Static malware analysis is typically the first line of investigation when dealing with a suspicious executable. Before a sample ever touches a sandbox, analysts can extract meaningful intelligence by examining its structure, metadata, embedded strings, imported APIs, and behavioral indicators — all without running a single line of code.

In this investigation, I conducted a comprehensive static analysis of multiple suspicious Windows Portable Executable (PE) samples using a dedicated malware analysis lab built on REMnux and FLARE-VM. The goal was to identify Indicators of Compromise (IOCs), uncover malicious capabilities, and map observed behaviors to the MITRE ATT&CK framework, entirely through static means.
The complete project, screenshots, and supporting documentation are available on . If you found this investigation useful, I would love to hear your thoughts or discuss alternative approaches to static malware analysis.
Contact: was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
SOCIAL SHARE CARD GENERATOR