Packer Detection: PE File Analyzer
Analyze PE files to detect 50+ packers, protectors, cryptors, and obfuscators. Upload any .exe or .dll file (or paste hex data) for instant analysis including full PE header parsing, section table examination, entropy scoring, and severity-rated packer identification. All processing is local and private.
Upload a PE file (.exe, .dll) or paste hex data to begin analysis.
The Packer Detection: PE File Analyzer scans headers, sections, and entropy to identify 50+ packers, protectors, and obfuscators.
Why Use Our PE Packer Detector?
50+ Packer Signature Database
Comprehensive detection rules covering all major packers, protectors, cryptors, and obfuscators — from UPX, ASPack, and Armadillo to Themida, VMProtect, Enigma, and MPRESS. Signatures are matched against PE headers, section names, entry point patterns, and structural characteristics.
Deep PE Structure Analysis
Full PE file parsing: DOS header, PE signature, COFF header, optional header (PE32/PE32+), and complete section table with name, virtual size, raw size, virtual address, and characteristics flags. Every structural detail is extracted and analyzed for packer indicators.
Entropy-Based & Heuristic Detection
Beyond signature matching, the analyzer computes Shannon entropy per section and applies heuristic rules: RWX sections (read+write+execute), suspiciously few sections, and abnormally high entropy regions — all strong indicators of packing that supplement signature-based detection.
100% Private Browser-Based Analysis
All PE parsing, signature matching, entropy calculation, and heuristic analysis runs entirely in your browser. Your files and data never leave your device. No upload, no server processing, no signup required. Export analysis reports as plain text for your records.
Common Use Cases for the PE Packer Detector
Malware Analysis & Triage
Identify which packer or protector was used to obfuscate a malware sample. Knowing the packer (UPX, ASPack, VMProtect, Themida) determines the unpacking strategy, tooling, and analysis approach needed for reverse engineering.
Executable Forensics
Scan unknown binary files to determine if they have been packed, protected, or obfuscated. The PE File Analyzer reveals multi-layer protection schemes and suspicious structural characteristics that warrant further investigation.
Software Protection Verification
Verify that your own software protection (Enigma, Themida, VMProtect) is correctly applied by scanning protected executables. Confirm expected signatures are present and protection layers are properly configured.
Reverse Engineering Preparation
Before analyzing a packed binary, scan it to know what you are dealing with. Different packers require different unpackers and approaches — the PE File Analyzer provides the critical first step in any reverse engineering workflow.
Incident Response & Threat Hunting
During security incidents, quickly scan suspicious executables to identify known packers and protectors. Accelerate triage by categorizing files based on their protection method and severity level.
Academic & CTF Research
Study packer evolution by scanning historical and modern binaries. Essential for Capture The Flag (CTF) reverse engineering challenges where identifying the packer is the first step toward solving the challenge.
Understanding PE Packer Detection
What is a PE Packer or Protector?
A PE packer is a tool that compresses or encrypts a Portable Executable (PE) file — the standard executable format on Windows (.exe, .dll, .sys) — and wraps it with a small decompression stub that restores the original code in memory at runtime. A protector adds layers of anti-debugging, anti-tampering, anti-dumping, and code obfuscation on top of packing. Common packers include UPX, ASPack, and MPRESS, while advanced protectors include VMProtect, Themida, Enigma, and Obsidium.
How the PE File Analyzer Works
- Upload or paste your PE file — The tool accepts .exe, .dll, .sys, .ocx, .scr, and .cpl files, or hex-encoded PE data pasted directly into the text area.
- Full PE structure parsing: The analyzer reads the DOS header, locates the PE signature at offset 0x3C, parses the COFF file header (machine type, number of sections, timestamp), and processes the optional header (PE32 or PE32+ magic, entry point, image base, subsystem). Every section in the section table is extracted with its name, virtual size/address, raw size/offset, and characteristics flags.
- Multi-layered detection: The engine applies three complementary detection approaches simultaneously: (1) signature-based detection matching section names and patterns against 50+ known packer profiles, (2) entropy analysis computing Shannon entropy per section to identify encrypted or compressed regions, and (3) heuristic analysis flagging structural anomalies like RWX sections, suspiciously few sections, or unusual entry point patterns.
Detection Methods Explained
- Signature-Based Detection: The core detection engine matches section names (UPX0, .vmp0, MPRESS1, .themida), DOS stub patterns, and structural characteristics against a database of 50+ known packer, protector, cryptor, and obfuscator profiles. Each signature includes a severity rating (Info through Critical), category classification, and detailed description.
- Entropy Analysis: Shannon entropy measures the randomness of data in each section. Normal executable code typically scores 4.0-6.0 bits/byte. Encrypted or compressed packer sections score 6.5-8.0 bits/byte. The analyzer computes entropy for every section and flags sections with abnormally high scores — a strong indicator of packing or encryption.
- Heuristic Indicators: Structural anomalies that suggest packing even without a signature match: RWX sections (writable executable code — a rarity in normal executables), sections with suspicious characteristics, an unusually low section count (packed files often compress many sections into 1-3), and entry points located in unexpected sections.
Privacy, Limitations & Best Practices
The PE Packer Detector processes all files and data entirely in your browser using JavaScript. No data is ever uploaded to any server, stored in any database, or shared with any third party. However, signature-based detection has inherent limitations: packers can be customized to evade signatures, custom/proprietary packers have no known signatures, and polymorphic packers change their signatures with each use. For best results, combine the PE Packer Detector with entropy analysis, behavioral analysis, and manual reverse engineering for a complete picture of any suspicious executable.
Frequently Asked Questions About PE Packer Detection
A PE (Portable Executable) packer is a tool that compresses or encrypts an executable file (.exe, .dll) and wraps it with a small decompression stub. When the packed executable runs, the stub decompresses or decrypts the original code in memory and transfers execution to it. Packing reduces file size and, when combined with encryption, makes reverse engineering more difficult. Protectors go further by adding anti-debugging, anti-dumping, and code virtualization layers.
The analyzer includes over 50 detection rules covering a comprehensive range of packers, protectors, cryptors, and obfuscators. This includes compression packers (UPX, ASPack, MPRESS, PEtite, FSG), advanced protectors (Themida, VMProtect, Enigma, Armadillo, Obsidium), encryption packers (Morphine, RPCrypt, Krypton), .NET obfuscators (ConfuserEx, Dotfuscator, Obfuscar, SmartAssembly), and heuristic indicators (high entropy, RWX sections, low section count).
You can upload actual PE files (.exe, .dll, .sys, .ocx, .scr, .cpl) directly using the file upload button, or paste hex-encoded binary data into the text area. When uploading a file, the analyzer reads the raw bytes and processes them entirely in your browser. A built-in example PE file is also available to demonstrate the tool capabilities.
Info — standard compression packers with minimal anti-analysis features (UPX, MPRESS, PKLite). Low — packers and protectors with basic anti-debugging (ASPack, NSPack, WinUpack). Medium — protectors with obfuscation, anti-debugging, and anti-dumping (AsProtect, Telock, PEtite with protection). High — advanced protectors with code virtualization, strong anti-debugging, and polymorphic capabilities (Themida, VMProtect, Armadillo, Enigma, Obsidium). Critical — packers with severe anti-analysis or malware-specific protection techniques.
Yes. The analyzer checks all 50+ detection rules simultaneously. If a binary has been processed by multiple packers (multi-layer packing or protection), each layer will be detected independently. Results are sorted by relevance and severity, with each detection showing the specific evidence that triggered the match. Heuristic indicators (high entropy, RWX sections) are also shown alongside signature-based detections.
Signature-based detection is highly accurate for known, unmodified packers. However, packers can be customized by their users to modify section names and signatures (a practice called "scrambling"), and some packers offer polymorphic modes that alter their signatures with each use. The analyzer mitigates this by combining signature matching with entropy analysis and heuristic detection — even if a signature is modified, structural anomalies and high entropy provide strong secondary indicators of packing.
Shannon entropy measures the randomness or information density of data, expressed in bits per byte (0-8). Unpacked executable code typically scores 4.0-6.0 bits/byte, while packed, encrypted, or compressed sections score 6.5-8.0 bits/byte because encrypted data has near-uniform byte distribution. The PE File Analyzer computes entropy for every section and highlights sections with abnormally high entropy — this is one of the most reliable indicators of packing, even when signature-based detection fails.
Yes, absolutely. All PE parsing, signature matching, entropy calculation, and heuristic analysis runs entirely in your browser using JavaScript. Your uploaded files, pasted hex data, analysis results, and scan reports never leave your device. No data is sent to any server, stored in any database, or shared with any third party. There are no file size limits — the only constraint is your browser available memory.
While the Binary Signature Scanner (BSS) performs general YARA-style pattern matching across all binary data, the PE Packer Detector is specifically optimized for PE file analysis. It parses the full PE structure (headers, section table, optional header), computes section-level entropy, applies heuristic rules specific to PE files, and specializes in packer/protector/obfuscator identification. The PE Packer Detector provides richer, more actionable results for PE analysis while the BSS offers broader signature matching across any binary format.