typeconceptconfidencehighcreated2026-07-29updated2026-07-29packerdetectionstatic-analysis

Packer Identification

General techniques for identifying executable packers, crypters, and protectors in static analysis.

Section-Name Heuristics

Pattern Packer / Tool
UPX0, UPX1, UPX2 UPX (standard)
.UPX, UPX! UPX (scrambled names)
NSIS Nullsoft Scriptable Install System
.petite, .PEDATA Petite
.aspack, .adata ASPack
.RLPack RLPack
.MPRESS1, .MPRESS2 MPRESS
. Themida Themida / WinLicense
.vmp0, .vmp1 VMProtect
.text, .data, .rsrc (high entropy .text) Custom / unknown packer

Entropy Analysis

  • Packed sections typically show entropy > 7.5 (close to random).
  • Unpacked code sections show entropy ~5.5–6.5 (x86/x64 instruction streams are compressible).
  • Entropy delta between sections can reveal a small decryptor stub + large encrypted payload.

Entry-Point Inspection

  • The EP should land in a code section (.text, UPX1, etc.).
  • If EP is in a non-standard section (e.g., .data), suspect self-modifying code or packer stub.
  • YARA signatures on first 32–64 bytes of EP can identify known packer stubs.

Import Table

  • Very few imports (only LoadLibraryA, GetProcAddress, VirtualAlloc) suggests packed payload.
  • Forwarded exports or import table with ordinal-only entries may indicate manual loading.

Tools

  • pestudio, Exeinfo PE, DiE (Detect It Easy) — GUI packer detectors
  • rabin2 -I — shows packer name, EP section, and canary/relro/pie flags
  • pefile Python library — programmatic PE parsing
  • ent / entcalc — entropy calculation

Related