Related Experiment Video
Updated: May 11, 2026

Substructure Analyzer: A User-Friendly Workflow for Rapid Exploration and Accurate Analysis of Cellular Bodies in Fluorescence Microscopy Images
Published on: July 15, 2020
UnSafengine64: A Safengine Unpacker for 64-Bit Windows Environments and Detailed Analysis Results on Safengine 2.4.0
Seokwoo Choi1, Taejoo Chang1, Yongsu Park2
1The Affiliated Institute of ETRI, P.O. Box 1, Yuseong, Daejeon 305-600, Republic of Korea.
This study introduces UnSafengine64, a tool to unpack malware protected by Safengine, a complex commercial packer. It enables detailed analysis of 64-bit Windows executables, overcoming anti-reversing techniques.
Area of Science:
- Computer Science
- Cybersecurity
- Software Engineering
Background:
- Malware developers employ sophisticated anti-reversing techniques, such as code encryption and virtualization, to hinder binary code analysis.
- Commercial packers like Safengine are widely used to protect malware, presenting significant challenges for security researchers.
- Existing analysis tools struggle with complex packers, necessitating advanced solutions for effective malware investigation.
Purpose of the Study:
- To develop and present UnSafengine64, a novel unpacker specifically designed for Safengine-packed 64-bit Windows executables.
- To enable detailed analysis of malware protected by one of the most complex commercial packers.
- To provide a method for overcoming advanced anti-reversing techniques used in malware.
Main Methods:
- Developed UnSafengine64 as a plug-in for the dynamic analysis tool Pin (Process Instrumentation Framework).
- Utilized auxiliary tools including Detect It Easy (DIE), IDA Pro, x64Dbg, and x64Unpack for comprehensive analysis.
- Implemented functionalities for detecting anti-debugging code, capturing memory dumps, and unpacking files.
Main Results:
- UnSafengine64 successfully unpacks executables protected by Safengine 2.4.0, producing clean, analyzable versions.
- The tool facilitates the analysis of obfuscated Application Programming Interface (API) calls and enables fine-grained instruction-level analysis.
- Demonstrated the ability to detect anti-debugging code and capture memory dumps of packed processes.
Conclusions:
- UnSafengine64 is an effective tool for unpacking Safengine-protected malware, significantly aiding in binary code analysis.
- The developed unpacker overcomes complex anti-reversing techniques, offering new possibilities for malware research.
- Published analysis results provide valuable insights into Safengine's obfuscation methods and packed executable structures.
More Related Videos
11:50A Standardized Pipeline for Examining Human Cerebellar Grey Matter Morphometry using Structural Magnetic Resonance Imaging
Published on: February 4, 2022
04:58Author Spotlight: Investigating the Role of Repetitive DNA Misregulation in Cancer Initiation and Immunotherapy Resistance
Published on: December 13, 2024