Analyzing Malware: A Comparative Study of Static and Dynamic Methods through Reverse Engineering

Authors

Keywords:

Malware, Reverse Engineering, Static analysis, Dynamic Analysis

Abstract

Malware remains a critical and evolving threat to modern computing environments, necessitating advanced defensive strategies from cybersecurity professionals. This study explores malware analysis through both static and dynamic approaches within a Windows-based environment, emphasizing the role of reverse engineering. Static analysis involves inspecting malware binaries, structure, and metadata without execution. Tools such as IDA Pro and CFF Explorer allow analysts to uncover embedded exploits, operational logic, and potential payloads, offering deep structural insight into the malware’s functionality.In contrast, dynamic analysis focuses on observing malware behaviour in real time by executing it within an isolated virtual machine. This method, supported by tools like Process Monitor (ProcMon), enables analysts to track runtime activities, such as API calls, file system alterations, registry modifications, and network interactions. The integration of these tools provides a comprehensive view of malware behaviour, both at the static and operational levels.The paper also highlights the growing sophistication of malware, which increasingly employs obfuscation and evasion techniques. Thus, combining static and dynamic analyses— augmented by antivirus tools and SIEM platforms like Wazuh—enhances detection capabilities. The study concludes that a hybrid reverse engineering strategy significantly strengthens malware defence, offering actionable recommendations to reduce future threats within enterprise-level Windows environments. Keyword—Malware,Reverse Engineering, Static analysis, Dynamic Analysis

Downloads

Download data is not yet available.

References

Abdelwahed, et. al., (2023). Detecting Malware

Activities with MalpMiner: A Dynamic Analysis

Approach. IEEE Access, 4.

Almarri & Sant, (2014), Optimised Malware

Detection in Digital Forensics (International Journal

of Network Security & Its Applications (IJNSA)) Vol

6 No 1.

Alsharabi et. al., (2023). Analysis of ransomware

Using Reverse Engineering Techniques to Develop

Effective Countermeasures. Journal of Advances in

Information Technology, 14(2), 284–294.

Anastasios, (2023). Malware Analysis and Reverse

Engineering. In University of West Attica, University

of West Attica [Thesis; PDF].

Arif Islam & Mohan Kumar, (2023). Cyber Safety

Analysis Using Reverse Engineering. In

International Journal of Research Publication and

Reviews & Karpagam Academy of Higher

Education (KAHE), International Journal of

Research Publication and Reviews (Vol. 4, Issue 1,

pp. 399–403).

Aslan, (2017), "Investigation of Possibilities to

Detect Malware Using Existing Tools," IEEE/ACS

14th International Conference on Computer

Systems and Applications (AICCSA), Ham-mamet,

Tunisia, 2017, pp. 1277-1284, doi:

10.1109/AICCSA.2017.24. Ghidra: Documentation.

(2024, April 20). National Security Agency.

https://github.com/NationalSecurityAgency/ghidra

Aslan, (2017), Performance Comparison of Static

Malware Analysis Tools Versus Antivirus Scanners

to Detect Malware, International Multidisciplinary

Studies Congress (IMSC), Akdeniz University,

Antalya/Turkey on 25-26 November 2017.

Balci, (n.d.). Malware Reverse Engineering

Handbook. CCDCOE. Ching (2021). Enhancing

Usability of Malware Analysis Pipelines with

Reverse Engineering. In Master of Science in

Computer Science [Thesis]. Syracuse University.

Blázquez & Tapiador, (2023) "Kunai: A static

analysis framework for Android apps," SoftwareX,

vol. 22, p. 101370.

Chen, et. al., (2023). Efficient Windows malware

identification and classification scheme for plant

protection information systems. Frontiers in Plant

Science, 14.

Cletus. et. al., (2024) An Evaluation of Current

Malware Trends and Defense Techniques: A

Scoping Review with Empirical Case Studies. In

Journal of Advances in Information Technology

(Vol. 15, Issue 5, pp. 649–671).

Damodaran, et. al., (2022), A Comparison of Static,

Dynamic, and Hybrid Analysis.

Eilam, (2003). Reversing - Secrets of Reverse

Engineering. Indianapolis: Wiley Publishing, Inc

Ferdous, et. al., (2023), "A Review of State-of-theArt Malware Attack Trends and Defence

Mechanisms," in IEEE Access, vol. 11, pp. 121118-

121141 for Malware Detection," Journal of

Computer Virology and Hacking

Gulmez, et. al., (2024), "Analysis of the Zero-Day

Detection of Metamorphic Malware," 2024 9th

International Conference on Computer Science and

Engineering (UBMK), Antalya, Turkiye, 2024, pp. 1-

6.

Hex Rays: IDA Pro, (2024, April 20). Hex Rays.

https://hex-rays.com/ida-pro/

Hinderaker, et. al., (2024), Exploring Destructive

Malware: A Practical Approach to Wiper Malware

“Developing wiper malware to identify weaknesses

and improve security in Windows systems”

M. Karresand, (2003), “Separating Trojan horses,

viruses, and worms – A proposed taxonomy of

software weapons,” in IEEE Systems, Man and

Cybernetics Society Information Assurance

Workshop, pp.127–134.

Manohar Venkat, et. al., (2023). Malware Reverse

Engineering to Find the Malicious Activity of Emotet.

In Advances in transdisciplinary engineering.

Megira, et. al., (2018), "Malware Analysis and

Detection Using Reverse Engineering Technique,"

Journal of Physics: Conference Series.

Moric, et. al., (2022). Static-Analysis Techniques of

Malware Reverse Engineering.

Nair, et. al., (2023). A Static Approach for Malware

Analysis: A Guide to Analysis Tools and

Techniques. International Journal for Research in

Applied Science and Engineering Technology,

11(12), 1451–1474.

Sihwail. et. al., (2018), "A Survey on Malware

Analysis Techniques: Static, Dynamic, Hybrid and

Memory Analysis," Int. J. Adv. Sci. Eng. Inf.

Technol., vol. 8, no. 4-2, pp. 1662-1671.

Song et al., Behaviour-based Malware Detection,

2015; Elastic Security, Wazuh Threat Detection

Rules, 2023.

Szor, (2005), The Art of Computer Virus Research

and Defence; Ligh et al., Malware Analyst's

Cookbook, 2010

Talukder & Talukder, (2020), A Survey on Malware

Detection and Analysis Tools, International

Journal of Network Security & Its Applications

(IJNSA) Vol. 12, No.2. Techniques.

Thomas, et. al., (2020), Advanced Threat Protection

with EDR, Springer; MITRE ATT&CK, EDR

Strategies, 2023;

Verizon DBIR, (2023), Phishing Trends; CISA

(2023), Cyber Hygiene Training, NIST SP 800-207,

Zero Trust Architecture, 2023; NSA, Application

Control for Malware Prevention

Wang et al. (2007), “Detecting worms via mining

dynamic program execution,” in Proceedings of the

3rd International Conference on Security and

Privacy in Communication Networks,

SecureComm, pp. 412–421.

Wibowo, (2011), Interoperability of reconfiguring

system on FPGA using a design entry of hardware

description language (Computation and

Communication Technologies: 3rd International

Conference on Advances in Computing, Control,

and Telecommunication Technologies, ACT

Computer Science Series 1) pp. 79-83.

Wiley, Shostack, (Wiley 2014), Threat Modelling,

Johnson (2019), Red Teaming: Ethical Hacking,

McGraw-Hill

Williamson & Beauparlant, (2024). Malware

Reverse Engineering with Large Language Model

for Superior Code Comprehensibility and IoC

Recommendations. Research Square (Research

Square).

Yadav, et. al., (2021), Detecting Malicious Domains,

IEEE ;MISP Project, Open Source Threat

Intelligence, 2023;

Ye, et. al., (2017), “A Survey on Malware Detection

Using Data Mining Techniques,” ACM Comput.

Surv.,1669 vol. 50, no. 3, pp. 1–40.

Yli-Lankoski, (n.d.). Designing and Implementing a

Secure Reverse-Engineering Environment for

Windows-based Malware [Master’s thesis]. JAMK

University of Applied Sciences.

Yusirwan, et. al., (2015a), "Implementation of

Malware Analysis using Static and Dynamic

Analysis Method," International Journal of

Computer Applications, vol. 117, no. 6, pp. 11-15.

Zaki & Humphrey, (2014), “Unveiling the kernel:

Rootkit discovery using selective automated kernel

memory differencing,” Virus Bull.,no. September,

pp. 239–256.

Zeltser, (2001), Reverse Engineering Malware.

Zeltser, (2022), Memory Forensics for Advanced

Threat Hunting, SANS; Sikorski & Honig (2012),

Practical Malware Analysis Cuckoo Sandbox Docs,

Automated Malware Analysis, 2023; Cavallaro et

al., Sandnet, IEEE 2011

Downloads

Published

2026-05-31