UPX Compression
Ultimate Packer for eXecutables — a free, portable executable packer using compression algorithms (NRV, UCL, LZMA, zlib) to reduce binary size. UPX is open-source and widely abused by malware authors as a first-stage packer.
Detection
- Section names
UPX0,UPX1,UPX2(or scrambled variants like.UPX,UPX!). - High entropy in the first section (
UPX0is typically zero-filled,UPX1contains compressed payload). - Entry point in
UPX1(the decompressor stub). - PE characteristics:
IMAGE_FILE_EXECUTABLE_IMAGE+IMAGE_FILE_32BIT_MACHINE. - YARA:
UPXsignature bytes at EP (\x60\xbe...for x86,\x48\x89...for x64).
Decompression
upx -d sample.bin -o sample_unpacked.bin
- UPX restores the original binary perfectly (bit-for-bit identical) unless the binary was modified after packing.
- Corrupted/truncated UPX headers prevent unpacking; manual reconstruction may be needed.
Anti-Analysis Variants
- Scrambled section names: Rename
UPX0/UPX1to.text/.datato evade naive detection. - Modified UPX stub: Custom decompressor code that still uses UPX format but changes entry-point bytes.
- Nested packing: UPX → UPX (double-packed) or UPX → custom crypter.
- Stripped UPX header: Remove
UPX!magic and version info; requires manual LZMA/UCL decompression.
Impact on Analysis
- Strings: Compressed strings are unreadable until unpacked.
- Imports: Original import table is compressed; only UPX stub imports (
LoadLibraryA,GetProcAddress,VirtualAlloc) are visible. - Resources: Original resource directory is compressed.
- Signature: File hash changes after packing; ssdeep/tlsh similarity may still detect packed siblings.
In This Corpus
- /intel/analyses/faa32ac2a1af9c0bdf39a6430313bdc3fe8b5e3e48d2d0a0cdecb96c960548c8.html — UPX 4.2.3 LZMA, standard section names, no anti-UPX tricks. Simply a size reducer for a 7.75 MB Go binary.
Related
- golang-stealer-build-pattern — Go binaries are often UPX-packed to reduce distribution size
- packer-identification — general packer detection techniques