53

StuffIt file signature

Magic number at the start of the file · SIT!.

53 49 54 21 00

Classic StuffIt archives from the Mac OS 8/9 era begin with the ASCII bytes SIT! followed by a NUL. The later StuffIt X (.sitx) format replaced this with its own header beginning StuffIt, so the two generations are easy to tell apart.

Hex signature
53 49 54 21 00
Offset
0 (start of file)
ASCII
SIT!.
Length
5 bytes

What this magic number means

A magic number is a short, fixed run of bytes at a known position that tells a program what a file really is, no matter what the filename says. If a file starts with the bytes 53 49 54 21 00 (the text SIT!.), it is a StuffIt file.

Because SIT is a Mac-era format, the files usually turn up in old backups. The Unarchiver on macOS still opens them, and on Windows the free StuffIt Expander is the usual route.

What each byte of 53 49 54 21 means

Here is the signature byte by byte, the way a hex editor shows it: the position in the file, the value in hex and in decimal, and the character that value stands for in ASCII. Bytes with no printable character show a dot.

Byte offsetHexDecimalASCII
05383S
14973I
25484T
32133!
4000.

Signature variants

StuffIt appears with more than one byte pattern. These all identify the same family:

Hex signatureOffsetNote
53 49 54 21 000classic StuffIt (.sit), SIT! then a null byte
53 74 75 66 66 49 740StuffIt X (.sitx), ASCII StuffIt

Formats that use the 53 49 54 21 signature

These file types in our database carry this signature:

How to check a file's signature

You can read the bytes of any file yourself. They are shown in hex, the same way this page lists them.

Linux & macOS

  • xxd -l 16 example.sit
  • hexdump -C -n 16 example.sit
  • file example.sit

Windows (PowerShell)

  • Format-Hex -Path example.sit -Count 16

Python

  • open("example.sit","rb").read(5).hex()

In your browser

Frequently asked questions

What is the StuffIt file signature?

StuffIt files start with the hex bytes 53 49 54 21 00 (SIT!. in ASCII). This magic number identifies the format regardless of the file's name or extension.

How do I check a file's magic number?

Open the file in a hex editor, or run a command such as xxd -l 16 example.sit on Linux or macOS, or Format-Hex -Path example.sit -Count 16 in Windows PowerShell, and read the first bytes.

Can a file fake the StuffIt signature?

Renaming a file does not change its bytes, so the extension can lie but the signature usually cannot. A genuine StuffIt file has these exact bytes; a file with the wrong bytes is not really StuffIt, whatever its name says.

Related signatures

Sources

Reuse this signature

This entry is part of the WhatFileType file signature reference, published under a CC BY 4.0 licence with the full provenance for every entry, a copy-paste embed and a JSON export. Credit WhatFileType and the data is yours to republish.