Evaluation of the effectiveness of static and dynamic methods in malware analysis

Main Article Content

Dominik Tracz

dominiktr11@gmail.com

https://orcid.org/0009-0008-5476-909X
Daniel Sawicki

d.sawicki@pollub.pl

https://orcid.org/0000-0001-6452-9294
Konrad Gromaszek

k.gromaszek@pollub.pl

Abstract

This study provides a comparative evaluation of static and dynamic analysis techniques applied to different malware families targeting Windows operating systems. Real-world samples were obtained from the MalwareBazaar portal and included Jigsaw ransomware, the StealC infostealer, and Remcos RAT. The results indicate that static analysis is effective for rapid initial triage of a sample. In-depth static analysis provides a high level of certainty about a sample's capabilities. In certain scenarios, static analysis was clearly insufficient, for example, when the code was protected by a packer, when the configuration was encrypted, or when the relevant stage existed only in memory. In those cases, dynamic analysis techniques, such as memory inspection and memory dumping using a debugger, proved essential for obtaining indicators of compromise. Moreover, dynamic analysis is required to confirm runtime behavior. The reported effectiveness values apply only to the analyzed samples and to the scoring system adopted in this study. The findings demonstrate that hybrid analysis provides the most comprehensive and reliable interpretation of malware behavior within this experimental scope.

Keywords:

: malware analysis, reverse engineering, static analysis, dynamic analysis, ransomware, infostealer

Sustainable Development Goal (SDG)

  • Industry, Innovation, Technology and Infrastructure

References

Article Details

Tracz, D., Sawicki, D., & Gromaszek, K. (2026). Evaluation of the effectiveness of static and dynamic methods in malware analysis. Journal of Computer Sciences Institute, 40, 297-303. https://doi.org/10.35784/jcsi.9916