BobSoft Mini Delphi Packer

The Delphi programming language can be an easy way to write applications and programs that leverage Windows API functions. In fact, some actors deliberately include the default libraries as a diversion to hamper static analysis and make the application "look legit" during dynamic analysis.

The packer goes to great lengths to ensure that it is not running in an analysis environment. Normal user activity involves many application windows being rotated or changed over a period of time. The first variant of the packer uses GetForegroundWindow API to check for the user activity of changing windows at least three times before it executes further. If it does not see the change of windows, it puts itself into an infinite sleep.


Technique Identifier

U1428

Technique Tags

delphi packer

Evasion Categories

Detection Rules

Contributor

Additional Resources

External Links
The resources provided below are associated links that will give you even more detailed information and research on current evasion technique. It is important to note that, while these resources may be helpful, it is important to exercise caution when following external links. As always, be careful when clicking on links from unknown sources, as they may lead to malicious content.

Matching Samples 10 most recent

Sample Name Matching Techniques First Seen Last Seen
Torture.exe 9 2025-12-16 3 months, 4 weeks ago
efak.exe 6 2025-12-13 4 months ago
3KTrangXinhTQ.exe 2 2025-12-01 4 months, 2 weeks ago
TORKpro300.exe 3 2025-07-08 9 months, 1 week ago
TuAnhPro.exe 2 2025-07-04 9 months, 1 week ago
mel.exe.exe 4 2025-06-25 9 months, 3 weeks ago
DP_Simple_Player.exe 5 2025-05-13 11 months ago
23b1971659b16e186f9e1b36d8bc...e512b346e78f77dc314503aac59a 13 2024-11-19 1 year, 4 months ago
View All

Created

June 21, 2022

Last Revised

March 24, 2026