Q about packer signatures
I'm trying to understand the packer signatures I've seen on some of the malware samples on this site. For example, one of them had:
NeoLite v2.00 [418,1673] FSG v2.0 -> bart/xt [652,2609] Microsoft Visual C++ v7.1 EXE [164,657] PE Pack v1.0 [450,1801] Ste@lth PE 1.01 -> BGCorp [757,3036]
I assume the executable was packed multiple times using the packers listed -- is that correct? If so, does the top-to-bottom ordering on this list correspond to going from the outermost-packer to the innermost-packer, or vice versa? Finally, what do the numbers "[418,1673]", "[652,2609]", etc., mean?