Themida Packed Boot LZ77 Decompressor
A specific Themida/WinLicense packing pattern observed in x64 PE32+ malware: the entry point is relocated to a .boot section containing a compact LZ77 bit-stream decompressor that unpacks an encrypted payload in-memory. The .themida section is a zero-length placeholder reserving virtual address space, and the first five PE section names are blanked (eight spaces) to defeat section-based clustering.
What the Technique Does
Themida wraps the original payload in a multi-stage loader. At rest, the payload is compressed with an LZ77 variant (bit-stream encoded, not byte-aligned) and optionally encrypted. The .boot stub reads bits from a compressed input stream, reconstructs the original bytes, and maps the decrypted PE into memory without writing to disk. Import tables are fully eliminated from the outer binary; the stub resolves APIs manually after decompression.
Detection / Fingerprint
| Indicator | Value |
|---|---|
| Section names | .themida, .boot present; first 1–5 sections often blank (8 spaces) |
| Entry point | Inside .boot (virtual address aligned to section start + small offset) |
| Imports | 1–3 imports only (typically GetModuleHandleA, TranslateMessage, or similar) |
.themida raw size |
Often 0 bytes (virtual-only placeholder) |
.boot entropy |
7.9+ (encrypted/compressed) |
| IAT | Stripped or minimal; no meaningful API surface visible statically |
| Capa | Hits packed file limitation warning; behavioral rules abort |
Implementation Patterns Observed
In sample 616740a4, the entry point at 0x140430058 implements a bit-reader with the following loop:
- Initialize a control byte
bVar7 = 0x80. - For each output byte, shift-left the control byte. If carry-out is set, the next bit(s) encode a back-reference; otherwise emit a literal.
- When the control byte reaches zero, fetch a new control byte from the input stream and continue.
- Back-references encode length (2–4 bytes typical) and distance via variable-length bit fields.
- The decompressor writes to a stack-resident destination buffer; no Windows API calls occur during the loop.
This matches the classic Themida "SecureEngine" decompressor template^[ghidra:entry].
Reproduce on Your Own VMs
Prerequisites: Windows VM with Themida/WinLicense trial or a packed benign sample for reference.
- Build a trivial x64 PE in Visual Studio (e.g., a console app that prints "hello").
- Pack it with Themida, selecting:
- Advanced Features → Encrypt 64-bit files
- Protection Options → Encrypt with SecureEngine
- File Options → Eliminate imports (reduce to 1–2 APIs)
- Inspect the output with
pefile/rabin2 -I:- Should see
.themidaand.bootsections - Entry point should be in
.boot - Import count should be ≤3
- Should see
- Open in Ghidra / IDA. The entry function will be a compact loop with bit-shifting, carry checks, and back-reference copying — no recognizable API calls.
- Compare section entropies:
.bootshould be near 8.0,.rsrcmay contain generic icons.
Verification: Run capa on the packed output — it should emit the packed-file limitation warning.
Defensive Countermeasures
- Entropy + import-count heuristics: Flag PEs with section entropy >7.9 and ≤3 imports for manual review.
- Section-name clustering: Blank section names (8 spaces) are a high-signal Themida fingerprint.
- Capa dynamic mode: For packed samples, detonate in CAPE and run capa against the behavioral report rather than the static file.
- Memory hunting: EDR can detect the
.boot→ RWX allocation transition if the decompressor usesVirtualAlloc/NtAllocateVirtualMemorybefore writing decrypted code.
Pages Where Observed
- /intel/analyses/616740a4ece7a72d3dad48c314db9e1f5b2f1cf2916c3de2eb27a707e1cbdccd.html — Proton Drive masquerade, self-signed Equalizer APO cert
- /intel/analyses/013723553a157de6a46952a5e06cbbb7efa2de04e5292a2066cd95e226192ca7.html — TreeSize masquerade, self-signed Logitech cert,
dropped-by-gcleaner/mix8.filedistribution - Additional Themida samples in corpus:
39f38ae2,426fdcf5,5b38cd1e,200d9984(raw analyses exist; no deep reports written)
Related
- packer-identification — general packer fingerprinting heuristics
- upx-compression — open-source alternative with different section patterns
- protector-lab-overlay — another commercial packer using AES-GCM encrypted overlay