| name | performing-static-malware-analysis-with-pe-studio |
| description | Use when performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary. Identifies suspicious characteristics including packing, anti-analysis techniques, and malicious imports. Activates for requests involving static malware analysis, PE file inspection, Windows executable analysis, or pre-execution malware triage.
'. |
| domain | cybersecurity |
| tags | ["malware","static-analysis","PE-analysis","PEStudio","reverse-engineering"] |
| subdomain | malware-analysis |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["DE.AE-02","RS.AN-03","ID.RA-01","DE.CM-01"] |
Performing Static Malware Analysis With Pe Studio
Overview
Cybersecurity skill for performing static malware analysis with pe studio. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"performing static malware analysis with pe studio"
-
"Performs static analysis of Windows PE (Portable Executable) malware samples usi"
-
A suspicious Windows executable has been collected and needs initial triage before sandbox execution
-
You need to identify imports, strings, and resources that reveal malware functionality without running the sample
-
Determining whether a PE file is packed, obfuscated, or contains anti-analysis techniques
-
Extracting indicators of compromise (hashes, URLs, IPs, registry keys) embedded in a binary
-
Classifying a sample's capabilities based on its import table and section characteristics
Do not use for dynamic behavioral analysis requiring execution; use a sandbox (Cuckoo, ANY.RUN) for runtime behavior observation.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- PEStudio (free edition from https://www.winitor.com/) installed on an isolated analysis workstation
- Python 3.8+ with
pefile library for scripted PE analysis (pip install pefile)
- CFF Explorer or PE-bear as supplementary PE analysis tools
- Access to VirusTotal API for hash lookups and community intelligence
- Isolated analysis VM with no network connectivity to production systems
- FLOSS (FireEye Labs Obfuscated String Solver) for extracting obfuscated strings
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": ,
}
() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}