恶意软件二进制文件是否可为加壳形式?如何判断加壳状态?
Great question—let’s break this down clearly, since dealing with packed malware samples is a common hurdle in analysis.
First off, yes, many of the unpacked binaries from theZoo are indeed packed. The repository aims to mirror real-world malware threats, and packing is one of the most common anti-analysis techniques threat actors use to hide payloads, evade signature detection, and complicate reverse engineering. You’ll find samples protected with everything from common packers like UPX to more obscure or custom ones.
How to Detect if a Sample is Packed
We can split detection into static (no execution needed) and dynamic (requires sandbox/debugger) methods:
Static Analysis Methods
Inspect File Headers & Sections
For Windows PE files, use tools likepevieworobjdumpto examine section details. Packed samples often show:- Unusual section names (e.g.,
UPX0/UPX1for UPX, or random-looking labels like.garb) - A massive gap between a section’s virtual size and raw size (compressed data expands significantly in memory)
- High entropy in sections (use the
entcommand to calculate—compressed/encrypted data has entropy close to 8.0)
- Unusual section names (e.g.,
Analyze the Import Table
Packed malware typically has a tiny import table, often only importing core functions fromkernel32.dll(likeLoadLibraryAandGetProcAddress). This is because the shellcode dynamically resolves other APIs at runtime instead of listing them upfront.Scan for Packer Signature Strings
Run thestringscommand on the binary to look for known packer identifiers. For example, UPX leaves the string "UPX!" in packed files, while other packers have unique signature strings you can cross-reference with packer databases.Use Packer Detection Tools
Tools like PEiD, Exeinfo PE, or Detect It Easy can quickly scan binaries and flag known packers. These rely on signature databases to match common packing patterns.
Dynamic Analysis Methods
Debugger Tracing
Use a debugger like x64dbg or OllyDbg to step through execution. Packed samples first run an unpacking stub: you’ll see code decrypting/uncompressing the original payload into memory, then jumping to the original entry point (OEP). Watch for memory regions marked as executable and written to—this is a strong unpacking signal.Memory Dump Analysis
After the unpacking routine finishes, dump the decrypted payload from memory (using debugger plugins orprocdump). Analyze this dumped file: it will have a full import table, normal section structure, and recognizable code patterns hidden in the original packed binary.
Bonus Tip
Some samples use multi-layer packing (packed multiple times with different tools). If your initial scan doesn’t find anything, try unpacking once and re-scanning the resulting binary.
内容的提问来源于stack exchange,提问作者Lelouch

