Skip to content

Unpacking Techniques

Intermediate reverse engineers often encounter packed binaries—malware that has been compressed or encrypted to evade detection. Unpacking these binaries is critical to analyzing their true behavior, identifying hidden payloads, and understanding evasion techniques. Ghidra, with its advanced decompiler and memory analysis tools, provides a robust framework for this process. This section explores techniques to identify, unpack, and analyze packed binaries using Ghidra.


Understanding Packed Binaries

Packed binaries use algorithms like UPX, PECompact, or custom packers to obfuscate their contents. Packers often:
- Encrypt or compress the payload.
- Add a stub to decrypt/load the payload at runtime.
- Modify the binary structure to avoid signature-based detection.

Key indicators of packing in Ghidra:
- Unusual sections (e.g., .text with non-executable code).
- Presence of decryption routines (e.g., XOR, AES).
- Memory allocation patterns (e.g., VirtualAlloc or HeapAlloc calls).

Example:

# Use Ghidra's "File > Open" to load a suspected packed binary.  
# Navigate to "Decompiler > Decompile" to analyze suspicious functions.  


Ghidra-Based Unpacking Strategies

1. Packer Identification

Use Ghidra’s "Analyze All" feature to auto-detect packers. Look for:
- Functions that manipulate memory (e.g., VirtualProtect, CreateProcess).
- Strings like "UPX" or "PECompact" in the binary.

Example:

# Search for packer-related strings in the binary:  
# Right-click a string > "Search for All Occurrences"  

2. Dynamic Analysis with Ghidra

Run the binary in a sandboxed environment and use Ghidra to:
- Monitor memory allocations (e.g., HeapAlloc calls).
- Capture the decrypted payload in memory.

Example:

# Use Ghidra's "Memory > Memory Map" to track allocated regions.  
# Set breakpoints on decryption routines to capture the payload.  

3. Manual Unpacking

If the packer is custom, manually reverse the unpacking logic:
- Identify the decryption routine (e.g., XOR key).
- Use Ghidra’s "Edit > Set Value" to modify the binary and bypass obfuscation.

Example:

# Modify a XOR key in the binary:  
# Right-click a value > "Edit Value" > Change to the correct key.  


Analyzing Hidden Payloads

Once unpacked, use Ghidra to:
- Decompile the payload to understand its logic.
- Identify API calls (e.g., LoadLibrary, CreateFile) for behavior analysis.
- Cross-reference with memory dumps to confirm the unpacked state.

Example:

# Decompile the payload:  
# Right-click a function > "Decompile" > Analyze API calls.  


Key takeaways

  • Packed binaries require dynamic and static analysis to uncover hidden payloads.
  • Ghidra’s decompiler and memory tools are essential for identifying packers and decrypting content.
  • Manual unpacking often involves modifying decryption routines or bypassing obfuscation.
  • Always validate findings with memory dumps and behavioral monitoring.
  • Understanding packing techniques helps Blue Teams detect and respond to evasion tactics in real-world scenarios.