Analyzing Malware: A Comparative Study of Static and Dynamic Methods through Reverse Engineering
Keywords:
Malware, Reverse Engineering, Static analysis, Dynamic AnalysisAbstract
Malware remains a critical and evolving threat to modern computing environments, necessitating advanced defensive strategies from cybersecurity professionals. This study explores malware analysis through both static and dynamic approaches within a Windows-based environment, emphasizing the role of reverse engineering. Static analysis involves inspecting malware binaries, structure, and metadata without execution. Tools such as IDA Pro and CFF Explorer allow analysts to uncover embedded exploits, operational logic, and potential payloads, offering deep structural insight into the malware’s functionality.In contrast, dynamic analysis focuses on observing malware behaviour in real time by executing it within an isolated virtual machine. This method, supported by tools like Process Monitor (ProcMon), enables analysts to track runtime activities, such as API calls, file system alterations, registry modifications, and network interactions. The integration of these tools provides a comprehensive view of malware behaviour, both at the static and operational levels.The paper also highlights the growing sophistication of malware, which increasingly employs obfuscation and evasion techniques. Thus, combining static and dynamic analyses— augmented by antivirus tools and SIEM platforms like Wazuh—enhances detection capabilities. The study concludes that a hybrid reverse engineering strategy significantly strengthens malware defence, offering actionable recommendations to reduce future threats within enterprise-level Windows environments. Keyword—Malware,Reverse Engineering, Static analysis, Dynamic Analysis
Downloads
References
Abdelwahed, et. al., (2023). Detecting Malware
Activities with MalpMiner: A Dynamic Analysis
Approach. IEEE Access, 4.
Almarri & Sant, (2014), Optimised Malware
Detection in Digital Forensics (International Journal
of Network Security & Its Applications (IJNSA)) Vol
6 No 1.
Alsharabi et. al., (2023). Analysis of ransomware
Using Reverse Engineering Techniques to Develop
Effective Countermeasures. Journal of Advances in
Information Technology, 14(2), 284–294.
Anastasios, (2023). Malware Analysis and Reverse
Engineering. In University of West Attica, University
of West Attica [Thesis; PDF].
Arif Islam & Mohan Kumar, (2023). Cyber Safety
Analysis Using Reverse Engineering. In
International Journal of Research Publication and
Reviews & Karpagam Academy of Higher
Education (KAHE), International Journal of
Research Publication and Reviews (Vol. 4, Issue 1,
pp. 399–403).
Aslan, (2017), "Investigation of Possibilities to
Detect Malware Using Existing Tools," IEEE/ACS
14th International Conference on Computer
Systems and Applications (AICCSA), Ham-mamet,
Tunisia, 2017, pp. 1277-1284, doi:
10.1109/AICCSA.2017.24. Ghidra: Documentation.
(2024, April 20). National Security Agency.
https://github.com/NationalSecurityAgency/ghidra
Aslan, (2017), Performance Comparison of Static
Malware Analysis Tools Versus Antivirus Scanners
to Detect Malware, International Multidisciplinary
Studies Congress (IMSC), Akdeniz University,
Antalya/Turkey on 25-26 November 2017.
Balci, (n.d.). Malware Reverse Engineering
Handbook. CCDCOE. Ching (2021). Enhancing
Usability of Malware Analysis Pipelines with
Reverse Engineering. In Master of Science in
Computer Science [Thesis]. Syracuse University.
Blázquez & Tapiador, (2023) "Kunai: A static
analysis framework for Android apps," SoftwareX,
vol. 22, p. 101370.
Chen, et. al., (2023). Efficient Windows malware
identification and classification scheme for plant
protection information systems. Frontiers in Plant
Science, 14.
Cletus. et. al., (2024) An Evaluation of Current
Malware Trends and Defense Techniques: A
Scoping Review with Empirical Case Studies. In
Journal of Advances in Information Technology
(Vol. 15, Issue 5, pp. 649–671).
Damodaran, et. al., (2022), A Comparison of Static,
Dynamic, and Hybrid Analysis.
Eilam, (2003). Reversing - Secrets of Reverse
Engineering. Indianapolis: Wiley Publishing, Inc
Ferdous, et. al., (2023), "A Review of State-of-theArt Malware Attack Trends and Defence
Mechanisms," in IEEE Access, vol. 11, pp. 121118-
121141 for Malware Detection," Journal of
Computer Virology and Hacking
Gulmez, et. al., (2024), "Analysis of the Zero-Day
Detection of Metamorphic Malware," 2024 9th
International Conference on Computer Science and
Engineering (UBMK), Antalya, Turkiye, 2024, pp. 1-
6.
Hex Rays: IDA Pro, (2024, April 20). Hex Rays.
Hinderaker, et. al., (2024), Exploring Destructive
Malware: A Practical Approach to Wiper Malware
“Developing wiper malware to identify weaknesses
and improve security in Windows systems”
M. Karresand, (2003), “Separating Trojan horses,
viruses, and worms – A proposed taxonomy of
software weapons,” in IEEE Systems, Man and
Cybernetics Society Information Assurance
Workshop, pp.127–134.
Manohar Venkat, et. al., (2023). Malware Reverse
Engineering to Find the Malicious Activity of Emotet.
In Advances in transdisciplinary engineering.
Megira, et. al., (2018), "Malware Analysis and
Detection Using Reverse Engineering Technique,"
Journal of Physics: Conference Series.
Moric, et. al., (2022). Static-Analysis Techniques of
Malware Reverse Engineering.
Nair, et. al., (2023). A Static Approach for Malware
Analysis: A Guide to Analysis Tools and
Techniques. International Journal for Research in
Applied Science and Engineering Technology,
11(12), 1451–1474.
Sihwail. et. al., (2018), "A Survey on Malware
Analysis Techniques: Static, Dynamic, Hybrid and
Memory Analysis," Int. J. Adv. Sci. Eng. Inf.
Technol., vol. 8, no. 4-2, pp. 1662-1671.
Song et al., Behaviour-based Malware Detection,
2015; Elastic Security, Wazuh Threat Detection
Rules, 2023.
Szor, (2005), The Art of Computer Virus Research
and Defence; Ligh et al., Malware Analyst's
Cookbook, 2010
Talukder & Talukder, (2020), A Survey on Malware
Detection and Analysis Tools, International
Journal of Network Security & Its Applications
(IJNSA) Vol. 12, No.2. Techniques.
Thomas, et. al., (2020), Advanced Threat Protection
with EDR, Springer; MITRE ATT&CK, EDR
Strategies, 2023;
Verizon DBIR, (2023), Phishing Trends; CISA
(2023), Cyber Hygiene Training, NIST SP 800-207,
Zero Trust Architecture, 2023; NSA, Application
Control for Malware Prevention
Wang et al. (2007), “Detecting worms via mining
dynamic program execution,” in Proceedings of the
3rd International Conference on Security and
Privacy in Communication Networks,
SecureComm, pp. 412–421.
Wibowo, (2011), Interoperability of reconfiguring
system on FPGA using a design entry of hardware
description language (Computation and
Communication Technologies: 3rd International
Conference on Advances in Computing, Control,
and Telecommunication Technologies, ACT
Computer Science Series 1) pp. 79-83.
Wiley, Shostack, (Wiley 2014), Threat Modelling,
Johnson (2019), Red Teaming: Ethical Hacking,
McGraw-Hill
Williamson & Beauparlant, (2024). Malware
Reverse Engineering with Large Language Model
for Superior Code Comprehensibility and IoC
Recommendations. Research Square (Research
Square).
Yadav, et. al., (2021), Detecting Malicious Domains,
IEEE ;MISP Project, Open Source Threat
Intelligence, 2023;
Ye, et. al., (2017), “A Survey on Malware Detection
Using Data Mining Techniques,” ACM Comput.
Surv.,1669 vol. 50, no. 3, pp. 1–40.
Yli-Lankoski, (n.d.). Designing and Implementing a
Secure Reverse-Engineering Environment for
Windows-based Malware [Master’s thesis]. JAMK
University of Applied Sciences.
Yusirwan, et. al., (2015a), "Implementation of
Malware Analysis using Static and Dynamic
Analysis Method," International Journal of
Computer Applications, vol. 117, no. 6, pp. 11-15.
Zaki & Humphrey, (2014), “Unveiling the kernel:
Rootkit discovery using selective automated kernel
memory differencing,” Virus Bull.,no. September,
pp. 239–256.
Zeltser, (2001), Reverse Engineering Malware.
Zeltser, (2022), Memory Forensics for Advanced
Threat Hunting, SANS; Sikorski & Honig (2012),
Practical Malware Analysis Cuckoo Sandbox Docs,
Automated Malware Analysis, 2023; Cavallaro et
al., Sandnet, IEEE 2011
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Indonesian Journal of Cybersecurity and Emerging Risks

This work is licensed under a Creative Commons Attribution 4.0 International License.
This work is licensed under a Creative Commons Attribution 4.0 International License (CC BY 4.0)


