cb-static-malware-analysis-with-pe-studio - Analyze Windows PE Malware Without Execution
Performs static analysis of Windows PE malware with PEStudio to examine headers, imports, strings, resources, and indicators without executing the binary.
Tags
Updated: 2026-10-06Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Compute cryptographic hashes
- Inspect PE headers
- Analyze section characteristics
- Analyze import tables
- Extract strings and indicators
- Identify packing techniques
- Classify sample capabilities
Inputs
- Windows PE malware sample
- Case identifier
- Artifact relative path
- VirusTotal API key
Outputs
- Cryptographic hash values
- PE analysis findings
- Extracted indicators
- VirusTotal lookup results
- Journal entries
- SIFT tool outputs
Requirements
- PEStudio installation
- Python 3.8 or later
- Python pefile library
- CFF Explorer or PE-bear
- VirusTotal API access
- FLOSS installation
- Isolated analysis workstation
- Verified SIFT tools
