typeconceptconfidencehighcreated2026-07-29updated2026-07-29packercompressionupxobfuscation

UPX Compression

Ultimate Packer for eXecutables — a free, portable executable packer using compression algorithms (NRV, UCL, LZMA, zlib) to reduce binary size. UPX is open-source and widely abused by malware authors as a first-stage packer.

Detection

  • Section names UPX0, UPX1, UPX2 (or scrambled variants like .UPX, UPX!).
  • High entropy in the first section (UPX0 is typically zero-filled, UPX1 contains compressed payload).
  • Entry point in UPX1 (the decompressor stub).
  • PE characteristics: IMAGE_FILE_EXECUTABLE_IMAGE + IMAGE_FILE_32BIT_MACHINE.
  • YARA: UPX signature bytes at EP (\x60\xbe... for x86, \x48\x89... for x64).

Decompression

upx -d sample.bin -o sample_unpacked.bin
  • UPX restores the original binary perfectly (bit-for-bit identical) unless the binary was modified after packing.
  • Corrupted/truncated UPX headers prevent unpacking; manual reconstruction may be needed.

Anti-Analysis Variants

  • Scrambled section names: Rename UPX0/UPX1 to .text/.data to evade naive detection.
  • Modified UPX stub: Custom decompressor code that still uses UPX format but changes entry-point bytes.
  • Nested packing: UPX → UPX (double-packed) or UPX → custom crypter.
  • Stripped UPX header: Remove UPX! magic and version info; requires manual LZMA/UCL decompression.

Impact on Analysis

  • Strings: Compressed strings are unreadable until unpacked.
  • Imports: Original import table is compressed; only UPX stub imports (LoadLibraryA, GetProcAddress, VirtualAlloc) are visible.
  • Resources: Original resource directory is compressed.
  • Signature: File hash changes after packing; ssdeep/tlsh similarity may still detect packed siblings.

In This Corpus

  • /intel/analyses/faa32ac2a1af9c0bdf39a6430313bdc3fe8b5e3e48d2d0a0cdecb96c960548c8.html — UPX 4.2.3 LZMA, standard section names, no anti-UPX tricks. Simply a size reducer for a 7.75 MB Go binary.

Related