example Picture),<br>from whom you also can believe, that they don't produce malware.</p>\n<p><br>The data you detect in the .bytes files is mostly in the .rsrc section, where<br>uncompressed DIB/BMP/ICO pictures can be stored.</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "66292",
      "postDate": "03/15/2015 22:08:45",
      "content": "<p>so that's icon of the malware? :D</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "66294",
      "postDate": "03/15/2015 22:19:14",
      "content": "<p>[quote=rcarson;66292]</p>\n<p>so that's icon of the malware? :D</p>\n<p>[/quote]</p>\n<p>goYPdUatw3BQEl6iCI0D seems to be a logo of a video game. (but this is no hint to the author of the malware)</p>\n<p>(turn the picture around 180 degrees and read from right to left to get text:&nbsp;&nbsp;&nbsp; &quot;left 4 dead&quot;)</p>\n<p>http://de.wikipedia.org/wiki/Left_4_Dead<br>https://www.google.de/?gws_rd=ssl#q=left+4+dead</p>\n<p>so obviously some malware producers use famous names to confuse users.</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "66303",
      "postDate": "03/16/2015 00:06:26",
      "content": "<p>It looks so neat! I am confused how you guys generated these pics. Can anyone be so kind to share some code here?&nbsp;</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "66305",
      "postDate": "03/16/2015 00:25:16",
      "content": "<p>[quote=Little Boat;66303]</p>\n<p>It looks so neat! I am confused how you guys generated these pics. Can anyone be so kind to share some code here?&nbsp;</p>\n<p>[/quote]</p>\n<p>check it out. :D</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "66308",
      "postDate": "03/16/2015 00:41:36",
      "content": "<p>[quote=rcarson;66305]</p>\n<p>[quote=Little Boat;66303]</p>\n<p>It looks so neat! I am confused how you guys generated these pics. Can anyone be so kind to share some code here?&nbsp;</p>\n<p>[/quote]</p>\n<p>check it out. :D</p>\n<p>[/quote]</p>\n<p>awesome!</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "66318",
      "postDate": "03/16/2015 03:14:27",
      "content": "<p>Wow.</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "66319",
      "postDate": "03/16/2015 03:22:51",
      "content": "<p>Cool ! &nbsp;These abilities of the malware authors are amazing... besides code obfuscation, they go to great length towards ego creativity ....</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "68468",
      "postDate": "03/26/2015 20:02:19",
      "content": "<p>[quote=rcarson;66305]</p>\n<p>[quote=Little Boat;66303]</p>\n<p>It looks so neat! I am confused how you guys generated these pics. Can anyone be so kind to share some code here?&nbsp;</p>\n<p>[/quote]</p>\n<p>check it out. :D</p>\n<p>[/quote]</p>\n<p>Can you explain the purpose of these four lines of code:</p>\n<p>b=int((array.shape[0]*16)**(0.5))<br>b=2**(int(log(b)/log(2))+1)<br>a=int(array.shape[0]*16/b)<br>array=array[:a*b/16,:]</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "68475",
      "postDate": "03/26/2015 20:56:12",
      "content": "<p>I'm just trying to reshape the image so that its aspect ratio is close to 1:1</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "68478",
      "postDate": "03/26/2015 21:03:30",
      "content": "<p>I tried your code, but some images have an aspect ratio of 2:1. Is it normal ?</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "68481",
      "postDate": "03/26/2015 21:18:15",
      "content": "<p>Of course normal. To make both width and height integers, my code may truncate the bytes a little bit. &nbsp;Actually there is no abnormal aspect ratio in this case. Anything convenient for visual inspection is Ok.&nbsp;</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "69605",
      "postDate": "04/04/2015 04:53:00",
      "content": "<p>I know I have been quiet for quite some time but this is what my paper uses to classify malware families :)</p>\n<p>Malware Images: Visualization and Automatic Classification</p>\n<p>http://vision.ece.ucsb.edu/~lakshman/nataraj_vizsec_2011_paper.pdf</p>\n<p>We have also built a server named SARVAM for Search And RetrieVAl of Malware where people can upload malware and retrieve the top matches:</p>\n<p>http://sarvam.ece.ucsb.edu</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "69606",
      "postDate": "04/04/2015 04:56:44",
      "content": "<p>[quote=Lakshman Nataraj;69605]</p>\n<p>I know I have been quiet for quite some time but this is what my paper uses to classify malware families :)</p>\n<p>Malware Images: Visualization and Automatic Classification</p>\n<p>http://vision.ece.ucsb.edu/~lakshman/nataraj_vizsec_2011_paper.pdf</p>\n<p>We have also built a server named SARVAM for Search And RetrieVAl of Malware where people can upload malware and retrieve the top matches:</p>\n<p>http://sarvam.ece.ucsb.edu</p>\n<p>[/quote]</p>\n<p>So Lakshman, tell me, if I read your paper, can I get 0.0027 log loss as well? :)</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "69607",
      "postDate": "04/04/2015 05:00:06",
      "content": "<p>[quote=Little Boat;69606]</p>\n<p>So Lakshman, tell me, if I read your paper, can I get 0.0027 log loss as well? :)</p>\n<p>[/quote]</p>\n<p>May be so, may be no but it may be worth the try :)</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "69608",
      "postDate": "04/04/2015 05:31:33",
      "content": "<p>[quote=Lakshman Nataraj;69607]</p>\n<p>[quote=Little Boat;69606]</p>\n<p>So Lakshman, tell me, if I read your paper, can I get 0.0027 log loss as well? :)</p>\n<p>[/quote]</p>\n<p>May be so, may be no but it may be worth the try :)</p>\n<p>[/quote]</p>\n<p>Ok then If you see my team's score jumps, then we are maybe using the paper!</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "69860",
      "postDate": "04/07/2015 06:28:09",
      "content": "<p>@LittleBoat it was the paper, yes?)</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "69887",
      "postDate": "04/07/2015 14:53:51",
      "content": "<p>[quote=Mikhail Trofimov;69860]</p>\n<p>@LittleBoat it was the paper, yes?)</p>\n<p>[/quote]</p>\n<p>Unfortunately, no, it's not the paper. I believe rcarson and xueer tried the ideas but it didn't help, at least not for us.&nbsp;</p>\n<p>And I am also dying to know how it is even possible to get 0.0002 logloss...</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "70010",
      "postDate": "04/08/2015 12:54:41",
      "content": "<p>Novel solution using well funded previous work. &nbsp;kudos!</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "72343",
      "postDate": "04/18/2015 20:24:04",
      "content": "<p>[quote=Xueer Chen]Check the attached two figures and tell me it is not intentional? &nbsp;:}[/quote]</p>\n<p>[quote=Patrick Chan]These abilities of the malware authors are amazing... besides code obfuscation, they go to great length towards ego creativity ....[/quote]</p>\n<p>What you're seeing here looks like images because they <strong>are</strong> images. These (among other stuff that the binary carries along) are stored in the resources section (.rsrc) of a PE file and can be addressed in the code e.g. to drop them to the drive and display them. So it's nothing too fancy; the malware authors just for whatever reasons wanted to bring along image files and that's the simplest way to do it.</p>\n<p>(The trickier part is that the widths of the pictures you produce have to be sufficiently &quot;compatible&quot; with the widths of these embedded images so they're not too distorted and can be recognized by eye.. ;) )</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "73046",
      "postDate": "04/21/2015 23:57:44",
      "content": "<p>[quote=LeoGM;72343]</p>\n<p>[quote=Xueer Chen]Check the attached two figures and tell me it is not intentional? &nbsp;:}[/quote]</p>\n<p>[quote=Patrick Chan]These abilities of the malware authors are amazing... besides code obfuscation, they go to great length towards ego creativity ....[/quote]</p>\n<p>What you're seeing here looks like images because they <strong>are</strong> images. These (among other stuff that the binary carries along) are stored in the resources section (.rsrc) of a PE file and can be addressed in the code e.g. to drop them to the drive and display them. So it's nothing too fancy; the malware authors just for whatever reasons wanted to bring along image files and that's the simplest way to do it.</p>\n<p>(The trickier part is that the widths of the pictures you produce have to be sufficiently &quot;compatible&quot; with the widths of these embedded images so they're not too distorted and can be recognized by eye.. ;) )</p>\n<p>[/quote]</p>\n\n<p>I don't know enough about malware files, or really files in general, to say for sure, but I think this is a good illustration of what you're talking about?&nbsp;My teammate and I managed to find a pretty interesting visual pattern that turned up in something like 90% of the kelihos_ver3's (most commonly at the end) and fit very nicely into a 128x128 image. If you convolve the flattened 1D representation of the figure with the full binaries as a matched filter and&nbsp;wrap&nbsp;the 8192 bytes on either side of the argmax of the convolution into a&nbsp;128x128 image, you get startlingly consistent results. Attached are the top 144 matches from our convolution, but the list continues on in the same way for a while. Interestingly, the same image can be seen in a larger form if the tile is reshaped to have a width of 192&nbsp;</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "522298",
      "postDate": "04/24/2019 07:21:04",
      "content": "<p>the first picture is HUAWEI ?</p>",
      "rawMarkdown": "the first picture is HUAWEI ?",
      "votes": null
    },
    {
      "id": "595269",
      "postDate": "08/09/2019 03:11:58",
      "content": "<p>can you plz share the code</p>",
      "rawMarkdown": "can you plz share the code",
      "votes": null
    },
    {
      "id": "2263034",
      "postDate": "05/17/2023 09:22:20",
      "content": "<p>can you share the binary to image conversion code this is my paper and am not getting how to start.  </p>",
      "rawMarkdown": "can you share the binary to image conversion code this is my paper and am not getting how to start.",
      "votes": null
    }
  ],
  "comments": [
    {
      "id": 66238,
      "author_name": "yejiming",
      "author_url": "",
      "post_date": "03/15/2015 15:19:46",
      "content": "<p>So amazing....</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 66243,
      "author_name": "ggglhf",
      "author_url": "",
      "post_date": "03/15/2015 16:07:56",
      "content": "<p>The level of mining ability of this one is over the roof!&nbsp;</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 66264,
      "author_name": "mikhailtrofimov",
      "author_url": "",
      "post_date": "03/15/2015 20:08:58",
      "content": "<p>Great insight!&nbsp;</p>\n<p>BTW - it may be an explaination, why bytes count are so strong features!</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 66265,
      "author_name": "carloshuertas",
      "author_url": "",
      "post_date": "03/15/2015 20:09:20",
      "content": "<p>I have to admit that I searched the internet to see if this wasn't some sort of April's fool equivalent hehehe.</p>\n<p>Here's another two examples</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 66285,
      "author_name": "blindape",
      "author_url": "",
      "post_date": "03/15/2015 21:16:54",
      "content": "<p>Very nice!</p>\n<p>This remember to</p>\n<p>http://en.wikipedia.org/wiki/Arecibo_message</p>\n<p>Perhaps this viruses are some kind of alien messages :-)</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 66289,
      "author_name": "jiweiliu",
      "author_url": "",
      "post_date": "03/15/2015 21:45:10",
      "content": "<p>[quote=NxGTR;66265]</p>\n<p>I have to admit that I searched the internet to see if this wasn't some sort of April's fool equivalent hehehe.</p>\n<p>Here's another two examples</p>\n<p>[/quote]</p>\n<p>And another two. seems &quot;Ramnit&quot; has most weird ones :P</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 66290,
      "author_name": "",
      "author_url": "",
      "post_date": "03/15/2015 21:50:12",
      "content": "<p><br>the found symbol in 5764RnJYTirWq1utgdkN picture&nbsp;could be the Huawei Logo&nbsp; http://en.wikipedia.org/wiki/Huawei<br>I do not think that this telecommunication company produces malware.</p>\n<p>in&nbsp; 8ZImDglPqC9RSok2WxQ1&nbsp;&nbsp; (DIB color 32bit per pixel with width 1196)&nbsp; or (1byte per pixel grayscale width 720) <br>you find&nbsp;a famous comapny name&nbsp;which searches here for the malware creators...<br>I do not think that these logos are any hint to the authors of the malware.</p>\n<p>In 8xZW7jgeCML04hIw3tOB (grayacale color and width 300) also a famous company name,</p>\n<p>(as in&nbsp; posted NxrC3kQvsl5AZ4WtowHD example Picture),<br>from whom you also can believe, that they don't produce malware.</p>\n<p><br>The data you detect in the .bytes files is mostly in the .rsrc section, where<br>uncompressed DIB/BMP/ICO pictures can be stored.</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 66292,
      "author_name": "jiweiliu",
      "author_url": "",
      "post_date": "03/15/2015 22:08:45",
      "content": "<p>so that's icon of the malware? :D</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 66294,
      "author_name": "",
      "author_url": "",
      "post_date": "03/15/2015 22:19:14",
      "content": "<p>[quote=rcarson;66292]</p>\n<p>so that's icon of the malware? :D</p>\n<p>[/quote]</p>\n<p>goYPdUatw3BQEl6iCI0D seems to be a logo of a video game. (but this is no hint to the author of the malware)</p>\n<p>(turn the picture around 180 degrees and read from right to left to get text:&nbsp;&nbsp;&nbsp; &quot;left 4 dead&quot;)</p>\n<p>http://de.wikipedia.org/wiki/Left_4_Dead<br>https://www.google.de/?gws_rd=ssl#q=left+4+dead</p>\n<p>so obviously some malware producers use famous names to confuse users.</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 66303,
      "author_name": "xiaozhouwang",
      "author_url": "",
      "post_date": "03/16/2015 00:06:26",
      "content": "<p>It looks so neat! I am confused how you guys generated these pics. Can anyone be so kind to share some code here?&nbsp;</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 66305,
      "author_name": "jiweiliu",
      "author_url": "",
      "post_date": "03/16/2015 00:25:16",
      "content": "<p>[quote=Little Boat;66303]</p>\n<p>It looks so neat! I am confused how you guys generated these pics. Can anyone be so kind to share some code here?&nbsp;</p>\n<p>[/quote]</p>\n<p>check it out. :D</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 66308,
      "author_name": "xiaozhouwang",
      "author_url": "",
      "post_date": "03/16/2015 00:41:36",
      "content": "<p>[quote=rcarson;66305]</p>\n<p>[quote=Little Boat;66303]</p>\n<p>It looks so neat! I am confused how you guys generated these pics. Can anyone be so kind to share some code here?&nbsp;</p>\n<p>[/quote]</p>\n<p>check it out. :D</p>\n<p>[/quote]</p>\n<p>awesome!</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 66318,
      "author_name": "triskelion",
      "author_url": "",
      "post_date": "03/16/2015 03:14:27",
      "content": "<p>Wow.</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 66319,
      "author_name": "drpatrickchan",
      "author_url": "",
      "post_date": "03/16/2015 03:22:51",
      "content": "<p>Cool ! &nbsp;These abilities of the malware authors are amazing... besides code obfuscation, they go to great length towards ego creativity ....</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 68468,
      "author_name": "thomasseleck",
      "author_url": "",
      "post_date": "03/26/2015 20:02:19",
      "content": "<p>[quote=rcarson;66305]</p>\n<p>[quote=Little Boat;66303]</p>\n<p>It looks so neat! I am confused how you guys generated these pics. Can anyone be so kind to share some code here?&nbsp;</p>\n<p>[/quote]</p>\n<p>check it out. :D</p>\n<p>[/quote]</p>\n<p>Can you explain the purpose of these four lines of code:</p>\n<p>b=int((array.shape[0]*16)**(0.5))<br>b=2**(int(log(b)/log(2))+1)<br>a=int(array.shape[0]*16/b)<br>array=array[:a*b/16,:]</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 68475,
      "author_name": "jiweiliu",
      "author_url": "",
      "post_date": "03/26/2015 20:56:12",
      "content": "<p>I'm just trying to reshape the image so that its aspect ratio is close to 1:1</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 68478,
      "author_name": "thomasseleck",
      "author_url": "",
      "post_date": "03/26/2015 21:03:30",
      "content": "<p>I tried your code, but some images have an aspect ratio of 2:1. Is it normal ?</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 68481,
      "author_name": "jiweiliu",
      "author_url": "",
      "post_date": "03/26/2015 21:18:15",
      "content": "<p>Of course normal. To make both width and height integers, my code may truncate the bytes a little bit. &nbsp;Actually there is no abnormal aspect ratio in this case. Anything convenient for visual inspection is Ok.&nbsp;</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 69605,
      "author_name": "",
      "author_url": "",
      "post_date": "04/04/2015 04:53:00",
      "content": "<p>I know I have been quiet for quite some time but this is what my paper uses to classify malware families :)</p>\n<p>Malware Images: Visualization and Automatic Classification</p>\n<p>http://vision.ece.ucsb.edu/~lakshman/nataraj_vizsec_2011_paper.pdf</p>\n<p>We have also built a server named SARVAM for Search And RetrieVAl of Malware where people can upload malware and retrieve the top matches:</p>\n<p>http://sarvam.ece.ucsb.edu</p>",
      "votes": null,
      "replies": [
        {
          "id": 2263034,
          "author_name": "ayushkumarmishra24",
          "author_url": "",
          "post_date": "05/17/2023 09:22:20",
          "content": "<p>can you share the binary to image conversion code this is my paper and am not getting how to start.  </p>",
          "votes": null,
          "replies": []
        }
      ]
    },
    {
      "id": 69606,
      "author_name": "xiaozhouwang",
      "author_url": "",
      "post_date": "04/04/2015 04:56:44",
      "content": "<p>[quote=Lakshman Nataraj;69605]</p>\n<p>I know I have been quiet for quite some time but this is what my paper uses to classify malware families :)</p>\n<p>Malware Images: Visualization and Automatic Classification</p>\n<p>http://vision.ece.ucsb.edu/~lakshman/nataraj_vizsec_2011_paper.pdf</p>\n<p>We have also built a server named SARVAM for Search And RetrieVAl of Malware where people can upload malware and retrieve the top matches:</p>\n<p>http://sarvam.ece.ucsb.edu</p>\n<p>[/quote]</p>\n<p>So Lakshman, tell me, if I read your paper, can I get 0.0027 log loss as well? :)</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 69607,
      "author_name": "",
      "author_url": "",
      "post_date": "04/04/2015 05:00:06",
      "content": "<p>[quote=Little Boat;69606]</p>\n<p>So Lakshman, tell me, if I read your paper, can I get 0.0027 log loss as well? :)</p>\n<p>[/quote]</p>\n<p>May be so, may be no but it may be worth the try :)</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 69608,
      "author_name": "xiaozhouwang",
      "author_url": "",
      "post_date": "04/04/2015 05:31:33",
      "content": "<p>[quote=Lakshman Nataraj;69607]</p>\n<p>[quote=Little Boat;69606]</p>\n<p>So Lakshman, tell me, if I read your paper, can I get 0.0027 log loss as well? :)</p>\n<p>[/quote]</p>\n<p>May be so, may be no but it may be worth the try :)</p>\n<p>[/quote]</p>\n<p>Ok then If you see my team's score jumps, then we are maybe using the paper!</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 69860,
      "author_name": "mikhailtrofimov",
      "author_url": "",
      "post_date": "04/07/2015 06:28:09",
      "content": "<p>@LittleBoat it was the paper, yes?)</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 69887,
      "author_name": "xiaozhouwang",
      "author_url": "",
      "post_date": "04/07/2015 14:53:51",
      "content": "<p>[quote=Mikhail Trofimov;69860]</p>\n<p>@LittleBoat it was the paper, yes?)</p>\n<p>[/quote]</p>\n<p>Unfortunately, no, it's not the paper. I believe rcarson and xueer tried the ideas but it didn't help, at least not for us.&nbsp;</p>\n<p>And I am also dying to know how it is even possible to get 0.0002 logloss...</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 70010,
      "author_name": "robertfontaine",
      "author_url": "",
      "post_date": "04/08/2015 12:54:41",
      "content": "<p>Novel solution using well funded previous work. &nbsp;kudos!</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 72343,
      "author_name": "lgmaag",
      "author_url": "",
      "post_date": "04/18/2015 20:24:04",
      "content": "<p>[quote=Xueer Chen]Check the attached two figures and tell me it is not intentional? &nbsp;:}[/quote]</p>\n<p>[quote=Patrick Chan]These abilities of the malware authors are amazing... besides code obfuscation, they go to great length towards ego creativity ....[/quote]</p>\n<p>What you're seeing here looks like images because they <strong>are</strong> images. These (among other stuff that the binary carries along) are stored in the resources section (.rsrc) of a PE file and can be addressed in the code e.g. to drop them to the drive and display them. So it's nothing too fancy; the malware authors just for whatever reasons wanted to bring along image files and that's the simplest way to do it.</p>\n<p>(The trickier part is that the widths of the pictures you produce have to be sufficiently &quot;compatible&quot; with the widths of these embedded images so they're not too distorted and can be recognized by eye.. ;) )</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 73046,
      "author_name": "alecgunny",
      "author_url": "",
      "post_date": "04/21/2015 23:57:44",
      "content": "<p>[quote=LeoGM;72343]</p>\n<p>[quote=Xueer Chen]Check the attached two figures and tell me it is not intentional? &nbsp;:}[/quote]</p>\n<p>[quote=Patrick Chan]These abilities of the malware authors are amazing... besides code obfuscation, they go to great length towards ego creativity ....[/quote]</p>\n<p>What you're seeing here looks like images because they <strong>are</strong> images. These (among other stuff that the binary carries along) are stored in the resources section (.rsrc) of a PE file and can be addressed in the code e.g. to drop them to the drive and display them. So it's nothing too fancy; the malware authors just for whatever reasons wanted to bring along image files and that's the simplest way to do it.</p>\n<p>(The trickier part is that the widths of the pictures you produce have to be sufficiently &quot;compatible&quot; with the widths of these embedded images so they're not too distorted and can be recognized by eye.. ;) )</p>\n<p>[/quote]</p>\n\n<p>I don't know enough about malware files, or really files in general, to say for sure, but I think this is a good illustration of what you're talking about?&nbsp;My teammate and I managed to find a pretty interesting visual pattern that turned up in something like 90% of the kelihos_ver3's (most commonly at the end) and fit very nicely into a 128x128 image. If you convolve the flattened 1D representation of the figure with the full binaries as a matched filter and&nbsp;wrap&nbsp;the 8192 bytes on either side of the argmax of the convolution into a&nbsp;128x128 image, you get startlingly consistent results. Attached are the top 144 matches from our convolution, but the list continues on in the same way for a while. Interestingly, the same image can be seen in a larger form if the tile is reshaped to have a width of 192&nbsp;</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 522298,
      "author_name": "freejourney",
      "author_url": "",
      "post_date": "04/24/2019 07:21:04",
      "content": "<p>the first picture is HUAWEI ?</p>",
      "votes": null,
      "replies": []
    },
    {
      "id": 595269,
      "author_name": "shansaa",
      "author_url": "",
      "post_date": "08/09/2019 03:11:58",
      "content": "<p>can you plz share the code</p>",
      "votes": null,
      "replies": []
    }
  ],
  "raw_markdown_by_id": {
    "66237": "",
    "66238": "",
    "66243": "",
    "66264": "",
    "66265": "",
    "66285": "",
    "66289": "",
    "66290": "",
    "66292": "",
    "66294": "",
    "66303": "",
    "66305": "",
    "66308": "",
    "66318": "",
    "66319": "",
    "68468": "",
    "68475": "",
    "68478": "",
    "68481": "",
    "69605": "",
    "69606": "",
    "69607": "",
    "69608": "",
    "69860": "",
    "69887": "",
    "70010": "",
    "72343": "",
    "73046": "",
    "522298": "the first picture is HUAWEI ?",
    "595269": "can you plz share the code",
    "2263034": "can you share the binary to image conversion code this is my paper and am not getting how to start."
  },
  "source": "meta"
}