Evaluation of the effectiveness of static and dynamic methods in malware analysis
Abstract
This study provides a comparative evaluation of static and dynamic analysis techniques applied to different malware families targeting Windows operating systems. Real-world samples were obtained from the MalwareBazaar portal and included Jigsaw ransomware, the StealC infostealer, and Remcos RAT. The results indicate that static analysis is effective for rapid initial triage of a sample. In-depth static analysis provides a high level of certainty about a sample's capabilities. In certain scenarios, static analysis was clearly insufficient, for example, when the code was protected by a packer, when the configuration was encrypted, or when the relevant stage existed only in memory. In those cases, dynamic analysis techniques, such as memory inspection and memory dumping using a debugger, proved essential for obtaining indicators of compromise. Moreover, dynamic analysis is required to confirm runtime behavior. The reported effectiveness values apply only to the analyzed samples and to the scoring system adopted in this study. The findings demonstrate that hybrid analysis provides the most comprehensive and reliable interpretation of malware behavior within this experimental scope.