Packer Identification
General techniques for identifying executable packers, crypters, and protectors in static analysis.
Section-Name Heuristics
| Pattern | Packer / Tool |
|---|---|
UPX0, UPX1, UPX2 |
UPX (standard) |
.UPX, UPX! |
UPX (scrambled names) |
NSIS |
Nullsoft Scriptable Install System |
.petite, .PEDATA |
Petite |
.aspack, .adata |
ASPack |
.RLPack |
RLPack |
.MPRESS1, .MPRESS2 |
MPRESS |
. Themida |
Themida / WinLicense |
.vmp0, .vmp1 |
VMProtect |
.text, .data, .rsrc (high entropy .text) |
Custom / unknown packer |
Entropy Analysis
- Packed sections typically show entropy > 7.5 (close to random).
- Unpacked code sections show entropy ~5.5–6.5 (x86/x64 instruction streams are compressible).
- Entropy delta between sections can reveal a small decryptor stub + large encrypted payload.
Entry-Point Inspection
- The EP should land in a code section (
.text,UPX1, etc.). - If EP is in a non-standard section (e.g.,
.data), suspect self-modifying code or packer stub. - YARA signatures on first 32–64 bytes of EP can identify known packer stubs.
Import Table
- Very few imports (only
LoadLibraryA,GetProcAddress,VirtualAlloc) suggests packed payload. - Forwarded exports or import table with ordinal-only entries may indicate manual loading.
Tools
pestudio,Exeinfo PE,DiE(Detect It Easy) — GUI packer detectorsrabin2 -I— shows packer name, EP section, and canary/relro/pie flagspefilePython library — programmatic PE parsingent/entcalc— entropy calculation
Related
- upx-compression — specific UPX detection and unpacking
- golang-stealer-build-pattern — Go binaries frequently packed with UPX