Malware Theory - How Packers Work, Polymorphism and Misconceptions

Опубликовано: 24 Март 2026
на канале: MalwareAnalysisForHedgehogs
9,191
365

How do packers work? What is binary padding and why is not the same as polymorphism. What is polymorphism in packers? Why is a scantime crypter not a packer?
I answer those questions.

Malware analysis courses: https://malwareanalysis-for-hedgehogs...
Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter:   / struppigel  

00:00 Intro
01:01 Why learn about packers?
01:36 Packer types
02:30 How packing works
03:50 Misconception: Packers inject stub into target
05:03 How packed files execute target file
06:11 Legit and malicious packers?
07:00 Misconception: Scantime crypter are packers
08:02 Target file placement in the stub
09:12 Binary Padding and why it is no polymorphism
10:03 Polymorphic packers
10:49 Oligomorphic packers
11:47 How polymorphism helps malware evade AVs
13:36 Metamorphism does not apply to packers

Revealing Packed Malware: https://ieeexplore.ieee.org/document/...

#malware #malwareanalysis #reverseengineering #unpacking #packers