awesome-executable-packing

Executable packing resources

A curated list of resources and tools related to executable packing and analysis

A curated list of awesome resources related to executable packing

GitHub

1k stars
45 watching
107 forks
last commit: almost 2 years ago
Linked from 4 awesome lists

awesomeawesome-listawesome-listsbinary-analysiscybersecurityexecutable-packinglistmalwaremalware-analysismalware-packersmalware-researchpackerspacking-detectionsecurity

Awesome Executable Packing / Literature / Documentation

a.out (FreeBSD manual pages)
A.out binary format
About anti-debug tricks
Android packers: Separating from the pack
Anti debugging protection techniques with examples
Anti-unpacker tricks
Anti-unpacker tricks - Part 14 (and previous parts)
API deobfuscator: Resolving obfuscated API functions in modern packers
The art of memory forensics: Detecting malware and threats in Windows, Linux, and mac memory
The art of unpacking
Awesome executable packing1,228almost 2 years ago
Cloak and dagger: Unpacking hidden malware attacks
Cluster analysis
Clustering algorithms
COM binary format
Common object file format (COFF)
Comparison of executable file formats
A complexity measure
Cyclomatic complexity density and software maintenance productivity
Defacto2
Do we need hundreds of classifiers to solve real world classification problems?
Dynamic binary analysis and obfuscated codes
elf (FreeBSD manual pages)
Entropy and the distinctive signs of packer PE files
Executable and linkable format (ELF)
Executable and linking format (ELF) specification
Executable file formats
FatELF: Universal binaries for Linux (HALTED)
Feature selection: A data perspective
How to use t-SNE effectively
Hyperion: Implementation of a PE-Crypter
Implementing your own generic unpacker
Mach-O - A look at apple executable files
Mach-O file format reference802almost 2 years ago
Mach-O internals
Machine learning
Making our own executable packer
The matthews correlation coefficient (MCC) should replace the ROC AUC as the standard metric for assessing binary classification
Microsoft portable executable and common object file format specification
MITRE ATT&CK | T1027.002 | obfuscated files or information: Software packing
MZ disk operating system (DOS)
NotPacked++: Evading static packing detection
On the worst-case complexity of timsort
One packer to rule them all: Empirical identification, comparison and circumvention of current antivirus detection techniques
One packer to rule them all: Empirical identification, comparison and circumvention of current antivirus detection techniques
Packer detection tool evaluation11over 5 years ago
Packers
Packing-box: Breaking detectors & visualizing packing
Packing-box: Improving detection of executable packing
Packing-box: Playing with executable packing
Parsing mach-O files
Pattern recognition and machine learning (Information science and statistics)
PE format - Win32 apps
PinDemonium: A DBI-based generic unpacker for Windows executables
Portable executable (PE)
Practical malware analysis: The hands-on guide to dissecting malicious software
ProtectMyTooling - Don't detect tools, detect techniques
Reverse engineering malware: Binary obfuscation and protection
Runtime packers: The hidden problem?
A survey of dimensionality reduction techniques
TitanMist: Your first step to reversing nirvana
Tuts 4 you - UnPackMe (.NET)
Tuts 4 you | unpackme
The "Ultimate" anti-debugging reference
Unpacking, reversing, patching
Virtual machine obfuscation
We can still crack you! General unpacking method for Android Packer (NO ROOT)
When malware is packing heat
Win32 portable executable packing uncovered
Writing a packer
Writing a simple PE packer in detail15over 7 years ago
x86 disassembly/Windows executable files

Awesome Executable Packing / Literature / Scientific Research

2-SPIFF: A 2-stage packer identification method based on function call graph and file attributes(December 2021)
Absent extreme learning machine algorithm with application to packed executable identification(January 2016)
An accurate packer identification method using support vector machine(January 2014)
Adaptive unpacking of Android Apps(May 2017)
Advanced feature engineering for static detection of executable packing(June 2024)
Advanced preprocessing of binary executable files and its usage in retargetable decompilation(December 2014)
Adversarial attacks against windows PE malware detection: A survey of the state-of-the-art(December 2021)
Adversarial EXEmples: A survey and experimental evaluation of practical attacks on machine learning for windows malware detection(September 2021)
Adversarial learning on static detection techniques for executable packing(June 2023)
Adversarial malware binaries: Evading deep learning for malware detection in executables(September 2018)
Adversarial tool for breaking static detection of executable packing(August 2024)
All-in-one framework for detection, unpacking, and verification for malware analysis(January 2019)
Analysis of machine learning approaches to packing detection(October 2023)
Anti-emulation trends in modern packers: A survey on the evolution of anti-emulation techniques in UPA packers(May 2018)
Anti-unpacker tricks(May 2008)
An application of machine learning to analysis of packed mac malware(May 2022)
Application of string kernel based support vector machine for malware packer identification(August 2013)
The application research of virtual machine in packers(August 2011)
AppSpear: Bytecode decrypting and DEX reassembling for packed Android malware(November 2015)
The arms race: Adversarial search defeats entropy used to detect malware(October 2018)
Assessing static and dynamic features for packing detection(October 2024)
Assessing the impact of packing on machine learning-based malware detection and classification systems(October 2024)
Automated static analysis of virtual-machine packers(August 2013)
Automatic analysis of malware behavior using machine learning(December 2011)
Automatic generation of adversarial examples for interpreting malware classifiers(March 2020)
Automatic static unpacking of malware binaries(October 2009)
BareUnpack: Generic unpacking on the bare-metal operating system(December 2018)
Binary-code obfuscations in prevalent packer tools(October 2013)
BinStat tool for recognition of packed executables(September 2010)
Birds of a feature: Intrafamily clustering for version identification of packed malware(September 2020)
BitBlaze: A new approach to computer security via binary analysis(December 2008)
Boosting scalability in anomaly-based packed executable filtering(November 2011)
Building a smart and automated tool for packed malware detections using machine learning(June 2020)
Bypassing anti-analysis of commercial protector methods using DBI tools(January 2021)
ByteWise: A case study in neural network obfuscation identification(January 2018)
Certified robustness of static deep learning-based malware detectors against patch and append attacks(November 2023)
Challenging anti-virus through evolutionary malware obfuscation(April 2016)
Chosen-instruction attack against commercial code virtualization obfuscators(April 2022)
Classification of packed executables for accurate computer virus detection(October 2008)
Classifying packed malware represented as control flow graphs using deep graph convolutional neural network(March 2020)
Classifying packed programs as malicious software detected(December 2016)
A close look at a daily dataset of malware samples(January 2019)
Collective classification for packed executable identification(September 2011)
A compact multi-step framework for packing identification in portable executable files for malware analysis(February 2024)
A comparative analysis of classifiers in the recognition of packed executables(November 2019)
A comparative analysis of software protection schemes(June 2014)
A comparative assessment of malware classification using binary texture analysis and dynamic analysis(September 2011)
Comparing malware samples for unpacking: A feasibility study(August 2016)
Complexity-based packed executable classification with high accuracy(December 2008)
A comprehensive solution for obfuscation detection and removal based on comparative analysis of deobfuscation tools(October 2021)
Computational-intelligence techniques for malware generation(October 2015)
Conceptual and empirical comparison of dimensionality reduction algorithms (PCA, KPCA, LDA, MDS, SVD, LLE, ISOMAP, LE, ICA, t-SNE)(May 2021)
A consistently-executing graph-based approach for malware packer identification(April 2019)
A control flow graph-based signature for packer identification(October 2017)
Control flow-based opcode behavior analysis for malware detection(July 2014)
Countering entropy measure attacks on packed software detection(January 2012)
Dealing with virtualization packers(May 2008)
Deceiving portable executable malware classifiers into targeted misclassification with practical adversarial examples(March 2020)
Decoding the secrets of machine learning in malware classification: A deep dive into datasets, feature extraction, and model performance(July 2023)
Denial-of-service attacks on host-based generic unpackers(December 2009)
Deobfuscation of packed and virtualization-obfuscation protected binaries(June 2011)
Design and development of a new scanning core engine for malware detection(October 2012)
Design and performance evaluation of binary code packing for protecting embedded software against reverse engineering(May 2010)
Detecting obfuscated malware using reduced opcode set and optimised runtime trace(May 2016)
Detecting packed executable file: Supervised or anomaly detection method?(August 2016)
Detecting packed executables based on raw binary data(June 2010)
Detecting packed executables using steganalysis(December 2014)
Detecting packed PE files: Executable file analysis for the Windows operating system(June 2021)
Detecting traditional packers, decisively(October 2013)
Detecting unknown malicious code by applying classification techniques on opcode patterns(February 2012)
Detection of metamorphic malware packers using multilayered LSTM networks(November 2020)
Detection of packed executables using support vector machines(July 2011)
Detection of packed malware(August 2012)
DexHunter: Toward extracting hidden code from packed Android applications(September 2015)
Disabling anti-debugging techniques for unpacking system in user-level debugger(October 2019)
DroidPDF: The obfuscation resilient packer detection framework for Android Apps(July 2020)
Dynamic binary instrumentation for deobfuscation and unpacking(November 2009)
Dynamic classification of packing algorithms for inspecting executables using entropy analysis(October 2013)
A dynamic heuristic method for detecting packed malware using naive bayes(November 2019)
Effective, efficient, and robust packing detection and classification(May 2019)
An efficient algorithm to extract control flow-based features for ioT malware detection(April 2021)
Efficient and automatic instrumentation for packed binaries(June 2009)
Efficient automatic original entry point detection(January 2019)
An efficient block-discriminant identification of packed malware(August 2015)
Efficient malware packer identification using support vector machines with spectrum kernel(July 2013)
Efficient SVM based packer identification with binary diffing measures(July 2019)
ELF-Miner: Using structural knowledge and data mining methods to detect new (Linux) malicious executables(March 2012)
EMBER: An open dataset for training static PE malware machine learning models(April 2018)
An empirical evaluation of an unpacking method implemented with dynamic binary instrumentation(September 2011)
Encoded executable file detection technique via executable file header analysis(April 2009)
Enhancing machine learning based malware detection model by reinforcement learning(November 2018)
Entropy analysis to classify unknown packing algorithms for malware detection(May 2016)
ERMDS: A obfuscation dataset for evaluating robustness of learning-based malware detection system(May 2023)
ESCAPE: Entropy score analysis of packed executable(October 2012)
Ether: Malware analysis via hardware virtualization extensions(October 2008)
Eureka: A framework for enabling static malware analysis(October 2008)
Evading anti-malware engines with deep reinforcement learning(March 2019)
Evading machine learning malware detection(July 2017)
Evading packing detection: Breaking heuristic-based static detectors(July 2024)
Experimental comparison of machine learning models in malware packing detection(September 2020)
An experimental study on identifying obfuscation techniques in packer(June 2016)
Experimental toolkit for manipulating executable packing(June 2024)
Experimental toolkit for studying executable packing - Analysis of the state-of-the-art packing detection techniques(June 2022)
Fast and robust fixed-point algorithms for independent component analysis(May 1999)
A fast flowgraph based classification system for packed and polymorphic malware on the endhost(April 2010)
A fast randomness test that preserves local detail(October 2008)
Feature selection for malware detection based on reinforcement learning(December 2019)
Feature set reduction for the detection of packed executables(June 2014)
File packing from the malware perspective: Techniques, analysis approaches, and directions for enhancements(December 2022)
Fileprints: Identifying file types by n-gram analysis(June 2005)
A fine-grained classification approach for the packed malicious code(October 2012)
Functionality-preserving black-box optimization of adversarial windows malware(May 2021)
Generating adversarial malware examples for black-box attacks based on GAN(February 2020)
A generic approach to automatic deobfuscation of executable code(May 2015)
Generic black-box end-to-end attack against state of the art API call based malware classifiers(September 2018)
Generic packing detection using several complexity analysis for accurate malware detection(January 2014)
Generic unpacker of executable files(April 2015)
Generic unpacking method based on detecting original entry point(November 2013)
Generic unpacking of self-modifying, aggressive, packed binary programs(May 2009)
Generic unpacking techniques(February 2009)
Generic unpacking using entropy analysis(October 2010)
Gunpack: Un outil générique d'unpacking de malwares(June 2016)
Hashing-based encryption and anti-debugger support for packing multiple files into single executable(February 2018)
A heuristic approach for detection of obfuscated malware(June 2009)
A heuristics-based static analysis approach for detecting packed PE binaries(October 2013)
Identifying malware packers through multilayer feature engineering in static analysis(February 2024)
An implementation of a generic unpacking method on Bochs Emulator(September 2009)
An improved method for packed malware detection using PE header and section table information(September 2019)
Improving malware detection using multi-view ensemble learning(August 2016)
Incremental clustering of malware packers using features based on transformed CFG(November 2022)
Information theoretic method for classification of packed and encoded files(September 2015)
Instructions-based detection of sophisticated obfuscation and packing(October 2014)
Intriguing properties of adversarial ML attacks in the problem space(March 2020)
Intriguing properties of neural networks(February 2014)
A learning model to detect maliciousness of portable executable using integrated feature set(January 2017)
Learning to evade static PE machine learning malware models via reinforcement learning(January 2018)
Limits of static analysis for malware detection(December 2007)
MAB-Malware: A reinforcement learning framework for attacking static malware classifiers(April 2021)
A machine-learning-based framework for supporting malware detection and analysis(September 2021)
Maitland: Analysis of packed and encrypted malware via paravirtualization extensions(June 2012)
Mal-EVE: Static detection model for evasive malware(August 2015)
Mal-flux: Rendering hidden code of packed binary executable(March 2019)
Mal-XT: Higher accuracy hidden-code extraction of packed binary executable(November 2018)
Mal-xtract: Hidden code extraction using memory analysis(January 2017)
MaliCage: A packed malware family classification framework based on DNN and GAN(August 2022)
Malware analysis using multiple API sequence mining control flow graph(July 2017)
Malware analysis using visualized images and entropy graphs(February 2015)
Malware detection through opcode sequence analysis using machine learning(June 2015)
Malware family classification method based on static feature extraction(December 2017)
Malware images: Visualization and automatic classification(July 2011)
Malware makeover: Breaking ML-based static analysis by modifying executable bytes(May 2021)
Malware obfuscation techniques: A brief survey(November 2010)
Malware obfuscation through evolutionary packers(July 2015)
Malwise - An effective and efficient classification system for packed and polymorphic malware(June 2013)
McBoost: Boosting scalability in malware collection and analysis using statistical classification of executables(December 2008)
Memory behavior-based automatic malware unpacking in stealth debugging environment(October 2010)
MetaAware: Identifying metamorphic malware(December 2007)
Metadata recovery from obfuscated programs using machine learning(December 2016)
MLxPack: Investigating the effects of packers on ML-based malware detection systems using static and dynamic traits(May 2022)
Modern linux malware exposed(June 2018)
MutantX-S: Scalable malware clustering based on static features(June 2013)
The new signature generation method based on an unpacking algorithm and procedure for a packer detection(February 2011)
Novel feature extraction, selection and fusion for effective malware family classification(March 2016)
Obfuscation-resilient executable payload extraction from packed malware(August 2021)
Obfuscation: The hidden malware(August 2011)
Obfuscation: Where are we in anti-DSE protections? (a first attempt)(December 2019)
Obfuscator-LLVM: Software protection for the masses(May 2015)
OmniUnpack: Fast, generic, and safe unpacking of malware(December 2007)
On deceiving malware classification with section injection(August 2022)
On evaluating adversarial robustness(February 2019)
On the (Im)possibility of obfuscating programs(August 2001)
On the adoption of anomaly detection for packed executable filtering(June 2014)
Opcode sequences as representation of executables for data-mining-based unknown malware detection(May 2013)
Opcodes as predictor for malware(January 2008)
OPEM: A static-dynamic approach for machine-learning-based malware detection(September 2012)
Original entry point detection based on graph similarity(April 2024)
An original entry point detection method with candidate-sorting for more effective generic unpacking(January 2015)
Packed malware detection using entropy related analysis: A survey(November 2015)
Packed malware variants detection using deep belief networks(March 2020)
Packed PE file detection for malware forensics(December 2009)
Packer analysis report debugging and unpacking the NsPack 3.4 and 3.7 packer(June 2010)
Packer classification based on association rule mining(July 2022)
Packer classifier based on PE header information(April 2015)
Packer detection for multi-layer executables using entropy analysis(March 2017)
Packer identification based on metadata signature(December 2017)
Packer identification method based on byte sequences(November 2018)
Packer identification method for multi-layer executables with k-Nearest neighbor of entropies(October 2020)
Packer identification using byte plot and Markov plot(September 2015)
Packer identification using hidden Markov model(November 2017)
Packer-complexity analysis in PANDA(January 2018)
PackGenome: Automatically generating robust YARA rules for accurate malware packer detection(November 2023)
Packing detection and classification relying on machine learning to stop malware propagation(December 2021)
Pandora's Bochs: Automatic unpacking of malware(January 2008)
Pattern recognition techniques for the classification of malware packers(July 2010)
PE file features in detection of packed executables(January 2012)
PE file header analysis-based packed PE file detection technique (PHAD)(October 2008)
PE-Miner: Mining structural information to detect malicious executables in realtime(September 2009)
PE-Probe: Leveraging packer detection and structural information to detect malicious portable executables(June 2009)
PEAL - Packed executable analysis(January 2012)
PEzoNG: Advanced packer for automated evasion on Windows(December 2022)
PolyPack: An automated online packing service for optimal antivirus evasion(August 2009)
PolyUnpack: Automating the hidden-code extraction of unpack-executing malware(December 2006)
Potent and stealthy control flow obfuscation by stack based self-modifying code(April 2013)
Practical attacks on machine learning: A case study on adversarial windows malware(September 2022)
Preprocessing of binary executable files towards retargetable decompilation(July 2013)
Prevalence and impact of low-entropy packing schemes in the malware ecosystem(February 2020)
Qualitative and quantitative evaluation of software packers(December 2015)
RAMBO: Run-Time packer analysis with multiple branch observation(July 2016)
REFORM: A framework for malware packer analysis using information theory and statistical methods(April 2010)
Renovo: A hidden code extractor for packed executables(November 2007)
RePEconstruct: Reconstructing binaries with self-modifying code and import address table destruction(October 2016)
RePEF — A system for restoring packed executable file for malware analysis(July 2011)
Research and implementation of compression shell unpacking technology for PE file(May 2009)
Research and implementation of packing technology for PE files(January 2013)
Research of software information hiding algorithm based on packing technology(September 2020)
Revealing packed malware(September 2008)
Reverse engineering self-modifying code: Unpacker extraction(October 2010)
Robust static analysis of portable executable malware(December 2014)
Runtime packers testing experiences(May 2008)
SATURN - Software deobfuscation framework based on LLVM(November 2019)
SCORE: Source code optimization & reconstruction(July 2020)
SE-PAC: A self-evolving packer classifier against rapid packers evolution(April 2021)
Secure and advanced unpacking using computer emulation(August 2007)
Semi-supervised learning for packed executable detection(September 2011)
Semi-supervised learning for unknown malware detection(April 2011)
Sensitive system calls based packed malware variants detection using principal component initialized multilayers neural networks(September 2018)
Sequential opcode embedding-based malware detection method(March 2022)
SoK: (state of) the art of war: Offensive techniques in binary analysis(May 2016)
SoK: Automatic deobfuscation of virtualization-protected applications(August 2021)
SoK: Deep packer inspection: A longitudinal study of the complexity of run-time packers(May 2015)
SPADE: Signature based packer detection(August 2012)
Standards and policies on packer use(October 2010)
Static analysis method on portable executable files for REMNUX based malware identification(October 2019)
Static analysis of executables to detect malicious patterns(August 2003)
Static features exploration for executable packing with unsupervised learning(June 2023)
Static malware detection & subterfuge: Quantifying the robustness of machine learning and current anti-virus(June 2018)
A static, packer-agnostic filter to detect similar malware samples(July 2012)
Structural feature based anomaly detection for packed executable identification(June 2011)
The study of evasion of packed PE from static detection(June 2012)
A study of the packer problem and its solutions(September 2008)
A survey on adversarial attacks for malware analysis(January 2022)
A survey on machine learning-based detection and classification technology of malware(September 2021)
A survey on malware analysis techniques: Static, dynamic, hybrid and memory analysis(September 2018)
Survey on malware evasion techniques: State of the art and challenges(February 2012)
A survey on run-time packers and mitigation techniques(November 2023)
Symbolic deobfuscation: From virtualized code back to the original(July 2018)
Symbolic execution of obfuscated code(October 2015)
Syntia: Synthesizing the semantics of obfuscated code(August 2017)
Technical report on the cleverhans v2.1.0 adversarial examples library(June 2018)
Things you may not know about Android (Un) packers: A systematic study based on whole-system emulation.(February 2018)
Thwarting real-time dynamic unpacking(January 2011)
A token strengthened encryption packer to prevent reverse engineering PE files(January 2015)
Toward generic unpacking techniques for malware analysis with quantification of code revelation(August 2009)
Towards paving the way for large-scale Windows malware analysis: Generic binary unpacking with orders-of-magnitude performance boost(October 2018)
Towards static analysis of virtualization-obfuscated binaries(October 2012)
Transcending transcend: Revisiting malware classification in the presence of concept drift(December 2021)
Tutorial: An overview of malware detection and evasion techniques(December 2018)
Two techniques for detecting packed portable executable files(June 2013)
Unconditional self-modifying code elimination with dynamic compiler optimizations(October 2010)
Understanding linux malware(May 2018)
Unknown malcode detection using OPCODE representation(December 2008)
A unpacking and reconstruction system-agunpacker(January 2009)
Unpacking framework for packed malicious executables(July 2013)
Unpacking techniques and tools in malware analysis(September 2012)
Unpacking virtualization obfuscators(August 2009)
Unsupervised clustering machine learning on packed executable(June 2022)
UnThemida: Commercial obfuscation technique analysis with a fully obfuscated program(July 2018)
Using entropy analysis to find encrypted and packed malware(March 2007)
VMAttack: Deobfuscating virtualization-based packed binaries(August 2017)
VMHunt: A verifiable approach to partially-virtualized binary code simplification(October 2018)
VMRe: A reverse framework of virtual machine protection packed binaries(June 2019)
WaveAtlas: Surfing through the landscape of current malware packers(September 2015)
When malware is packin' heat; limits of machine learning classifiers based on static analysis features(January 2020)
WYSINWYX: What you see is not what you execute(August 2010)
x64Unpack: Hybrid emulation unpacker for 64-bit Windows Environments and detailed analysis results on VMProtect 3.4(July 2020)

Awesome Executable Packing / Datasets

ContagioContagio is a collection of the latest malware samples, threats, observations, and analyses
CyberCrimeC² tracking and malware database
Dataset of Packed ELF18over 3 years agoDataset of packed ELF samples
Dataset of Packed PE29about 2 years agoSanitized version of the original dataset, PackingData, removing packed samples from the Notpacked folder but also samples in packer folders that failed to be packed (having a same hash as the original unpacked executable)
Ember962almost 2 years agoCollection of features from PE files that serve as a benchmark dataset for researchers
FFRI Dataset Scripts10about 2 years agoMake datasets like FFRI Dataset
MaleX42almost 2 years agoCurated dataset of malware and benign Windows executable samples for malware researchers containing 1,044,394 Windows executable binaries and corresponding image representations with 864,669 labelled as malware and 179,725 as benign
MalfeaseDataset of about 5,000 packed malware samples
MalheurContains the recorded behavior of malicious software (malware) and has been used for developing methods for classifying and clustering malware behavior (see the JCS article from 2011)
MaliciaDataset of 11,688 malicous PE files collected from 500 drive-by download servers over a period of 11 months in 2013 (DISCONTINUED)
MalShareFree Malware repository providing researchers access to samples, malicious feeds, and Yara results
The Malware MuseumThe Malware Museum is a collection of malware programs, usually viruses, that were distributed in the 1980s and 1990s on home computers
MalwareBazaarProject operated by abuse.ch aimed to collect and share malware samples, helping IT-security researchers and threat analysts protecting their constituency and customers from cyber threats
MalwareGalleryYet another malware collection in the Internet
MalwareSamplesBringing you the best of the worst files on the Internet
MalwareTipsMalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats
OARC Malware DatasetSemi-public dataset of 3,467 samples captured in the wild from Sep 2005 to Jan 2006 by mail traps, user submissions, honeypots and other sources aggregated by the OARC, available to qualified academic and industry researchers upon request
Open Malware ProjectOnline collection of malware samples (formerly Offensive Computing)
PackingData11about 7 years agoOriginal dataset with sample PE files packed with a large variety of packers, including ASPack, BeRoEXEPacker, exe32pack, eXpressor, FSG, JDPack, MEW, Molebox, MPRESS, Neolite, NSPack, Pckman, PECompact, PEtite, RLPack, UPX, WinUpack, Yoda's Crypter and Yoda's Protector
Packware84over 2 years agoDatasets and codes that are needed to reproduce the experiments in the paper "When Malware is Packing Heat"
RCE Lab42about 4 years agoCrackme's, keygenme's, serialme's ; the "tuts4you" folder contains many packed binaries
Runtime Packers TestsetDataset of 10 common Malware files, packed with about 40 different runtime packers in over 500 versions and options, with a total of about 5,000 samples
SACSlovak Antivirus Center, non-commercial project of AVIR and ESET companies ; contains packers, detectors and unpackers
SOREL646over 5 years agoSophos-ReversingLabs 20 Million dataset
theZoo11,409over 2 years agoProject created to make the possibility of malware analysis open and available to the public
ViruSignAnother online malware database
VirusSamples
VirusShareVirus online database with more than 44 millions of samples
VirusTotalFile analysis Web service for detecting malware
VX HeavenSite dedicated to providing information about computer viruses
VX UndergroundPL-CERT based open source MWDB python application holding a malware database containing every APT sample from 2010 and over 7.5M maliciousbinaries
VXvaultOnline malware database
WildListCooperative listing of malwares reported as being in the wild by security professionals

Awesome Executable Packing / Packers / After 2010

AlienyzeAdvanced software protection and security for Windows 32-bit executables
Alternate EXE PackerCompression tool for executable files (type EXE) or DLL's relying on UPX 3.96
Amber1,208over 2 years agoPosition-independent(reflective) PE loader that enables in-memory execution of native PE files(EXE, DLL, SYS)
AndromedaCustom packer used in malware campaigns using RunPE techniques for evading AV mitigation methods
APKProtectAPK encryption and shell protection supporting Java and C++
ArmadilloIncorporates both a license manager and wrapper system for protecting PE files
ASPackAdvanced solution created to provide Win32 EXE file packing and to protect them against non-professional reverse engineering
ASProtect 32Multifunctional EXE packing tool designed for software developers to protect 32-bit applications with in-built application copy protection system
ASProtect 64Tool for protecting 64-bit applications and .NET applications for Windows against unauthorized use, industrial and home copying, professional hacking and analysis of software products distributed over the Internet and on any physical media
ASM Guard242over 2 years agoFree packer utility for compressing and complicating reversing compiled native code (native files), protecting resources, adding DRM, and packing into an optimized loader
AutoITLegitimate executable encryption service
AxProtectorEncrypts the complete software you aim to protect, and shields it with a security shell, AxEngine, best-of-breed anti-debugging and anti-disassembly methods are then injected into your software
BangCle389about 8 years agoProtection tool using the second generation Android Hardening Protection, loading the encrypted DEX file from memory dynamically
BeroBero EXE Packer (BEP) for 32-bit windows executables
BIN-crypterEXE protection software against crackers and decompilers
BoxedApp Packer
Code VirtualizerCode Virtualizer is a powerful code obfuscation system for Windows, Linux and macOS applications that helps developers to protect their sensitive code areas against Reverse Engineering with very strong obfuscation code, based on code virtualization
ConfuserEx2,403over 2 years agoAn open-source, free protector for .NET applications
Crinkler1,081about 4 years agoCompressing linker for Windows, specifically targeted towards executables with a size of just a few kilobytes
DarkCryptSimply and powerful plugin for Total Commander used for file encryption using 100 algorithms and 5 modes
DexGuardAndroid app obfuscation & security protocols for mobile app protection
DexProtectorMulti-layered RASP solution that secures your Android and iOS apps against static and dynamic analysis, illegal use and tampering
DotBundleGUI tool to compress, encrypt ad password-protect a .NET application or embed .NET libraries
DotNetZStraightforward and lightweight, command-line piece of software written in C that allows you to compress and pack Microsoft .NET Framework executable files
ElecKeySuite of software and tools that offer a complete solution for software protection, copy protection, and license management
ELFCrypt114about 6 years agoSimple ELF crypter using RC4 encryption
ELFuck32almost 11 years agoELF packer for i386 original version from sk2 by sd
Enigma ProtectorProfessional system for executable files licensing and protection
Enigma Virtual BoxApplication virtualization system for Windows
Eronona-Packer46over 6 years agoThis is a packer for exe under win32
EXE BundleBundles application files into a single PE32 file
EXE StealthAnti-cracking protection and licensing tool for PE files featuring compression and encryption polymorphic technology
Ezuri225about 2 years agoA Simple Linux ELF Runtime Crypter
GzExeUtility that allows to compress executables as a shell script
hXOR-Packer57about 5 years agoPE packer with Huffman compression and XOR encryption
Hyperion39over 2 years ago
LIAPPEasiest and most powerful mobile app security solution
LM-X License ManagerLM-X License Manager lets you protect your products against piracy by enforcing various levels of security, save time, and reduce business risks
m0dern_p4cker42over 5 years agoJust a modern packer for elf binaries ( works on linux executables only )
MidgetPack197about 12 years agoMidgetpack is a binary packer for ELF binaries, such as burneye, upx or other tools
MPRESSCompresses (using LZMA) and protects PE, .NET or Mach-O programs against reverse engineering
NetCrypt59almost 8 years agoA proof-of-concept packer for .NET executables, designed to provide a starting point to explain the basic principles of runtime packing
.netshrinkExecutable compressor for your Windows or Linux .NET application executable file using LZMA
NPackCan compress 32bits and 64bits exe, dll, ocx, scr Windows program
ObsidiumFeature-rich professional software protection and licensing system designed as a cost effective and easy to implement, yet reliable and non-invasive way to protect your 32- and 64-bit Windows software applications and games from reverse engineering
obfus.h986almost 2 years agoMacro-header for compile-time C obfuscation/virtualization (tcc, win x86/x64)
Origami168over 3 years agoPacker compressing .net assemblies, (ab)using the PE format for data storage
OSX_PackerBinary packer for the Mach-O file format
Pakkero252over 3 years agoPakkero is a binary packer written in Go made for fun and educational purpose
Pakr8over 9 years agoIn-memory packer for macOS Mach-O bundles
Papaw43over 4 years agoPermissively-licensed packer for ELF executables using LZMA Zstandard or Deflate compression
PE-Packer330almost 2 years agoSimple packer for Windows 32-bits PE files
PE-Toy9almost 10 years agoA PE file packer
PELockSoftware protection system for Windows executable files ; protects your applications from tampering and reverse engineering, and provides extensive support for software license key management, including support for time trial periods
PePacker49over 9 years agoSimple PE Packer Which Encrypts .text Section I release a simple PE file packer which encrypts the .text section and adds a decryption stub to the end of the last section
PEShieldPE-SHiELD is a program, which encrypts 32-bit Windows EXE files, leaving them still executable
PESpin
PEtiteFree Win32 (Windows 95/98/2000/NT/XP/Vista/7/etc) executable (EXE/DLL/etc) compressor
PEzoNGFramework for automatically creating stealth binaries that target a very low detection rate in a Windows environment
PEzor1,869over 2 years agoOpen-Source Shellcode & PE Packer
ProtectMyTooling893almost 2 years agoMulti-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry
RapidEXESimple and efficient way to convert a PHP/Python script to a standalone executable
Silent-Packer81over 2 years agoSilent Packer is an ELF / PE packer written in pure C
Simple-PE32-Packer10about 8 years agoSimple PE32 Packer with aPLib compression library
SimpleDPack110over 3 years agoA very simple windows EXE packing tool for learning or investigating PE structure
Smart PackerPacks 32 & 64bit applications with DLLs, data files, 3rd party run-time into one single executable that runs instantly, with no installs or hassles
SquishyModern packer developed for 64kb demoscene productions, targets 32bit and 64bit executables
theArk52almost 7 years agoWindows x86 PE Packer In C++
ThemidaFrom Renovo paper: Themida converts the original x86 instructions into virtual instructions in its own randomized instruction set, and then interpret these virtual instructions at run-time
UPXUltimate Packer for eXecutables
VirtualMachineObfuscationPoCObfuscation method using virtual machine
VMProtectVMProtect protects code by executing it on a virtual machine with non-standard architecture that makes it extremely difficult to analyze and crack the software
Ward19about 3 years agoSimple implementation of an ELF packer that creates stealthy droppers for loading malicious ELFs in-memory
xorPacker14about 6 years agoSimple packer working with all PE files which cipher your exe with a XOR implementation
ZProtectRenames metadata entities and supports advanced obfuscation methods that harden protection scheme and foil reverse engineering altogether

Awesome Executable Packing / Packers / Between 2000 and 2010

20to4Executable compressor that is able to stuff about 20k of finest code and data into less than 4k
ACProtectApplication that allows to protect Windows executable files against piracy, using RSA to create and verify the registration keys and unlock code
AHPackPE and PE+ file packer
Application ProtectorTool for protecting Windows applications
AT4RE ProtectorVery simple PE files protector programmed in ASM
AverCryptorSmall and very handy utility designed to encrypt notes in which you can store any private information - it helps to hide your infection from antiviruses
BurnEyeBurneye ELF encryption program, x86-linux binary
ByteBoozerCommodore 64 executable packer
CryptExecNext-generation runtime binary encryption using on-demand function extraction
EXE GuarderLicensing tool for PE files allowing to compress and specify a password notice
EXE WrapperProtects any EXE file with a password from non-authorized execution
Exe32PackCompresses Win32 EXEs, DLLs, etc and dynamically expands them upon execution
EXECryptorProtects EXE programs from reverse engineering, analysis, modifications and cracking
ExeFogSimple Win32 PE files packer
eXPressorUsed as a compressor this tool can compress EXE files to half their normal size
FSG, perfect compressor for small exes, eg
GHF ProtectorExecutable packer / protector based on open source engines Morphine and AHPack
HackStopEXE and COM programs encrypter and protector
KkrunchyKkrunchy is a small exe packer primarily meant for 64k intros
LaturiLinker and compressor intended to be used for macOS 1k, 4k and perhaps 64K intros
mPackmPack - mario PACKersimple Win32 PE Executable compressor
NSPack32/64-bits exe, dll, ocx, scr Windows program compressor
NTPackerPE file packer relying on aPlib for compression and/or XOR for encryption
PECompactWindows executable compressor featuring third-party plug-ins offering protection against reverse engineering
RDMCDMC algorithm based packer
RLPackCompresses your executables and dynamic link libraries in a way that keeps them small and has no effect on compressed file functionality
RSCCROSE Super COM Crypt ; polymorph cryptor for files greater than 300-400B and smaller than 60kB
RUCCROSE Ultra COM Compressor ; COM and EXE compression utility based on 624
Sentinel HASP EnvelopeWrapping application that protects the target application with a secure shield, providing a means to counteract reverse engineering and other anti-debugging measures
sePACKERSimple Executable Packer is compressing executables' code section inorder to decrease size of binary files
ShivaShiva is a tool to encrypt ELF executables under Linux
tElockTelock is a practical tool that intends to help developers who want to protect their work and reduce the size of the executable files
TTProtectProfessional protection tool designed for software developers to protect their PE applications against illegal modification or decompilation
UPackCompresses Windows PE file
UPX-ScramblerScrambler for files packed with UPX (up to 1.06) so that they cannot be unpacked with the '-d' option
WinUpackGraphical interface for Upack, a command-line program used to create self-extracting archives from Windows PE files
x86.Virtualizerx86 Virtualizer
XCompPE32 image file packer and rebuilder
Yoda CrypterSupports polymorphic encryption, softice detection, anti-debug API's, anti-dumping, etc, encrypts the Import Table and erases PE Header
Yoda ProtectorFree, open source, Windows 32-bit software protector

Awesome Executable Packing / Packers / Before 2000

32LiteCompression tool for executable files created with Watcom C/C++ compiler
624COM packer that can compress COM programs shorter than 25000 bytes
ABK ScramblerCOM file scrambler and protector recoded from ABKprot
AEPAddition Encode-Protective for COM and EXE file
AINEXEDOS executable packer (part of the AIN Archiver suite)
aPack16-bit real-mode DOS executable ( .EXE and .COM ) compressor
AVPackEncrypts EXE or COM files so that they'll be able to start on your PC only
AXEProgram compression utility
BIN-LockCOM file scrambler for preventing reverse engineering
BitLokCOM and EXE file protector
C0NtRiVERCOM file encryptor
CauseWay CompressorDOS EXE compressor
CC ProCOM and EXE executable file compression utility
CEXECompresses an input EXE into a smaller executable (only runs on WinNT, Win2000 and above - won't run on Win95 or Win98)
COMProtectorAdds a security envelope around DOS .COM files by randomly encrypting it and adding several anti-debugging tricks
CrackStopTool that creates a security envelope around a DOS EXE file to protect it against crackers
CrunchFile encryptor for COM and EXE files
EPackEXE and COM file compressor ; works with DOS/Windows95 files
ExeGuardDOS EXE files free protector using anti-debugging ticks to prevent hacking, analysis and unpacking
EXELOCK 666Utility for protecting .EXE files so no lamers can hack out the copyright
Fire-Pack
FSEFinal Fantasy Security Envelope freeware for protecting COM and EXE progams
Gardian AngelCOM and EXE encrypter and protector using a variety of anti-debugging tricks
JMCryptExeDOS EXE encrypter
LGLZDOS EXE and COM file compressor using modified LZ77
LzExeMS-DOS executable file compressor
MaskTool that prevents COM program from being cracked by using encryption and anti-debugging tricks
MegaliteMS-DOS executable file compressor
MessThis tool does the same as HackStop, with the exception that it is freeware for non-commercial use
Morphine289almost 10 years agoApplication for PE files encryption
NeoliteCompresses Windows 32-bit EXE files and DLLs
PACKExecutable files compressor
Pack-Ice
PCShrinkWindows 9x/NT executable file compressor relying on the aPLib compression library
PE DiminisherSimple PE packer relying on the aPLib compression library
PE-ProtectorEncrypter/protector for Windows 9x/ME to protect executable files PEagainst reverse engineering or cracking with a very strong protection
PEBundlePhysically attaches DLL(s) to an executable, resolving dependencies in memory
PEPackPE compression tool based on the code of a newer version of PE-SHiELD
PKliteEasy-to-use file compression program for compressing DOS and Windows executable files
Pro-PackDOS executable file compressor
RERPROSE's EXE Relocation Packer
RJCrushEXE and COM files compressor with the ability to compress overlays
ScorpionEXE and COM file encrypter and protector
SecuPackWin32 executable compressor
ShrinkerCompresses (up to 70%) 16 and 32 bit Windows and real mode DOS programs
SPack
$PIRITCOM/EXE executable files polymorphic encryptor
SysPackDevice drivers compressor
T-PackExecutable COM-FILE compressor (LZ77) optimized for small files like BBS-Addys or similar files
TinyProgEXE and COM programs compressor
TRAPEXE and COM files encrypter and protector
VacuumRuntime Compressor for DOS32 executables
VGCryptPE crypter for Win95/98/NT
WinLiteCompresses Windows executables (such as Pklite, Diet or Wwpack) for executables programs under DOS
WWPackSqueezes EXE files, compresses relocation tables, optimizes headers, protects EXE files from hacking
XEPE32 image file packer and rebuilder
XorCopyCOM file XOR-based encrypter
XORERCOM file XOR-based encrypter
XPADOS executable packer
XPackEXE/COM/SYS executable file compressor

Awesome Executable Packing / Tools

Android Unpacker1,129over 6 years agoAndroid Unpacker presented at Defcon 22: Android Hacker Protection Level 0
Angr7,647almost 2 years agoPlatform-agnostic binary analysis framework
APKiD2,096almost 2 years agoAndroid application Identifier for packers, protectors, obfuscators and oddities - PEiD for Android
aPLibCompression library based on the algorithm used in aPACK
AppSpear42over 8 years agoUniversal and automated unpacking system suitable for both Dalvik and ART
Assiste (Packer)Assiste.com's example list of packers
AVClass464almost 2 years agoPython tools to tag / label malware samples
Bintropy43almost 2 years agoPrototype analysis tool that estimates the likelihood that a binary file contains compressed or encrypted bytes
BinUnpackUnpacking approach free from tedious memory access monitoring, therefore introducing very small runtime overhead
BinutilsThe GNU Binutils are a collection of binary tools for Linux (it namely includes Readelf)
BitBlazeAnalysis platform that features a novel fusion of static and dynamic analysis techniques, mixed concrete and symbolic execution, and whole-system emulation and binary instrumentation, all to facilitate state-of-the art research on real security problems
Capa4,944almost 2 years agoOpen-source tool to identify capabilities in PE, ELF or .NET executable files
CapstoneLightweight multi-platform, multi-architecture disassembly framework
CFF ExplorerPE32/64 and .NET editor, part of the Explorer Suite
ChkEXEIdentifies almost any EXE/COM packer, crypter or protector
Clamscan UnpackerUnpacker derived from ClamAV
COM2EXEFree tool for converting COM files to EXE format
de4dot7,002about 6 years ago.NET deobfuscator and unpacker
de4js1,362almost 5 years agoJavaScript Deobfuscator and Unpacker
Defacto2 Analyzers ArchiveCollection of 60 binary files analysers for MS-DOS and Windows32 from the 1990s and the 2000s
Defacto2 Packers ArchiveCollection of 460 binary and data file packers for MS-DOS and Windows32 from the 1990s and 2000s
Defacto2 Unpackers ArchiveCollection of 152 binary files unpackers for MS-DOS and Windows 32 from the 1990s and 2000s
DIE2,431almost 2 years agoDetect It Easy ; Program for determining types of files
DSFF2about 2 years agoDataSet File Format for exchanging datasets and converting to ARFF (for use with Weka), CSV or Packing-Box's dataset structure
DynamoRIORuntime code manipulation system that supports code transformations on any part of a program, while it executes
EmulatorSymantec Endpoint Protector (from v14) capability to create a virtual machine on the fly to identify, detonate, and eliminate malware hiding inside custom malware packers
EtherUnpackPrecision universal automated unpacker (successor of PolyUnpack)
EurekaBinary static analysis preparation framework implementing a novel binary unpacking strategy based on statistical bigram analysis and coarse-grained execution tracing
EXEInfo-PE772almost 2 years agoFast detector for executable PE files
ExeScanExecutable file analyzer which detects the most famous EXE/COM Protectors, Packers, Converters and compilers
EXEToolsForum for reverse engineering and executale packing related topics
FUU46about 13 years agoFast Universal Unpacker
GetTypFile format detection program for DOS based on special strings and byte code
GUnpackerShell tool that performs OEP positioning and dumps decrypted code
Gym-Malware617almost 4 years agoThis is a malware manipulation environment for OpenAI's gym
IDR975about 3 years agoInteractive Delphi Reconstructor
ImpRECThis can be used to repair the import table for packed programs
JustinJust-In-Time AV scanning ; generic unpacking solution
Language 2000Ultimate compiler detection utility
LIEF4,546almost 2 years agoLibrary to Instrument Executable Formats ; Python package for parsing PE, ELF, Mach-O and DEX formats, modifying and rebuilding executables
LordPEPE header viewer, editor and rebuilder
Malheur369over 7 years agoTool for the automatic analysis of malware behavior (recorded from malicious software in a sandbox environment)
MalUnpack668over 2 years agoDynamic unpacker based on PE-sieve
Manalyze1,024over 2 years agoRobust parser for PE files with a flexible plugin architecture which allows users to statically analyze files in-depth
MRC(Mandiant Red Curtain) Free software for Incident Responders that assists with the analysis of malware ; it examines executable files (e.g., .exe, .dll, and so on) to determine how suspicious they are based on a set of criteria
.NET Deobfuscator1,264almost 4 years agoList of .NET Deobfuscators and Unpackers
Oedipus11about 10 years agoA Python framework that uses machine learning algorithms to implement the metadata recovery attack against obfuscated programs
OEPdetAutomated original-entry-point detector
OllyDbg Scripts9over 8 years agoCollection of OllyDbg scripts for unpacking many different packers
OmniUnpackNew technique for fast, generic, and safe unpacking of malware by monitoring the execution in real-time and detecting the removed layers of packing
PackerAttacker270over 8 years agoTool that uses memory and code hooks to detect packers
PackerBreakerTool for helping unpack, decompress and decrypt most of the programs packed, compressed or encrypted using advanced emulation technology
PackerGrind36over 4 years agoAdaptive unpacking tool for tracking packing bahaviors and unpacking Android packed apps
PackerID42over 6 years agoFork of packerid.py using PEid signatures and featuring additional output types, formats, digital signature extraction, and disassembly support
PackID9over 10 years agoPacker identification multiplatform tool/library using the same database syntax as PEiD
Packing-Box49almost 2 years agoDocker image gathering many packing-related tools and for making datasets of packed executables for use with machine learning
PANDA2,507almost 2 years agoPlatform for Architecture-Neutral Dynamic Analysis
Pandora's BochsExtension to the Bochs PC eumlator to enable it to monitor execution of the unpacking stubs for extracting the original code
PCjsPCjs uses JavaScript to recreate the IBM PC experience, using original ROMs, CPUs running at their original speeds, and early IBM video cards and monitors
PE Compression TestList of packers tested on a few sample executables for comparing compressed sizes
PE DetectiveThis GUI tool can scan single PE files or entire directories (also recursevely) and generate complete reports
PE-bear772over 3 years agoFreeware reversing tool for PE files aimed to deliver fast and flexible “first view” for malware analysts, stable and capable to handle malformed PE files
PEdumpDump windows PE files using Ruby
Pefeats2over 5 years agoUtility for extracting 119 features from a PE file for use with machine learning algorithms
Pefile1,890about 2 years agoMulti-platform Python module to parse and work with Portable Executable files
PEFrame612about 4 years agoTool for performing static analysis on PE malware and generic suspicious files
PEiDPacked Executable iDentifier
PEiD (CLI)130over 2 years agoPython implementation of PEiD featuring an additional tool for making new signatures
PEiD (yara)17over 9 years agoYet another implementation of PEiD with yara
PeLib63over 6 years agoPE file manipulation library
PEPack710over 2 years agoPE file packer detection tool, part of the Unix package "pev"
PEscanCLI tool to scan PE files to identify how they were constructed
PETools1,057over 8 years agoOld-school reverse engineering tool (with a long history since 2002) for manipulating PE files
PEviewProvides a quick and easy way to view the structure and content of 32-bit Portable Executable (PE) and Component Object File Format (COFF) files
PExplorerMost feature-packed program for inspecting the inner workings of your own software, and more importantly, third party Windows applications and libraries for which you do not have source code
PinDynamic binary instrumentation framework for the IA-32, x86-64 and MIC instruction-set architectures that enables the creation of dynamic program analysis tools
PINdemonium229about 10 years agoUnpacker for PE files exploiting the capabilities of PIN
PolyUnpack12over 14 years agoImplemention attempt of the general approach for extracting the original hidden code of PE files without any heuristic assumptions
PortEx499about 2 years agoJava library for static malware analysis of PE files with a focus on PE malformation robustness and anomaly detection
PROTECTiON iDPE file signature-based scanner
ProToolsProgrammer's Tools, a web site dedicated for all kinds of tools and utilities for the true WinBloze programmer, including packers, crypters, etc
PyPackerDetect30almost 8 years agoSmall python script/library to detect whether an executable is packed
PyPackerDetect (refactored)21almost 2 years agoA complete refactoring of the original project to a Python package with a console script to detect whether an executable is packed
PyPeid6over 2 years agoYet another implementation of PEiD with yara-python
Quick UnpackGeneric unpacker that facilitates the unpacking process
RDG Packer DetectorPacker detection tool
Reko2,173almost 2 years agoFree decompiler for machine code binaries
REMINDer2almost 2 years agoPacking detection tool based on the entropy value of the entry point section and the WRITE attribute
REMnuxLinux toolkit for reverse-engineering and analyzing malicious software
RenovoDetection tool built on top of TEMU (dynamic analysis component of BitBlaze) based on the execution of newly-generated code and monitoring memory writes after the program starts
ResourceHackerResource editor for 32bit and 64bit Windows applications
RetDec8,060about 2 years agoRetargetable machine-code decompiler based on LLVM
RTDRose Patch - TinyProt/Rosetiny Unpacker
RUPPROSE SWE UnPaCKER PaCKaGE (for DOS executables only)
SAFEStatic Analyzer For Executables (available on demand)
SecML Malware208almost 2 years agoCreate adversarial attacks against machine learning Windows malware detectors
ShowStopper197about 4 years agoTool to help malware researchers explore and test anti-debug techniques or verify debugger plugins or other solutions that clash with standard anti-debug methods
StudPEPE viewer and editor (32/64 bit)
SymPackSafe, portable, largely effective but not generic library for packing detection and unpacking ; part of the Norton Antivirus solution
Titanium PlatformMachine learning hybrid cloud platform that harvests thousands of file types at scale, speeds threat detection through machine learning binary analysis, and continuously monitors an index of over 10B files for future threats
TrIDUtility for identifying file types from their binary signatures
Triton3,565almost 2 years agoDynamic binary analysis library
Tuts 4 YouNon-commercial, independent community dedicated to the sharing of knowledge and information on reverse code engineering
Unipacker666about 2 years agoAutomatic and platform-independent unpacker for Windows binaries based on emulation
UnpacMeAutomated malware unpacking service
UnpckarcPacked executables detection tool relying on several heuristics
UUUniversal Unpacker
UundoUniversal Undo - Universal Unpacker
Uunp (IDA Pro plugin)IDA Pro debugger plug-in module automating the analysis and unpacking of packed binaries
UUPUniversal exe-file UnPacker
VMHunt175almost 8 years agoSet of tools for analyzing virtualized binary code ; now only supports 32 bit traces
VMUnpackerUnpacker based on the technology of virtual machine
Winbindex609almost 2 years agoAn index of Windows binaries, including download links for executables such as EXE, DLL and SYS files
yarGen1,569over 2 years agoGenerator for YARA rules - The main principle is the creation of yara rules from strings found in malware files while removing all strings that also appear in goodware files

Backlinks from these awesome lists:

More related projects: