Courseiva

CHFI Mobile and Malware Forensics Practice Question

During static analysis of a PE file, an analyst uses PEiD and detects the signature 'UPX 0.89.6 - 1.02 / 1.05 - 1.24'. What should the analyst do next?

⚠ Common exam trap

The CHFI exam often tests the misconception that a packer signature automatically indicates malware, when in fact packing is a legitimate software distribution technique and the analyst must unpack the file to determine its true nature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unpack the file using a UPX unpacker or manual unpacking

The signature 'UPX 0.89.6 - 1.02 / 1.05 - 1.24' indicates the file is packed with UPX (Ultimate Packer for eXecutables). Packing is a common technique used by malware authors to obfuscate the original code and evade signature-based detection. The analyst must unpack the file using a UPX unpacker or manual unpacking to reveal the actual executable code for further static or dynamic analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The file is clean; no further analysis needed

    Why it's wrong here

    PEiD's UPX signature is a packer indicator, not a verdict of cleanliness. UPX compresses the executable's original code and imports, so the static analysis performed on the packed file only sees the unpacking stub, not the actual logic. Legitimate and malicious binaries alike are packed with UPX, and a clean verdict would require unpacking and inspecting the decompressed code.

  • ✓

    Unpack the file using a UPX unpacker or manual unpacking

    Why this is correct

    Because UPX modifies the PE structure and replaces the original entry point with an unpacking stub, the file must first be unpacked to recover the original code for static analysis. If the sample retains a standard UPX header, running `upx -d` can restore it; otherwise, manual unpacking (e.g., OEP tracing via the pushad/popad pair, memory dump, and import reconstruction with Scylla or ImportREC) is required. Only then can strings, imports, and code logic be truly analyzed.

  • ✗

    Delete the file as it is definitely malware

    Why it's wrong here

    UPX is a legitimate open-source packer used by many non-malicious programs, so PEiD's signature match alone cannot establish malicious intent. Deleting the binary destroys potential forensic evidence and is an unsafe response, as the sample may be a harmless packed application. The correct action is to preserve the artifact and unpack it to examine the underlying code.

  • ✗

    Run the file in a sandbox immediately

    Why it's wrong here

    Immediately running the packed file in a sandbox will execute the unpacking stub and then the original code, so dynamic behavior can be observed, but it bypasses static analysis of the recovered code and may miss packer-specific indicators or artifacts. For a methodical analysis, the sample should be unpacked first so that both static inspection and dynamic monitoring can be performed against the true entry point. Additionally, automated sandboxes frequently complete before manual unpacking is attempted, which limits deeper reverse engineering.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.