awesome-executable-packing

Executable packing resources

A curated list of resources and tools related to executable packing and analysis

A curated list of awesome resources related to executable packing

GitHub

1k stars
45 watching
106 forks
last commit: 10 days ago
Linked from 4 awesome lists

awesomeawesome-listawesome-listsbinary-analysiscybersecurityexecutable-packinglistmalwaremalware-analysismalware-packersmalware-researchpackerspacking-detectionsecurity

Awesome Executable Packing / Literature / Documentation

a.out (FreeBSD manual pages)
A.out binary format
About anti-debug tricks
Android packers: Separating from the pack
Anti debugging protection techniques with examples
Anti-unpacker tricks
Anti-unpacker tricks - Part 14 (and previous parts)
API deobfuscator: Resolving obfuscated API functions in modern packers
The art of memory forensics: Detecting malware and threats in Windows, Linux, and mac memory
The art of unpacking
Awesome executable packing 1,206 10 days ago
Cloak and dagger: Unpacking hidden malware attacks
Cluster analysis
Clustering algorithms
COM binary format
Common object file format (COFF)
Comparison of executable file formats
A complexity measure
Cyclomatic complexity density and software maintenance productivity
Defacto2
Do we need hundreds of classifiers to solve real world classification problems?
Dynamic binary analysis and obfuscated codes
elf (FreeBSD manual pages)
Entropy and the distinctive signs of packer PE files
Executable and linkable format (ELF)
Executable and linking format (ELF) specification
Executable file formats
FatELF: Universal binaries for Linux (HALTED)
Feature selection: A data perspective
How to use t-SNE effectively
Hyperion: Implementation of a PE-Crypter
Implementing your own generic unpacker
Mach-O - A look at apple executable files
Mach-O file format reference 795 about 1 month ago
Mach-O internals
Machine learning
Making our own executable packer
The matthews correlation coefficient (MCC) should replace the ROC AUC as the standard metric for assessing binary classification
Microsoft portable executable and common object file format specification
MITRE ATT&CK | T1027.002 | obfuscated files or information: Software packing
MZ disk operating system (DOS)
NotPacked++: Evading static packing detection
On the worst-case complexity of timsort
One packer to rule them all: Empirical identification, comparison and circumvention of current antivirus detection techniques
One packer to rule them all: Empirical identification, comparison and circumvention of current antivirus detection techniques
Packer detection tool evaluation 11 over 3 years ago
Packers
Packing-box: Breaking detectors & visualizing packing
Packing-box: Improving detection of executable packing
Packing-box: Playing with executable packing
Parsing mach-O files
Pattern recognition and machine learning (Information science and statistics)
PE format - Win32 apps
PinDemonium: A DBI-based generic unpacker for Windows executables
Portable executable (PE)
Practical malware analysis: The hands-on guide to dissecting malicious software
ProtectMyTooling - Don't detect tools, detect techniques
Reverse engineering malware: Binary obfuscation and protection
Runtime packers: The hidden problem?
A survey of dimensionality reduction techniques
TitanMist: Your first step to reversing nirvana
Tuts 4 you - UnPackMe (.NET)
Tuts 4 you | unpackme
The "Ultimate" anti-debugging reference
Unpacking, reversing, patching
Virtual machine obfuscation
We can still crack you! General unpacking method for Android Packer (NO ROOT)
When malware is packing heat
Win32 portable executable packing uncovered
Writing a packer
Writing a simple PE packer in detail 15 over 5 years ago
x86 disassembly/Windows executable files

Awesome Executable Packing / Literature / Scientific Research

2-SPIFF: A 2-stage packer identification method based on function call graph and file attributes (December 2021)
Absent extreme learning machine algorithm with application to packed executable identification (January 2016)
An accurate packer identification method using support vector machine (January 2014)
Adaptive unpacking of Android Apps (May 2017)
Advanced feature engineering for static detection of executable packing (June 2024)
Advanced preprocessing of binary executable files and its usage in retargetable decompilation (December 2014)
Adversarial attacks against windows PE malware detection: A survey of the state-of-the-art (December 2021)
Adversarial EXEmples: A survey and experimental evaluation of practical attacks on machine learning for windows malware detection (September 2021)
Adversarial learning on static detection techniques for executable packing (June 2023)
Adversarial malware binaries: Evading deep learning for malware detection in executables (September 2018)
Adversarial tool for breaking static detection of executable packing (August 2024)
All-in-one framework for detection, unpacking, and verification for malware analysis (January 2019)
Analysis of machine learning approaches to packing detection (October 2023)
Anti-emulation trends in modern packers: A survey on the evolution of anti-emulation techniques in UPA packers (May 2018)
Anti-unpacker tricks (May 2008)
An application of machine learning to analysis of packed mac malware (May 2022)
Application of string kernel based support vector machine for malware packer identification (August 2013)
The application research of virtual machine in packers (August 2011)
AppSpear: Bytecode decrypting and DEX reassembling for packed Android malware (November 2015)
The arms race: Adversarial search defeats entropy used to detect malware (October 2018)
Assessing static and dynamic features for packing detection (October 2024)
Assessing the impact of packing on machine learning-based malware detection and classification systems (October 2024)
Automated static analysis of virtual-machine packers (August 2013)
Automatic analysis of malware behavior using machine learning (December 2011)
Automatic generation of adversarial examples for interpreting malware classifiers (March 2020)
Automatic static unpacking of malware binaries (October 2009)
BareUnpack: Generic unpacking on the bare-metal operating system (December 2018)
Binary-code obfuscations in prevalent packer tools (October 2013)
BinStat tool for recognition of packed executables (September 2010)
Birds of a feature: Intrafamily clustering for version identification of packed malware (September 2020)
BitBlaze: A new approach to computer security via binary analysis (December 2008)
Boosting scalability in anomaly-based packed executable filtering (November 2011)
Building a smart and automated tool for packed malware detections using machine learning (June 2020)
Bypassing anti-analysis of commercial protector methods using DBI tools (January 2021)
ByteWise: A case study in neural network obfuscation identification (January 2018)
Certified robustness of static deep learning-based malware detectors against patch and append attacks (November 2023)
Challenging anti-virus through evolutionary malware obfuscation (April 2016)
Chosen-instruction attack against commercial code virtualization obfuscators (April 2022)
Classification of packed executables for accurate computer virus detection (October 2008)
Classifying packed malware represented as control flow graphs using deep graph convolutional neural network (March 2020)
Classifying packed programs as malicious software detected (December 2016)
A close look at a daily dataset of malware samples (January 2019)
Collective classification for packed executable identification (September 2011)
A compact multi-step framework for packing identification in portable executable files for malware analysis (February 2024)
A comparative analysis of classifiers in the recognition of packed executables (November 2019)
A comparative analysis of software protection schemes (June 2014)
A comparative assessment of malware classification using binary texture analysis and dynamic analysis (September 2011)
Comparing malware samples for unpacking: A feasibility study (August 2016)
Complexity-based packed executable classification with high accuracy (December 2008)
A comprehensive solution for obfuscation detection and removal based on comparative analysis of deobfuscation tools (October 2021)
Computational-intelligence techniques for malware generation (October 2015)
Conceptual and empirical comparison of dimensionality reduction algorithms (PCA, KPCA, LDA, MDS, SVD, LLE, ISOMAP, LE, ICA, t-SNE) (May 2021)
A consistently-executing graph-based approach for malware packer identification (April 2019)
A control flow graph-based signature for packer identification (October 2017)
Control flow-based opcode behavior analysis for malware detection (July 2014)
Countering entropy measure attacks on packed software detection (January 2012)
Dealing with virtualization packers (May 2008)
Deceiving portable executable malware classifiers into targeted misclassification with practical adversarial examples (March 2020)
Decoding the secrets of machine learning in malware classification: A deep dive into datasets, feature extraction, and model performance (July 2023)
Denial-of-service attacks on host-based generic unpackers (December 2009)
Deobfuscation of packed and virtualization-obfuscation protected binaries (June 2011)
Design and development of a new scanning core engine for malware detection (October 2012)
Design and performance evaluation of binary code packing for protecting embedded software against reverse engineering (May 2010)
Detecting obfuscated malware using reduced opcode set and optimised runtime trace (May 2016)
Detecting packed executable file: Supervised or anomaly detection method? (August 2016)
Detecting packed executables based on raw binary data (June 2010)
Detecting packed executables using steganalysis (December 2014)
Detecting packed PE files: Executable file analysis for the Windows operating system (June 2021)
Detecting traditional packers, decisively (October 2013)
Detecting unknown malicious code by applying classification techniques on opcode patterns (February 2012)
Detection of metamorphic malware packers using multilayered LSTM networks (November 2020)
Detection of packed executables using support vector machines (July 2011)
Detection of packed malware (August 2012)
DexHunter: Toward extracting hidden code from packed Android applications (September 2015)
Disabling anti-debugging techniques for unpacking system in user-level debugger (October 2019)
DroidPDF: The obfuscation resilient packer detection framework for Android Apps (July 2020)
Dynamic binary instrumentation for deobfuscation and unpacking (November 2009)
Dynamic classification of packing algorithms for inspecting executables using entropy analysis (October 2013)
A dynamic heuristic method for detecting packed malware using naive bayes (November 2019)
Effective, efficient, and robust packing detection and classification (May 2019)
An efficient algorithm to extract control flow-based features for ioT malware detection (April 2021)
Efficient and automatic instrumentation for packed binaries (June 2009)
Efficient automatic original entry point detection (January 2019)
An efficient block-discriminant identification of packed malware (August 2015)
Efficient malware packer identification using support vector machines with spectrum kernel (July 2013)
Efficient SVM based packer identification with binary diffing measures (July 2019)
ELF-Miner: Using structural knowledge and data mining methods to detect new (Linux) malicious executables (March 2012)
EMBER: An open dataset for training static PE malware machine learning models (April 2018)
An empirical evaluation of an unpacking method implemented with dynamic binary instrumentation (September 2011)
Encoded executable file detection technique via executable file header analysis (April 2009)
Enhancing machine learning based malware detection model by reinforcement learning (November 2018)
Entropy analysis to classify unknown packing algorithms for malware detection (May 2016)
ERMDS: A obfuscation dataset for evaluating robustness of learning-based malware detection system (May 2023)
ESCAPE: Entropy score analysis of packed executable (October 2012)
Ether: Malware analysis via hardware virtualization extensions (October 2008)
Eureka: A framework for enabling static malware analysis (October 2008)
Evading anti-malware engines with deep reinforcement learning (March 2019)
Evading machine learning malware detection (July 2017)
Evading packing detection: Breaking heuristic-based static detectors (July 2024)
Experimental comparison of machine learning models in malware packing detection (September 2020)
An experimental study on identifying obfuscation techniques in packer (June 2016)
Experimental toolkit for manipulating executable packing (June 2024)
Experimental toolkit for studying executable packing - Analysis of the state-of-the-art packing detection techniques (June 2022)
Fast and robust fixed-point algorithms for independent component analysis (May 1999)
A fast flowgraph based classification system for packed and polymorphic malware on the endhost (April 2010)
A fast randomness test that preserves local detail (October 2008)
Feature selection for malware detection based on reinforcement learning (December 2019)
Feature set reduction for the detection of packed executables (June 2014)
File packing from the malware perspective: Techniques, analysis approaches, and directions for enhancements (December 2022)
Fileprints: Identifying file types by n-gram analysis (June 2005)
A fine-grained classification approach for the packed malicious code (October 2012)
Functionality-preserving black-box optimization of adversarial windows malware (May 2021)
Generating adversarial malware examples for black-box attacks based on GAN (February 2020)
A generic approach to automatic deobfuscation of executable code (May 2015)
Generic black-box end-to-end attack against state of the art API call based malware classifiers (September 2018)
Generic packing detection using several complexity analysis for accurate malware detection (January 2014)
Generic unpacker of executable files (April 2015)
Generic unpacking method based on detecting original entry point (November 2013)
Generic unpacking of self-modifying, aggressive, packed binary programs (May 2009)
Generic unpacking techniques (February 2009)
Generic unpacking using entropy analysis (October 2010)
Gunpack: Un outil générique d'unpacking de malwares (June 2016)
Hashing-based encryption and anti-debugger support for packing multiple files into single executable (February 2018)
A heuristic approach for detection of obfuscated malware (June 2009)
A heuristics-based static analysis approach for detecting packed PE binaries (October 2013)
Identifying malware packers through multilayer feature engineering in static analysis (February 2024)
An implementation of a generic unpacking method on Bochs Emulator (September 2009)
An improved method for packed malware detection using PE header and section table information (September 2019)
Improving malware detection using multi-view ensemble learning (August 2016)
Incremental clustering of malware packers using features based on transformed CFG (November 2022)
Information theoretic method for classification of packed and encoded files (September 2015)
Instructions-based detection of sophisticated obfuscation and packing (October 2014)
Intriguing properties of adversarial ML attacks in the problem space (March 2020)
Intriguing properties of neural networks (February 2014)
A learning model to detect maliciousness of portable executable using integrated feature set (January 2017)
Learning to evade static PE machine learning malware models via reinforcement learning (January 2018)
Limits of static analysis for malware detection (December 2007)
MAB-Malware: A reinforcement learning framework for attacking static malware classifiers (April 2021)
A machine-learning-based framework for supporting malware detection and analysis (September 2021)
Maitland: Analysis of packed and encrypted malware via paravirtualization extensions (June 2012)
Mal-EVE: Static detection model for evasive malware (August 2015)
Mal-flux: Rendering hidden code of packed binary executable (March 2019)
Mal-XT: Higher accuracy hidden-code extraction of packed binary executable (November 2018)
Mal-xtract: Hidden code extraction using memory analysis (January 2017)
MaliCage: A packed malware family classification framework based on DNN and GAN (August 2022)
Malware analysis using multiple API sequence mining control flow graph (July 2017)
Malware analysis using visualized images and entropy graphs (February 2015)
Malware detection through opcode sequence analysis using machine learning (June 2015)
Malware family classification method based on static feature extraction (December 2017)
Malware images: Visualization and automatic classification (July 2011)
Malware makeover: Breaking ML-based static analysis by modifying executable bytes (May 2021)
Malware obfuscation techniques: A brief survey (November 2010)
Malware obfuscation through evolutionary packers (July 2015)
Malwise - An effective and efficient classification system for packed and polymorphic malware (June 2013)
McBoost: Boosting scalability in malware collection and analysis using statistical classification of executables (December 2008)
Memory behavior-based automatic malware unpacking in stealth debugging environment (October 2010)
MetaAware: Identifying metamorphic malware (December 2007)
Metadata recovery from obfuscated programs using machine learning (December 2016)
MLxPack: Investigating the effects of packers on ML-based malware detection systems using static and dynamic traits (May 2022)
Modern linux malware exposed (June 2018)
MutantX-S: Scalable malware clustering based on static features (June 2013)
The new signature generation method based on an unpacking algorithm and procedure for a packer detection (February 2011)
Novel feature extraction, selection and fusion for effective malware family classification (March 2016)
Obfuscation-resilient executable payload extraction from packed malware (August 2021)
Obfuscation: The hidden malware (August 2011)
Obfuscation: Where are we in anti-DSE protections? (a first attempt) (December 2019)
Obfuscator-LLVM: Software protection for the masses (May 2015)
OmniUnpack: Fast, generic, and safe unpacking of malware (December 2007)
On deceiving malware classification with section injection (August 2022)
On evaluating adversarial robustness (February 2019)
On the (Im)possibility of obfuscating programs (August 2001)
On the adoption of anomaly detection for packed executable filtering (June 2014)
Opcode sequences as representation of executables for data-mining-based unknown malware detection (May 2013)
Opcodes as predictor for malware (January 2008)
OPEM: A static-dynamic approach for machine-learning-based malware detection (September 2012)
Original entry point detection based on graph similarity (April 2024)
An original entry point detection method with candidate-sorting for more effective generic unpacking (January 2015)
Packed malware detection using entropy related analysis: A survey (November 2015)
Packed malware variants detection using deep belief networks (March 2020)
Packed PE file detection for malware forensics (December 2009)
Packer analysis report debugging and unpacking the NsPack 3.4 and 3.7 packer (June 2010)
Packer classification based on association rule mining (July 2022)
Packer classifier based on PE header information (April 2015)
Packer detection for multi-layer executables using entropy analysis (March 2017)
Packer identification based on metadata signature (December 2017)
Packer identification method based on byte sequences (November 2018)
Packer identification method for multi-layer executables with k-Nearest neighbor of entropies (October 2020)
Packer identification using byte plot and Markov plot (September 2015)
Packer identification using hidden Markov model (November 2017)
Packer-complexity analysis in PANDA (January 2018)
PackGenome: Automatically generating robust YARA rules for accurate malware packer detection (November 2023)
Packing detection and classification relying on machine learning to stop malware propagation (December 2021)
Pandora's Bochs: Automatic unpacking of malware (January 2008)
Pattern recognition techniques for the classification of malware packers (July 2010)
PE file features in detection of packed executables (January 2012)
PE file header analysis-based packed PE file detection technique (PHAD) (October 2008)
PE-Miner: Mining structural information to detect malicious executables in realtime (September 2009)
PE-Probe: Leveraging packer detection and structural information to detect malicious portable executables (June 2009)
PEAL - Packed executable analysis (January 2012)
PEzoNG: Advanced packer for automated evasion on Windows (December 2022)
PolyPack: An automated online packing service for optimal antivirus evasion (August 2009)
PolyUnpack: Automating the hidden-code extraction of unpack-executing malware (December 2006)
Potent and stealthy control flow obfuscation by stack based self-modifying code (April 2013)
Practical attacks on machine learning: A case study on adversarial windows malware (September 2022)
Preprocessing of binary executable files towards retargetable decompilation (July 2013)
Prevalence and impact of low-entropy packing schemes in the malware ecosystem (February 2020)
Qualitative and quantitative evaluation of software packers (December 2015)
RAMBO: Run-Time packer analysis with multiple branch observation (July 2016)
REFORM: A framework for malware packer analysis using information theory and statistical methods (April 2010)
Renovo: A hidden code extractor for packed executables (November 2007)
RePEconstruct: Reconstructing binaries with self-modifying code and import address table destruction (October 2016)
RePEF — A system for restoring packed executable file for malware analysis (July 2011)
Research and implementation of compression shell unpacking technology for PE file (May 2009)
Research and implementation of packing technology for PE files (January 2013)
Research of software information hiding algorithm based on packing technology (September 2020)
Revealing packed malware (September 2008)
Reverse engineering self-modifying code: Unpacker extraction (October 2010)
Robust static analysis of portable executable malware (December 2014)
Runtime packers testing experiences (May 2008)
SATURN - Software deobfuscation framework based on LLVM (November 2019)
SCORE: Source code optimization & reconstruction (July 2020)
SE-PAC: A self-evolving packer classifier against rapid packers evolution (April 2021)
Secure and advanced unpacking using computer emulation (August 2007)
Semi-supervised learning for packed executable detection (September 2011)
Semi-supervised learning for unknown malware detection (April 2011)
Sensitive system calls based packed malware variants detection using principal component initialized multilayers neural networks (September 2018)
Sequential opcode embedding-based malware detection method (March 2022)
SoK: (state of) the art of war: Offensive techniques in binary analysis (May 2016)
SoK: Automatic deobfuscation of virtualization-protected applications (August 2021)
SoK: Deep packer inspection: A longitudinal study of the complexity of run-time packers (May 2015)
SPADE: Signature based packer detection (August 2012)
Standards and policies on packer use (October 2010)
Static analysis method on portable executable files for REMNUX based malware identification (October 2019)
Static analysis of executables to detect malicious patterns (August 2003)
Static features exploration for executable packing with unsupervised learning (June 2023)
Static malware detection & subterfuge: Quantifying the robustness of machine learning and current anti-virus (June 2018)
A static, packer-agnostic filter to detect similar malware samples (July 2012)
Structural feature based anomaly detection for packed executable identification (June 2011)
The study of evasion of packed PE from static detection (June 2012)
A study of the packer problem and its solutions (September 2008)
A survey on adversarial attacks for malware analysis (January 2022)
A survey on machine learning-based detection and classification technology of malware (September 2021)
A survey on malware analysis techniques: Static, dynamic, hybrid and memory analysis (September 2018)
Survey on malware evasion techniques: State of the art and challenges (February 2012)
A survey on run-time packers and mitigation techniques (November 2023)
Symbolic deobfuscation: From virtualized code back to the original (July 2018)
Symbolic execution of obfuscated code (October 2015)
Syntia: Synthesizing the semantics of obfuscated code (August 2017)
Technical report on the cleverhans v2.1.0 adversarial examples library (June 2018)
Things you may not know about Android (Un) packers: A systematic study based on whole-system emulation. (February 2018)
Thwarting real-time dynamic unpacking (January 2011)
A token strengthened encryption packer to prevent reverse engineering PE files (January 2015)
Toward generic unpacking techniques for malware analysis with quantification of code revelation (August 2009)
Towards paving the way for large-scale Windows malware analysis: Generic binary unpacking with orders-of-magnitude performance boost (October 2018)
Towards static analysis of virtualization-obfuscated binaries (October 2012)
Transcending transcend: Revisiting malware classification in the presence of concept drift (December 2021)
Tutorial: An overview of malware detection and evasion techniques (December 2018)
Two techniques for detecting packed portable executable files (June 2013)
Unconditional self-modifying code elimination with dynamic compiler optimizations (October 2010)
Understanding linux malware (May 2018)
Unknown malcode detection using OPCODE representation (December 2008)
A unpacking and reconstruction system-agunpacker (January 2009)
Unpacking framework for packed malicious executables (July 2013)
Unpacking techniques and tools in malware analysis (September 2012)
Unpacking virtualization obfuscators (August 2009)
Unsupervised clustering machine learning on packed executable (June 2022)
UnThemida: Commercial obfuscation technique analysis with a fully obfuscated program (July 2018)
Using entropy analysis to find encrypted and packed malware (March 2007)
VMAttack: Deobfuscating virtualization-based packed binaries (August 2017)
VMHunt: A verifiable approach to partially-virtualized binary code simplification (October 2018)
VMRe: A reverse framework of virtual machine protection packed binaries (June 2019)
WaveAtlas: Surfing through the landscape of current malware packers (September 2015)
When malware is packin' heat; limits of machine learning classifiers based on static analysis features (January 2020)
WYSINWYX: What you see is not what you execute (August 2010)
x64Unpack: Hybrid emulation unpacker for 64-bit Windows Environments and detailed analysis results on VMProtect 3.4 (July 2020)

Awesome Executable Packing / Datasets

Contagio Contagio is a collection of the latest malware samples, threats, observations, and analyses
CyberCrime C² tracking and malware database
Dataset of Packed ELF 17 almost 2 years ago Dataset of packed ELF samples
Dataset of Packed PE 29 4 months ago Sanitized version of the original dataset, PackingData, removing packed samples from the Notpacked folder but also samples in packer folders that failed to be packed (having a same hash as the original unpacked executable)
Ember 946 4 months ago Collection of features from PE files that serve as a benchmark dataset for researchers
FFRI Dataset Scripts 10 4 months ago Make datasets like FFRI Dataset
MaleX 39 about 1 month ago Curated dataset of malware and benign Windows executable samples for malware researchers containing 1,044,394 Windows executable binaries and corresponding image representations with 864,669 labelled as malware and 179,725 as benign
Malfease Dataset of about 5,000 packed malware samples
Malheur Contains the recorded behavior of malicious software (malware) and has been used for developing methods for classifying and clustering malware behavior (see the JCS article from 2011)
Malicia Dataset of 11,688 malicous PE files collected from 500 drive-by download servers over a period of 11 months in 2013 (DISCONTINUED)
MalShare Free Malware repository providing researchers access to samples, malicious feeds, and Yara results
The Malware Museum The Malware Museum is a collection of malware programs, usually viruses, that were distributed in the 1980s and 1990s on home computers
MalwareBazaar Project operated by abuse.ch aimed to collect and share malware samples, helping IT-security researchers and threat analysts protecting their constituency and customers from cyber threats
MalwareGallery Yet another malware collection in the Internet
MalwareSamples Bringing you the best of the worst files on the Internet
MalwareTips MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats
OARC Malware Dataset Semi-public dataset of 3,467 samples captured in the wild from Sep 2005 to Jan 2006 by mail traps, user submissions, honeypots and other sources aggregated by the OARC, available to qualified academic and industry researchers upon request
Open Malware Project Online collection of malware samples (formerly Offensive Computing)
PackingData 11 about 5 years ago Original dataset with sample PE files packed with a large variety of packers, including ASPack, BeRoEXEPacker, exe32pack, eXpressor, FSG, JDPack, MEW, Molebox, MPRESS, Neolite, NSPack, Pckman, PECompact, PEtite, RLPack, UPX, WinUpack, Yoda's Crypter and Yoda's Protector
Packware 83 5 months ago Datasets and codes that are needed to reproduce the experiments in the paper "When Malware is Packing Heat"
RCE Lab 41 about 2 years ago Crackme's, keygenme's, serialme's ; the "tuts4you" folder contains many packed binaries
Runtime Packers Testset Dataset of 10 common Malware files, packed with about 40 different runtime packers in over 500 versions and options, with a total of about 5,000 samples
SAC Slovak Antivirus Center, non-commercial project of AVIR and ESET companies ; contains packers, detectors and unpackers
SOREL 638 over 3 years ago Sophos-ReversingLabs 20 Million dataset
theZoo 11,317 6 months ago Project created to make the possibility of malware analysis open and available to the public
ViruSign Another online malware database
VirusSamples
VirusShare Virus online database with more than 44 millions of samples
VirusTotal File analysis Web service for detecting malware
VX Heaven Site dedicated to providing information about computer viruses
VX Underground PL-CERT based open source MWDB python application holding a malware database containing every APT sample from 2010 and over 7.5M maliciousbinaries
VXvault Online malware database
WildList Cooperative listing of malwares reported as being in the wild by security professionals

Awesome Executable Packing / Packers / After 2010

Alienyze Advanced software protection and security for Windows 32-bit executables
Alternate EXE Packer Compression tool for executable files (type EXE) or DLL's relying on UPX 3.96
Amber 1,187 9 months ago Position-independent(reflective) PE loader that enables in-memory execution of native PE files(EXE, DLL, SYS)
Andromeda Custom packer used in malware campaigns using RunPE techniques for evading AV mitigation methods
APKProtect APK encryption and shell protection supporting Java and C++
Armadillo Incorporates both a license manager and wrapper system for protecting PE files
ASPack Advanced solution created to provide Win32 EXE file packing and to protect them against non-professional reverse engineering
ASProtect 32 Multifunctional EXE packing tool designed for software developers to protect 32-bit applications with in-built application copy protection system
ASProtect 64 Tool for protecting 64-bit applications and .NET applications for Windows against unauthorized use, industrial and home copying, professional hacking and analysis of software products distributed over the Internet and on any physical media
AutoIT Legitimate executable encryption service
AxProtector Encrypts the complete software you aim to protect, and shields it with a security shell, AxEngine, best-of-breed anti-debugging and anti-disassembly methods are then injected into your software
BangCle 389 over 6 years ago Protection tool using the second generation Android Hardening Protection, loading the encrypted DEX file from memory dynamically
Bero Bero EXE Packer (BEP) for 32-bit windows executables
BIN-crypter EXE protection software against crackers and decompilers
BoxedApp Packer
Code Virtualizer Code Virtualizer is a powerful code obfuscation system for Windows, Linux and macOS applications that helps developers to protect their sensitive code areas against Reverse Engineering with very strong obfuscation code, based on code virtualization
ConfuserEx 2,369 6 months ago An open-source, free protector for .NET applications
Crinkler 1,075 over 2 years ago Compressing linker for Windows, specifically targeted towards executables with a size of just a few kilobytes
DarkCrypt Simply and powerful plugin for Total Commander used for file encryption using 100 algorithms and 5 modes
DexGuard Android app obfuscation & security protocols for mobile app protection
DexProtector Multi-layered RASP solution that secures your Android and iOS apps against static and dynamic analysis, illegal use and tampering
DotBundle GUI tool to compress, encrypt ad password-protect a .NET application or embed .NET libraries
DotNetZ Straightforward and lightweight, command-line piece of software written in C that allows you to compress and pack Microsoft .NET Framework executable files
ElecKey Suite of software and tools that offer a complete solution for software protection, copy protection, and license management
ELFCrypt 93 about 4 years ago Simple ELF crypter using RC4 encryption
ELFuck 32 almost 9 years ago ELF packer for i386 original version from sk2 by sd
Enigma Protector Professional system for executable files licensing and protection
Enigma Virtual Box Application virtualization system for Windows
Eronona-Packer 46 almost 5 years ago This is a packer for exe under win32
EXE Bundle Bundles application files into a single PE32 file
EXE Stealth Anti-cracking protection and licensing tool for PE files featuring compression and encryption polymorphic technology
Ezuri 226 about 2 months ago A Simple Linux ELF Runtime Crypter
GzExe Utility that allows to compress executables as a shell script
hXOR-Packer 58 about 3 years ago PE packer with Huffman compression and XOR encryption
Hyperion 39 7 months ago
LIAPP Easiest and most powerful mobile app security solution
LM-X License Manager LM-X License Manager lets you protect your products against piracy by enforcing various levels of security, save time, and reduce business risks
m0dern_p4cker 42 over 3 years ago Just a modern packer for elf binaries ( works on linux executables only )
MidgetPack 197 over 10 years ago Midgetpack is a binary packer for ELF binaries, such as burneye, upx or other tools
MPRESS Compresses (using LZMA) and protects PE, .NET or Mach-O programs against reverse engineering
NetCrypt 58 about 6 years ago A proof-of-concept packer for .NET executables, designed to provide a starting point to explain the basic principles of runtime packing
.netshrink Executable compressor for your Windows or Linux .NET application executable file using LZMA
NPack Can compress 32bits and 64bits exe, dll, ocx, scr Windows program
Obsidium Feature-rich professional software protection and licensing system designed as a cost effective and easy to implement, yet reliable and non-invasive way to protect your 32- and 64-bit Windows software applications and games from reverse engineering
Origami 168 almost 2 years ago Packer compressing .net assemblies, (ab)using the PE format for data storage
OSX_Packer Binary packer for the Mach-O file format
Pakkero 250 almost 2 years ago Pakkero is a binary packer written in Go made for fun and educational purpose
Pakr 8 almost 8 years ago In-memory packer for macOS Mach-O bundles
Papaw 41 over 2 years ago Permissively-licensed packer for ELF executables using LZMA Zstandard or Deflate compression
PE-Packer 328 about 1 month ago Simple packer for Windows 32-bits PE files
PE-Toy 9 almost 8 years ago A PE file packer
PELock Software protection system for Windows executable files ; protects your applications from tampering and reverse engineering, and provides extensive support for software license key management, including support for time trial periods
PePacker 49 over 7 years ago Simple PE Packer Which Encrypts .text Section I release a simple PE file packer which encrypts the .text section and adds a decryption stub to the end of the last section
PEShield PE-SHiELD is a program, which encrypts 32-bit Windows EXE files, leaving them still executable
PESpin
PEtite Free Win32 (Windows 95/98/2000/NT/XP/Vista/7/etc) executable (EXE/DLL/etc) compressor
PEzoNG Framework for automatically creating stealth binaries that target a very low detection rate in a Windows environment
PEzor 1,856 10 months ago Open-Source Shellcode & PE Packer
ProtectMyTooling 872 about 1 year ago Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry
RapidEXE Simple and efficient way to convert a PHP/Python script to a standalone executable
Silent-Packer 80 8 months ago Silent Packer is an ELF / PE packer written in pure C
Simple-PE32-Packer 10 about 6 years ago Simple PE32 Packer with aPLib compression library
SimpleDPack 108 almost 2 years ago A very simple windows EXE packing tool for learning or investigating PE structure
Smart Packer Packs 32 & 64bit applications with DLLs, data files, 3rd party run-time into one single executable that runs instantly, with no installs or hassles
Squishy Modern packer developed for 64kb demoscene productions, targets 32bit and 64bit executables
theArk 52 about 5 years ago Windows x86 PE Packer In C++
Themida From Renovo paper: Themida converts the original x86 instructions into virtual instructions in its own randomized instruction set, and then interpret these virtual instructions at run-time
UPX Ultimate Packer for eXecutables
VirtualMachineObfuscationPoC Obfuscation method using virtual machine
VMProtect VMProtect protects code by executing it on a virtual machine with non-standard architecture that makes it extremely difficult to analyze and crack the software
Ward 18 over 1 year ago Simple implementation of an ELF packer that creates stealthy droppers for loading malicious ELFs in-memory
xorPacker 14 over 4 years ago Simple packer working with all PE files which cipher your exe with a XOR implementation
ZProtect Renames metadata entities and supports advanced obfuscation methods that harden protection scheme and foil reverse engineering altogether

Awesome Executable Packing / Packers / Between 2000 and 2010

20to4 Executable compressor that is able to stuff about 20k of finest code and data into less than 4k
ACProtect Application that allows to protect Windows executable files against piracy, using RSA to create and verify the registration keys and unlock code
AHPack PE and PE+ file packer
Application Protector Tool for protecting Windows applications
AT4RE Protector Very simple PE files protector programmed in ASM
AverCryptor Small and very handy utility designed to encrypt notes in which you can store any private information - it helps to hide your infection from antiviruses
BurnEye Burneye ELF encryption program, x86-linux binary
ByteBoozer Commodore 64 executable packer
CryptExec Next-generation runtime binary encryption using on-demand function extraction
EXE Guarder Licensing tool for PE files allowing to compress and specify a password notice
EXE Wrapper Protects any EXE file with a password from non-authorized execution
Exe32Pack Compresses Win32 EXEs, DLLs, etc and dynamically expands them upon execution
EXECryptor Protects EXE programs from reverse engineering, analysis, modifications and cracking
ExeFog Simple Win32 PE files packer
eXPressor Used as a compressor this tool can compress EXE files to half their normal size
FSG , perfect compressor for small exes, eg
GHF Protector Executable packer / protector based on open source engines Morphine and AHPack
HackStop EXE and COM programs encrypter and protector
Kkrunchy Kkrunchy is a small exe packer primarily meant for 64k intros
Laturi Linker and compressor intended to be used for macOS 1k, 4k and perhaps 64K intros
mPack mPack - mario PACKersimple Win32 PE Executable compressor
NSPack 32/64-bits exe, dll, ocx, scr Windows program compressor
NTPacker PE file packer relying on aPlib for compression and/or XOR for encryption
PECompact Windows executable compressor featuring third-party plug-ins offering protection against reverse engineering
RDMC DMC algorithm based packer
RLPack Compresses your executables and dynamic link libraries in a way that keeps them small and has no effect on compressed file functionality
RSCC ROSE Super COM Crypt ; polymorph cryptor for files greater than 300-400B and smaller than 60kB
RUCC ROSE Ultra COM Compressor ; COM and EXE compression utility based on 624
Sentinel HASP Envelope Wrapping application that protects the target application with a secure shield, providing a means to counteract reverse engineering and other anti-debugging measures
sePACKER Simple Executable Packer is compressing executables' code section inorder to decrease size of binary files
Shiva Shiva is a tool to encrypt ELF executables under Linux
tElock Telock is a practical tool that intends to help developers who want to protect their work and reduce the size of the executable files
TTProtect Professional protection tool designed for software developers to protect their PE applications against illegal modification or decompilation
UPack Compresses Windows PE file
UPX-Scrambler Scrambler for files packed with UPX (up to 1.06) so that they cannot be unpacked with the '-d' option
WinUpack Graphical interface for Upack, a command-line program used to create self-extracting archives from Windows PE files
x86.Virtualizer x86 Virtualizer
XComp PE32 image file packer and rebuilder
Yoda Crypter Supports polymorphic encryption, softice detection, anti-debug API's, anti-dumping, etc, encrypts the Import Table and erases PE Header
Yoda Protector Free, open source, Windows 32-bit software protector

Awesome Executable Packing / Packers / Before 2000

32Lite Compression tool for executable files created with Watcom C/C++ compiler
624 COM packer that can compress COM programs shorter than 25000 bytes
ABK Scrambler COM file scrambler and protector recoded from ABKprot
AEP Addition Encode-Protective for COM and EXE file
AINEXE DOS executable packer (part of the AIN Archiver suite)
aPack 16-bit real-mode DOS executable ( .EXE and .COM ) compressor
AVPack Encrypts EXE or COM files so that they'll be able to start on your PC only
AXE Program compression utility
BIN-Lock COM file scrambler for preventing reverse engineering
BitLok COM and EXE file protector
C0NtRiVER COM file encryptor
CauseWay Compressor DOS EXE compressor
CC Pro COM and EXE executable file compression utility
CEXE Compresses an input EXE into a smaller executable (only runs on WinNT, Win2000 and above - won't run on Win95 or Win98)
COMProtector Adds a security envelope around DOS .COM files by randomly encrypting it and adding several anti-debugging tricks
CrackStop Tool that creates a security envelope around a DOS EXE file to protect it against crackers
Crunch File encryptor for COM and EXE files
EPack EXE and COM file compressor ; works with DOS/Windows95 files
ExeGuard DOS EXE files free protector using anti-debugging ticks to prevent hacking, analysis and unpacking
EXELOCK 666 Utility for protecting .EXE files so no lamers can hack out the copyright
Fire-Pack
FSE Final Fantasy Security Envelope freeware for protecting COM and EXE progams
Gardian Angel COM and EXE encrypter and protector using a variety of anti-debugging tricks
JMCryptExe DOS EXE encrypter
LGLZ DOS EXE and COM file compressor using modified LZ77
LzExe MS-DOS executable file compressor
Mask Tool that prevents COM program from being cracked by using encryption and anti-debugging tricks
Megalite MS-DOS executable file compressor
Mess This tool does the same as HackStop, with the exception that it is freeware for non-commercial use
Morphine 289 about 8 years ago Application for PE files encryption
Neolite Compresses Windows 32-bit EXE files and DLLs
PACK Executable files compressor
Pack-Ice
PCShrink Windows 9x/NT executable file compressor relying on the aPLib compression library
PE Diminisher Simple PE packer relying on the aPLib compression library
PE-Protector Encrypter/protector for Windows 9x/ME to protect executable files PEagainst reverse engineering or cracking with a very strong protection
PEBundle Physically attaches DLL(s) to an executable, resolving dependencies in memory
PEPack PE compression tool based on the code of a newer version of PE-SHiELD
PKlite Easy-to-use file compression program for compressing DOS and Windows executable files
Pro-Pack DOS executable file compressor
RERP ROSE's EXE Relocation Packer
RJCrush EXE and COM files compressor with the ability to compress overlays
Scorpion EXE and COM file encrypter and protector
SecuPack Win32 executable compressor
Shrinker Compresses (up to 70%) 16 and 32 bit Windows and real mode DOS programs
SPack
$PIRIT COM/EXE executable files polymorphic encryptor
SysPack Device drivers compressor
T-Pack Executable COM-FILE compressor (LZ77) optimized for small files like BBS-Addys or similar files
TinyProg EXE and COM programs compressor
TRAP EXE and COM files encrypter and protector
Vacuum Runtime Compressor for DOS32 executables
VGCrypt PE crypter for Win95/98/NT
WinLite Compresses Windows executables (such as Pklite, Diet or Wwpack) for executables programs under DOS
WWPack Squeezes EXE files, compresses relocation tables, optimizes headers, protects EXE files from hacking
XE PE32 image file packer and rebuilder
XorCopy COM file XOR-based encrypter
XORER COM file XOR-based encrypter
XPA DOS executable packer
XPack EXE/COM/SYS executable file compressor

Awesome Executable Packing / Tools

Android Unpacker 1,123 almost 5 years ago Android Unpacker presented at Defcon 22: Android Hacker Protection Level 0
Angr 7,592 9 days ago Platform-agnostic binary analysis framework
APKiD 2,070 7 days ago Android application Identifier for packers, protectors, obfuscators and oddities - PEiD for Android
aPLib Compression library based on the algorithm used in aPACK
AppSpear 42 almost 7 years ago Universal and automated unpacking system suitable for both Dalvik and ART
Assiste (Packer) Assiste.com's example list of packers
AVClass 464 about 1 month ago Python tools to tag / label malware samples
Bintropy 42 10 months ago Prototype analysis tool that estimates the likelihood that a binary file contains compressed or encrypted bytes
BinUnpack Unpacking approach free from tedious memory access monitoring, therefore introducing very small runtime overhead
Binutils The GNU Binutils are a collection of binary tools for Linux (it namely includes Readelf)
BitBlaze Analysis platform that features a novel fusion of static and dynamic analysis techniques, mixed concrete and symbolic execution, and whole-system emulation and binary instrumentation, all to facilitate state-of-the art research on real security problems
Capa 4,873 6 days ago Open-source tool to identify capabilities in PE, ELF or .NET executable files
Capstone Lightweight multi-platform, multi-architecture disassembly framework
CFF Explorer PE32/64 and .NET editor, part of the Explorer Suite
ChkEXE Identifies almost any EXE/COM packer, crypter or protector
Clamscan Unpacker Unpacker derived from ClamAV
COM2EXE Free tool for converting COM files to EXE format
de4dot 6,972 about 4 years ago .NET deobfuscator and unpacker
de4js 1,347 about 3 years ago JavaScript Deobfuscator and Unpacker
Defacto2 Analyzers Archive Collection of 60 binary files analysers for MS-DOS and Windows32 from the 1990s and the 2000s
Defacto2 Packers Archive Collection of 460 binary and data file packers for MS-DOS and Windows32 from the 1990s and 2000s
Defacto2 Unpackers Archive Collection of 152 binary files unpackers for MS-DOS and Windows 32 from the 1990s and 2000s
DIE 2,382 4 days ago Detect It Easy ; Program for determining types of files
DSFF 2 3 months ago DataSet File Format for exchanging datasets and converting to ARFF (for use with Weka), CSV or Packing-Box's dataset structure
DynamoRIO Runtime code manipulation system that supports code transformations on any part of a program, while it executes
Emulator Symantec Endpoint Protector (from v14) capability to create a virtual machine on the fly to identify, detonate, and eliminate malware hiding inside custom malware packers
EtherUnpack Precision universal automated unpacker (successor of PolyUnpack)
Eureka Binary static analysis preparation framework implementing a novel binary unpacking strategy based on statistical bigram analysis and coarse-grained execution tracing
EXEInfo-PE 758 30 days ago Fast detector for executable PE files
ExeScan Executable file analyzer which detects the most famous EXE/COM Protectors, Packers, Converters and compilers
EXETools Forum for reverse engineering and executale packing related topics
FUU 46 over 11 years ago Fast Universal Unpacker
GetTyp File format detection program for DOS based on special strings and byte code
GUnpacker Shell tool that performs OEP positioning and dumps decrypted code
Gym-Malware 612 almost 2 years ago This is a malware manipulation environment for OpenAI's gym
IDR 968 over 1 year ago Interactive Delphi Reconstructor
ImpREC This can be used to repair the import table for packed programs
Justin Just-In-Time AV scanning ; generic unpacking solution
Language 2000 Ultimate compiler detection utility
LIEF 4,499 4 days ago Library to Instrument Executable Formats ; Python package for parsing PE, ELF, Mach-O and DEX formats, modifying and rebuilding executables
LordPE PE header viewer, editor and rebuilder
Malheur 368 over 5 years ago Tool for the automatic analysis of malware behavior (recorded from malicious software in a sandbox environment)
MalUnpack 657 9 months ago Dynamic unpacker based on PE-sieve
Manalyze 1,018 11 months ago Robust parser for PE files with a flexible plugin architecture which allows users to statically analyze files in-depth
MRC (Mandiant Red Curtain) Free software for Incident Responders that assists with the analysis of malware ; it examines executable files (e.g., .exe, .dll, and so on) to determine how suspicious they are based on a set of criteria
.NET Deobfuscator 1,256 almost 2 years ago List of .NET Deobfuscators and Unpackers
Oedipus 11 over 8 years ago A Python framework that uses machine learning algorithms to implement the metadata recovery attack against obfuscated programs
OEPdet Automated original-entry-point detector
OllyDbg Scripts 9 over 6 years ago Collection of OllyDbg scripts for unpacking many different packers
OmniUnpack New technique for fast, generic, and safe unpacking of malware by monitoring the execution in real-time and detecting the removed layers of packing
PackerAttacker 268 over 6 years ago Tool that uses memory and code hooks to detect packers
PackerBreaker Tool for helping unpack, decompress and decrypt most of the programs packed, compressed or encrypted using advanced emulation technology
PackerGrind 34 over 2 years ago Adaptive unpacking tool for tracking packing bahaviors and unpacking Android packed apps
PackerID 42 over 4 years ago Fork of packerid.py using PEid signatures and featuring additional output types, formats, digital signature extraction, and disassembly support
PackID 9 over 8 years ago Packer identification multiplatform tool/library using the same database syntax as PEiD
Packing-Box 49 5 days ago Docker image gathering many packing-related tools and for making datasets of packed executables for use with machine learning
PANDA 2,489 17 days ago Platform for Architecture-Neutral Dynamic Analysis
Pandora's Bochs Extension to the Bochs PC eumlator to enable it to monitor execution of the unpacking stubs for extracting the original code
PCjs PCjs uses JavaScript to recreate the IBM PC experience, using original ROMs, CPUs running at their original speeds, and early IBM video cards and monitors
PE Compression Test List of packers tested on a few sample executables for comparing compressed sizes
PE Detective This GUI tool can scan single PE files or entire directories (also recursevely) and generate complete reports
PE-bear 767 over 1 year ago Freeware reversing tool for PE files aimed to deliver fast and flexible “first view” for malware analysts, stable and capable to handle malformed PE files
PEdump Dump windows PE files using Ruby
Pefeats 2 almost 4 years ago Utility for extracting 119 features from a PE file for use with machine learning algorithms
Pefile 1,880 3 months ago Multi-platform Python module to parse and work with Portable Executable files
PEFrame 610 over 2 years ago Tool for performing static analysis on PE malware and generic suspicious files
PEiD Packed Executable iDentifier
PEiD (CLI) 128 6 months ago Python implementation of PEiD featuring an additional tool for making new signatures
PEiD (yara) 17 almost 8 years ago Yet another implementation of PEiD with yara
PeLib 63 almost 5 years ago PE file manipulation library
PEPack 689 6 months ago PE file packer detection tool, part of the Unix package "pev"
PEscan CLI tool to scan PE files to identify how they were constructed
PETools 1,039 over 6 years ago Old-school reverse engineering tool (with a long history since 2002) for manipulating PE files
PEview Provides a quick and easy way to view the structure and content of 32-bit Portable Executable (PE) and Component Object File Format (COFF) files
PExplorer Most feature-packed program for inspecting the inner workings of your own software, and more importantly, third party Windows applications and libraries for which you do not have source code
Pin Dynamic binary instrumentation framework for the IA-32, x86-64 and MIC instruction-set architectures that enables the creation of dynamic program analysis tools
PINdemonium 227 over 8 years ago Unpacker for PE files exploiting the capabilities of PIN
PolyUnpack 12 over 12 years ago Implemention attempt of the general approach for extracting the original hidden code of PE files without any heuristic assumptions
PortEx 496 2 months ago Java library for static malware analysis of PE files with a focus on PE malformation robustness and anomaly detection
PROTECTiON iD PE file signature-based scanner
ProTools Programmer's Tools, a web site dedicated for all kinds of tools and utilities for the true WinBloze programmer, including packers, crypters, etc
PyPackerDetect 29 about 6 years ago Small python script/library to detect whether an executable is packed
PyPackerDetect (refactored) 21 10 months ago A complete refactoring of the original project to a Python package with a console script to detect whether an executable is packed
PyPeid 6 5 months ago Yet another implementation of PEiD with yara-python
Quick Unpack Generic unpacker that facilitates the unpacking process
RDG Packer Detector Packer detection tool
Reko 2,168 13 days ago Free decompiler for machine code binaries
REMINDer 2 10 months ago Packing detection tool based on the entropy value of the entry point section and the WRITE attribute
REMnux Linux toolkit for reverse-engineering and analyzing malicious software
Renovo Detection tool built on top of TEMU (dynamic analysis component of BitBlaze) based on the execution of newly-generated code and monitoring memory writes after the program starts
ResourceHacker Resource editor for 32bit and 64bit Windows applications
RetDec 8,025 about 2 months ago Retargetable machine-code decompiler based on LLVM
RTD Rose Patch - TinyProt/Rosetiny Unpacker
RUPP ROSE SWE UnPaCKER PaCKaGE (for DOS executables only)
SAFE Static Analyzer For Executables (available on demand)
SecML Malware 206 4 months ago Create adversarial attacks against machine learning Windows malware detectors
ShowStopper 196 over 2 years ago Tool to help malware researchers explore and test anti-debug techniques or verify debugger plugins or other solutions that clash with standard anti-debug methods
StudPE PE viewer and editor (32/64 bit)
SymPack Safe, portable, largely effective but not generic library for packing detection and unpacking ; part of the Norton Antivirus solution
Titanium Platform Machine learning hybrid cloud platform that harvests thousands of file types at scale, speeds threat detection through machine learning binary analysis, and continuously monitors an index of over 10B files for future threats
TrID Utility for identifying file types from their binary signatures
Triton 3,539 29 days ago Dynamic binary analysis library
Tuts 4 You Non-commercial, independent community dedicated to the sharing of knowledge and information on reverse code engineering
Unipacker 654 about 2 months ago Automatic and platform-independent unpacker for Windows binaries based on emulation
UnpacMe Automated malware unpacking service
Unpckarc Packed executables detection tool relying on several heuristics
UU Universal Unpacker
Uundo Universal Undo - Universal Unpacker
Uunp (IDA Pro plugin) IDA Pro debugger plug-in module automating the analysis and unpacking of packed binaries
UUP Universal exe-file UnPacker
VMHunt 174 almost 6 years ago Set of tools for analyzing virtualized binary code ; now only supports 32 bit traces
VMUnpacker Unpacker based on the technology of virtual machine
Winbindex 603 4 days ago An index of Windows binaries, including download links for executables such as EXE, DLL and SYS files
yarGen 1,555 6 months ago Generator for YARA rules - The main principle is the creation of yara rules from strings found in malware files while removing all strings that also appear in goodware files

Backlinks from these awesome lists:

More related projects: