Courseiva

CHFI Mobile and Malware Forensics Practice Question

An analyst suspects a Windows executable is packed. They run `strings` on the file and see few readable strings, and PEiD reports 'UPX 0.89.6 - 1.02 / 1.05 - 1.24'. Which static analysis technique should the analyst use NEXT to extract the original code?

⚠ Common exam trap

The CHFI exam often tests the distinction between detection (YARA), dynamic analysis (sandbox), and direct disassembly (IDA) versus the correct unpacking step, trapping candidates who think any analysis tool can handle packed files without prior decompression.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use UPX with the -d flag to decompress the executable

UPX (Ultimate Packer for Executables) is a common packer that compresses Windows executables. The PEiD output 'UPX 0.89.6 - 1.02 / 1.05 - 1.24' confirms the file is packed with UPX. Running `upx -d` (decompress) reverses the packing, restoring the original executable code for static analysis. This is the standard next step before attempting disassembly or dynamic analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use UPX with the -d flag to decompress the executable

    Why this is correct

    UPX is a widely used open-source packer that stores a compressed executable and a self-extracting stub. Running `upx -d file.exe` invokes UPX's decompression routine, which reconstructs the original Portable Executable (PE) sections, restores the original entry point, and simplifies subsequent static analysis. This is the intended static analysis answer because it directly reverses the packing transformation, unlike dynamic execution. If the file were packed with a different tool, `upx -d` would fail with a validation error, but the question specifically indicates UPX.

  • ✗

    Search for known YARA rules matching UPX

    Why it's wrong here

    YARA rules are pattern-matching signatures used to classify files based on binary content, metadata, or behavioral indicators; they can detect that a binary was packed with UPX by matching known UPX section names or byte patterns. However, detection is not extraction—YARA rules produce a flag or alert, not the decompressed code. The original code remains wrapped in the UPX container until a decompressor such as `upx -d` is invoked, so YARA alone is insufficient for static analysis of the underlying logic.

  • ✗

    Run the executable in Cuckoo Sandbox to obtain dynamic analysis

    Why it's wrong here

    Cuckoo Sandbox is an automated dynamic analysis tool that executes the sample in an isolated guest environment and records system calls, network traffic, file modifications, and memory dumps. While this may reveal runtime behavior and even capture a memory-resident unpacked image, it answers the question from a dynamic perspective, not the static approach asked about. Moreover, dynamic analysis requires the executable to actually run, which raises evasion and anti-sandbox risks; unpacking with `upx -d` is a static and deterministic recovery of the original code.

  • ✗

    Load the file into IDA Pro and attempt to disassemble directly

    Why it's wrong here

    Loading a packed executable directly into IDA Pro typically produces disassembly of the UPX decompression stub and the sparse, compressed data sections, not the original program flow. The actual code is not yet in its executed form, so the disassembly will be dominated by the tiny stub that reads compressed bytes—not the program's logic. Professional reverse engineers either run `upx -d` first to reconstruct the image or manually trace the stub and dump the unpacked memory, then rebuild the import table before a meaningful IDA session can begin.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.