Binary Signature Scanner
Scan binary data for 120+ packer, protector, and obfuscator signatures. Detect UPX, ASPack, Armadillo, MPRESS, FSG, VMProtect, Themida, Enigma, ConfuserEx, Dotfuscator, Obsidium, and many more. YARA-style byte pattern matching with severity ratings, offset reporting, and detailed descriptions. Free, private, and no signup required.
Binary Signature Scanner
Scan binary data for 120+ packer, protector, and obfuscator signatures. Detect UPX, ASPack, Themida, VMProtect, Enigma, ConfuserEx, and more.
Paste hex data or upload a file
The scanner will check for 120+ packer and protector signatures.
Powerful Binary Signature Detection
Detect over 100 executable packers, cryptors, and protectors using our comprehensive binary signature database. Ideal for malware analysis, software forensics, and reverse engineering.
100+ Packer Signatures
Comprehensive signature database covering all major packers, protectors, cryptors, and obfuscators — from classic UPX, ASPack, and Armadillo to modern VMProtect, Themida, and Enigma.
YARA-Style Pattern Matching
Byte-level scanning engine matches hex signature patterns against your binary data with offset reporting. Supports wildcard nibbles (?), length-agnostic matching, and multi-signature patterns.
Severity & Risk Assessment
Every signature comes with a severity rating (Info, Low, Medium, High, Critical) and a detailed description. Quickly prioritize which packers and protectors are most significant in your analysis.
100% Private Browser-Based
All scanning and signature matching runs entirely in your browser. Your binary data, uploaded files, and scan results never leave your device. No signup, no tracking, no limits.
Common Use Cases
The Binary Signature Scanner is used by security researchers, malware analysts, reverse engineers, and software developers worldwide.
Malware Analysis
Identify which packer or protector was used to obfuscate a malware sample. Knowing the packer (UPX, ASPack, VMProtect) determines the unpacking strategy and tooling needed.
Executable Forensics
Scan unknown binary files to determine if they have been packed or protected. Detect multi-layer protection where multiple packers are applied to the same executable.
Software Protection Audit
Verify that your own software protection (Themida, Enigma, Obsidium) is correctly applied by scanning your protected executables and confirming the expected signatures are present.
Reverse Engineering Prep
Before diving into a packed binary, scan it to know what you are dealing with. Different packers require different unpackers and approaches — know your target first.
Incident Response
During a security incident, quickly scan suspicious executables to identify known packers and protectors. Accelerate triage by categorizing files based on their protection method.
Academic Research
Study packer evolution by scanning historical and modern binaries. Track which packers are most prevalent in malware samples or legitimate software over time.
About Binary Signature Scanning
Understand how the Binary Signature Scanner works, what signatures it detects, and how to interpret results for effective binary analysis.
What Are Packer Signatures?
Packer signatures are unique byte sequences (magic bytes or characteristic patterns) found in the headers or code sections of executables that have been processed by a packer or protector. Each packer — from UPX to VMProtect — leaves distinctive fingerprints in the file it processes. The Binary Signature Scanner maintains a database of these fingerprints and matches them against your uploaded binary data.
How Signature Matching Works
The scanner converts your input (hex string or uploaded file) into a raw byte array. Each signature rule defines a hex pattern to match, with optional wildcard nibbles for variable bytes. The engine searches for each pattern at every offset in the input data. When a match is found, it reports the offset, the matched bytes, the signature name, severity level, and a detailed description of what the packer does.
Severity Ratings Explained
Signatures are rated on a 5-level scale: Info (standard compression packers like UPX), Low (common protectors with basic anti-debugging), Medium (packers with obfuscation and anti-analysis), High (advanced protectors with virtualization and strong anti-debug), and Critical (malicious-specific packers or those with severe anti-analysis). Use the severity filter to focus on the most significant detections.
Limitations & Best Practices
Signature-based detection has limitations: packers can be modified to evade signatures, custom packers may have no known signatures, and polymorphic packers change their signatures with each use. The scanner detects known, documented packers — it does not detect custom obfuscation. For best results, combine signature scanning with entropy analysis and behavioral analysis for a complete picture.
Frequently Asked Questions
Everything you need to know about binary signature scanning and packer detection.
A binary packer is a tool that compresses or encrypts an executable file and wraps it with a small decompression stub that restores the original code in memory at runtime. A protector adds layers of anti-debugging, anti-tampering, and obfuscation on top of packing. Common packers include UPX, ASPack, and MPRESS, while protectors include VMProtect, Themida, and Enigma.
The scanner includes over 120 signatures covering a wide range of packers, cryptors, protectors, and obfuscation tools. This includes everything from classic packers like UPX and PKLite to modern virtualization-based protectors like VMProtect and Themida, and packer frameworks like ConfuserEx and Dotfuscator for .NET executables.
You can paste hex-encoded binary data (with or without spaces), upload a file (which is read and converted to hex automatically), or use the example presets. The tool accepts any binary file format — PE executables (.exe, .dll), ELF binaries, .NET assemblies, and raw binary dumps.
Info — standard compression packers (UPX, MPRESS). Low — common protectors with minimal anti-analysis. Medium — packers with obfuscation and anti-debugging. High — advanced protectors with virtualization. Critical — severe anti-analysis or malware-specific packers. Use the severity dropdown to filter results.
Yes. Every scan checks all 120+ signatures simultaneously. If a binary has been processed by multiple packers (multi-layer packing), the scanner will detect each layer independently. Results are displayed in a table sorted by match offset, showing the exact location in the file where each signature was found.
Signature matching is highly accurate for known, unmodified packers. However, packers can be customized by their users to modify signatures, and some packers offer polymorphic modes that alter their signatures with each use. False positives are possible when unrelated data coincidentally matches a short signature. Always verify results with additional analysis.
Absolutely. All scanning and signature matching runs entirely in your browser using JavaScript. Your binary data, uploaded files, and scan results are never sent to any server, stored, or tracked. The signature database is bundled with the tool and processed locally on your device.
Yes. The Binary Signature Scanner is excellent for CTF (Capture The Flag) reverse engineering challenges where you need to quickly identify what packer or protector was used on a binary. The severity ratings and detailed descriptions help you understand what you are dealing with and which unpacking approach to use.
Yes — 100% free with no signup, no account, and no usage limits. Scan as many files as you need, as many times as you want. All features including file upload, severity filtering, search, and export are available without any restrictions or premium tiers.