typetechniqueconfidencehighcreated2026-08-01updated2026-08-24packerobfuscationevasionanti-vmcompilerpe

Themida Packed Boot LZ77 Decompressor

A specific Themida/WinLicense packing pattern observed in x64 PE32+ malware: the entry point is relocated to a .boot section containing a compact LZ77 bit-stream decompressor that unpacks an encrypted payload in-memory. The .themida section is a zero-length placeholder reserving virtual address space, and the first five PE section names are blanked (eight spaces) to defeat section-based clustering.

What the Technique Does

Themida wraps the original payload in a multi-stage loader. At rest, the payload is compressed with an LZ77 variant (bit-stream encoded, not byte-aligned) and optionally encrypted. The .boot stub reads bits from a compressed input stream, reconstructs the original bytes, and maps the decrypted PE into memory without writing to disk. Import tables are fully eliminated from the outer binary; the stub resolves APIs manually after decompression.

Detection / Fingerprint

Indicator Value
Section names .themida, .boot present; first 1–5 sections often blank (8 spaces)
Entry point Inside .boot (virtual address aligned to section start + small offset)
Imports 1–3 imports only (typically GetModuleHandleA, TranslateMessage, or similar)
.themida raw size Often 0 bytes (virtual-only placeholder)
.boot entropy 7.9+ (encrypted/compressed)
IAT Stripped or minimal; no meaningful API surface visible statically
Capa Hits packed file limitation warning; behavioral rules abort

Implementation Patterns Observed

In sample 616740a4, the entry point at 0x140430058 implements a bit-reader with the following loop:

  1. Initialize a control byte bVar7 = 0x80.
  2. For each output byte, shift-left the control byte. If carry-out is set, the next bit(s) encode a back-reference; otherwise emit a literal.
  3. When the control byte reaches zero, fetch a new control byte from the input stream and continue.
  4. Back-references encode length (2–4 bytes typical) and distance via variable-length bit fields.
  5. The decompressor writes to a stack-resident destination buffer; no Windows API calls occur during the loop.

This matches the classic Themida "SecureEngine" decompressor template^[ghidra:entry].

Reproduce on Your Own VMs

Prerequisites: Windows VM with Themida/WinLicense trial or a packed benign sample for reference.

  1. Build a trivial x64 PE in Visual Studio (e.g., a console app that prints "hello").
  2. Pack it with Themida, selecting:
    • Advanced Features → Encrypt 64-bit files
    • Protection Options → Encrypt with SecureEngine
    • File Options → Eliminate imports (reduce to 1–2 APIs)
  3. Inspect the output with pefile / rabin2 -I:
    • Should see .themida and .boot sections
    • Entry point should be in .boot
    • Import count should be ≤3
  4. Open in Ghidra / IDA. The entry function will be a compact loop with bit-shifting, carry checks, and back-reference copying — no recognizable API calls.
  5. Compare section entropies: .boot should be near 8.0, .rsrc may contain generic icons.

Verification: Run capa on the packed output — it should emit the packed-file limitation warning.

Defensive Countermeasures

  • Entropy + import-count heuristics: Flag PEs with section entropy >7.9 and ≤3 imports for manual review.
  • Section-name clustering: Blank section names (8 spaces) are a high-signal Themida fingerprint.
  • Capa dynamic mode: For packed samples, detonate in CAPE and run capa against the behavioral report rather than the static file.
  • Memory hunting: EDR can detect the .boot → RWX allocation transition if the decompressor uses VirtualAlloc/NtAllocateVirtualMemory before writing decrypted code.

Pages Where Observed

  • /intel/analyses/616740a4ece7a72d3dad48c314db9e1f5b2f1cf2916c3de2eb27a707e1cbdccd.html — Proton Drive masquerade, self-signed Equalizer APO cert
  • /intel/analyses/013723553a157de6a46952a5e06cbbb7efa2de04e5292a2066cd95e226192ca7.html — TreeSize masquerade, self-signed Logitech cert, dropped-by-gcleaner / mix8.file distribution
  • Additional Themida samples in corpus: 39f38ae2, 426fdcf5, 5b38cd1e, 200d9984 (raw analyses exist; no deep reports written)

Related