A malware analyst performs static analysis on a suspicious executable and calculates its Shannon entropy at 7.9 out of a maximum of 8.0, with no readable strings and no recognizable import table. Which of the following BEST explains this finding?
- AThe file is likely packed or encrypted, a technique commonly used by malware to evade static signature detection
- BThe file uses only standard, unmodified Windows API calls
- CThe file is corrupted and will fail to execute on any system
- DThe file is a plain-text configuration script
Show answer & explanationAnswer & explanation
Correct answer: A. The file is likely packed or encrypted, a technique commonly used by malware to evade static signature detection
Entropy close to the theoretical maximum of 8.0 indicates data that appears random, which is characteristic of compressed or encrypted content. Malware authors commonly pack or encrypt executables to obscure strings and imports from static analysis tools and antivirus signatures; the payload is typically decrypted/unpacked only in memory at runtime.
Why the other options are wrong
- B. A visible, unmodified import table would produce lower entropy and recognizable structure, not near-maximum randomness.
- C. High entropy does not indicate corruption; packed files execute normally after runtime unpacking.
- D. Plain text has very low entropy (repetitive, predictable characters), the opposite of this finding.
Entropy Analysis (Packed Malware)
A static analysis technique measuring randomness in a file's byte distribution; entropy near 8.0 (max) suggests compression or encryption, often used to hide malicious code from static detection.
- Entropy scale: 0 (no randomness) to 8 (maximum randomness)
- Packed/encrypted malware typically shows entropy above ~7.0
- Missing strings/imports alongside high entropy strengthens the packed-malware hypothesis
Memory trick: Near-maximum entropy means the file is wearing a disguise.