Evaluation of the effectiveness of static and dynamic methods in malware analysis
Article Sidebar
Issue Vol. 40 (2026)
-
Analysis of the capabilities of predictive artificial intelligence models in corporate risk management
Kacper Ziemski188-192
-
Usability and availability of selected e-commerce services
Marcin Kozicki, Maria Skublewska-Paszkowska193-200
-
Comparison of C++ and Python performance based on selected algorithms
Szymon Bogucki, Kacper Burda201-205
-
Security analysis of selected web applications using vulnerability scanners
Mariusz Choroś, Marta Dziuba-Kozieł206-212
-
Comparison of Java and .NET reflection mechanisms for dynamic module loading: a performance benchmark study
Michał Mazur, Sebastian Maruszak, Marek Miłosz213-217
-
Comparative analysis of network vulnerability detection tools
Mateusz Zdunek218-225
-
Evaluation of mobile applications for personal finance management using the MARS scale
Łukasz Nikiel, Artsiom Patskevich, Marek Miłosz226-231
-
Comparison of the effectiveness of roulette betting strategies using Monte Carlo simulation
Marek Sarnecki232-238
-
Analysis of optimization capabilities of selected database management systems
Paweł Tarkiewicz, Małgorzata Plechawska-Wójcik239-246
-
Comparative analysis of Espresso and Appium frameworks for automated UI testing of Android mobile applications
Jakub Derkacz247-254
-
Comparative analysis of the applicability of artificial intelligence models for code generation
Patryk Warchoł, Małgorzata Plechawska-Wójcik255-262
-
Comparison of the effectiveness of selected tools for detecting texts generated by artificial intelligence
Marcin Brodacki, Małgorzata Plechawska-Wójcik263-269
-
Comparative analysis of selected containerization tools in terms of MCP
Paweł Jan Tłusty, Maciej Pańczyk270-276
-
SpikeCliff effect: empirical analysis of deterministic timing discontinuities in sponge-based XOF functions
Łukasz Wójcik, Stanisław Lota277-282
-
Comparison of AI agents for creating SQL queries
Julia Sierpień, Maria Skublewska-Paszkowska283-288
-
Comparative analysis of the performance of PostgreSQL and Neo4j databases in the context of genealogical queries
Michał Muzyka, Mateusz Niedźwiedź, Marek Miłosz289-296
-
Evaluation of the effectiveness of static and dynamic methods in malware analysis
Dominik Tracz, Daniel Sawicki, Konrad Gromaszek297-303
-
Comparison of classical machine learning methods in the task of obesity level classification
Paweł Biesaga, Paweł Powroźnik304-312
Main Article Content
Authors
Abstract
This study provides a comparative evaluation of static and dynamic analysis techniques applied to different malware families targeting Windows operating systems. Real-world samples were obtained from the MalwareBazaar portal and included Jigsaw ransomware, the StealC infostealer, and Remcos RAT. The results indicate that static analysis is effective for rapid initial triage of a sample. In-depth static analysis provides a high level of certainty about a sample's capabilities. In certain scenarios, static analysis was clearly insufficient, for example, when the code was protected by a packer, when the configuration was encrypted, or when the relevant stage existed only in memory. In those cases, dynamic analysis techniques, such as memory inspection and memory dumping using a debugger, proved essential for obtaining indicators of compromise. Moreover, dynamic analysis is required to confirm runtime behavior. The reported effectiveness values apply only to the analyzed samples and to the scoring system adopted in this study. The findings demonstrate that hybrid analysis provides the most comprehensive and reliable interpretation of malware behavior within this experimental scope.
Keywords:
Sustainable Development Goal (SDG)
- Industry, Innovation, Technology and Infrastructure
References
[1] M. Sikorski, A. Honig, Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software, No Starch Press, San Francisco, 2012.
[2] E. Eilam, Reversing: Secrets of Reverse Engineering, Wiley, Indianapolis, 2005.
[3] A. Damodaran, F. Di Troia, V. A. Corrado, T. H. Austin, M. Stamp, A Comparison of Static, Dynamic, and Hybrid Analysis for Malware Detection, Journal of Computer Virology and Hacking Techniques 13 (2017) 1-12, https://doi.org/10.1007/s11416-015-0261-z.
[4] K. Monnappa, Learning Malware Analysis: Explore the concepts, tools, and techniques to analyze and investigate Windows malware, Packt Publishing, Birmingham, 2018.
[5] V. M. Alvarez, YARA: The pattern matching swiss knife, https://virustotal.github.io/yara/, [12.05.2026].
[6] horsicq, Detect It Easy: packer and compiler detection tool, https://github.com/horsicq/Detect-It-Easy, [18.05.2026].
[7] Sekoia TDR, StealC: a copycat of Vidar and Raccoon infostealers gaining in popularity - Part 1, https://blog.sekoia.io/stealc-a-copycat-of-vidar-and-raccoon-infostealers-gaining-in-popularity-part-1/, [02.06.2026].
[8] Sekoia TDR, StealC: a copycat of Vidar and Raccoon infostealers gaining in popularity - Part 2, https://blog.sekoia.io/stealc-a-copycat-of-vidar-and-raccoon-infostealers-gaining-in-popularity-part-2/, [02.06.2026].
[9] W. Harris, Improving the security of Chrome cookies on Windows, Google Security Blog, https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html, [03.06.2026].
[10] A. Afianian, S. Niksefat, B. Sadeghiyan, D. Baptiste, Malware Dynamic Analysis Evasion Techniques: A Survey, ACM Computing Surveys 52(6) (2019) 1–28, https://doi.org/10.1145/3365001.
[11] L. Maffia, D. Nisi, P. Kotzias, G. Lagorio, S. Aonzo, D. Balzarotti, Longitudinal Study of the Prevalence of Malware Evasive Techniques, arXiv preprint arXiv:2112.11289 (2021), https://doi.org/10.48550/arXiv.2112.11289.
[12] O. Alrawi, M. Y. Wong, A. Avgetidis, K. Valakuzhy, B. V. Adjibi, K. Karakatsanis, M. Ahamad, D. Blough, F. Monrose, M. Antonakakis, SoK: An Essential Guide For Using Malware Sandboxes In Security Applications: Challenges, Pitfalls, and Lessons Learned, arXiv preprint arXiv:2403.16304 (2024), https://doi.org/10.48550/arXiv.2403.16304.
[13] K. Aryal, M. Gupta, M. Abdelsalam, M. Saleh, Intra-section code cave injection for adversarial evasion attacks on windows PE malware file, Computers & Security 159 (2025) 104690, https://doi.org/10.1016/j.cose.2025.104690.
[14] R. J. Joyce, E. Raff, C. Nicholas, J. Holt, MalDICT: Benchmark Datasets on Malware Behaviors, Platforms, Exploitation, and Packers, arXiv preprint arXiv:2310.11706 (2023), https://doi.org/10.48550/arXiv.2310.11706.
[15] abuse.ch, MalwareBazaar: malware sample exchange portal, https://bazaar.abuse.ch/, [29.05.2026].
[16] National Security Agency, Ghidra Software Reverse Engineering Framework, https://ghidra-sre.org/, [05.06.2026].
[17] ANY.RUN, Interactive Online Malware Sandbox, https://any.run/, [29.05.2026].
Article Details
Abstract views: 1

