{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T20:24:13Z","timestamp":1782937453204,"version":"3.54.5"},"reference-count":57,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2025,11,10]],"date-time":"2025-11-10T00:00:00Z","timestamp":1762732800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Malware remains one of the most persistent and evolving threats to cybersecurity, necessitating robust analysis techniques to understand and mitigate its impact. This study presents a comprehensive analysis of selected malware samples using both static and dynamic analysis techniques. In the static phase, file structure, embedded strings, and code signatures were examined, while in the dynamic analysis phase, the malware was executed in a virtual sandbox environment to observe process creation, network communication, and file system changes. By combining these two approaches, various types of malware files could be characterized and have their key elements revealed. This improved the understanding of the code capabilities and evasive behaviors of malicious files. The goal of these analyses was to create a database of malware profiling tools and tools that can be utilized to identify and analyze malware. The results demonstrate that integrating static and dynamic methodologies improves the accuracy of malware profiling and supports more effective threat detection and incident response strategies.<\/jats:p>","DOI":"10.3390\/jcp5040098","type":"journal-article","created":{"date-parts":[[2025,11,10]],"date-time":"2025-11-10T17:45:34Z","timestamp":1762796734000},"page":"98","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Integrated Analysis of Malicious Software: Insights from Static and Dynamic Perspectives"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-5716-4241","authenticated-orcid":false,"given":"Maria-M\u0103d\u0103lina","family":"Andronache","sequence":"first","affiliation":[{"name":"Research Institute \u201cCAMPUS\u201d, National University of Science and Technology POLITEHNICA Bucharest, RO-060042 Bucharest, Romania"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1970-1117","authenticated-orcid":false,"given":"Alexandru","family":"Vulpe","sequence":"additional","affiliation":[{"name":"Telecommunications Department, National University of Science and Technology POLITEHNICA Bucharest, RO-060042 Bucharest, Romania"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1710-8010","authenticated-orcid":false,"given":"Corneliu","family":"Burileanu","sequence":"additional","affiliation":[{"name":"The Electronic Devices, Circuits and Architectures Department, National University of Science and Technology POLITEHNICA Bucharest, RO-060042 Bucharest, Romania"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,11,10]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"tyaf019","DOI":"10.1093\/cybsec\/tyaf019","article-title":"Learning from safety science: Designing incident reporting systems in cybersecurity","volume":"11","author":"Ebert","year":"2025","journal-title":"J. Cybersecur."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"tyae030","DOI":"10.1093\/cybsec\/tyae030","article-title":"Telling stories about vendors: Narrative practices to negotiate risk and establish an organizational cybersecurity culture","volume":"11","author":"Osburn","year":"2025","journal-title":"J. Cybersecur."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Kazi, M.A. (2025). Detecting Malware C&C Communication Traffic Using Artificial Intelligence Techniques. J. Cybersecur. Priv., 5.","DOI":"10.3390\/jcp5010004"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"19","DOI":"10.3390\/jcp1010003","article-title":"Investigating Anti-Evasion Malware Triggers Using Automated Sandbox Reconfiguration Techniques","volume":"1","author":"Mills","year":"2021","journal-title":"J. Cybersecur. Priv."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"tyy007","DOI":"10.1093\/cybsec\/tyy007","article-title":"Malware in the future? Forecasting of analyst detection of cyber events","volume":"4","author":"Bakdash","year":"2018","journal-title":"J. Cybersecur."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"108415","DOI":"10.1109\/ACCESS.2025.3582086","article-title":"A Review of the Recent Trends in Mobile Malware Evolution, Detection, and Analysis","volume":"13","author":"Almarri","year":"2025","journal-title":"IEEE Access"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"74335","DOI":"10.1109\/ACCESS.2025.3550781","article-title":"From Static to AI-Driven Detection: A Comprehensive Review of Obfuscated Malware Techniques","volume":"13","author":"Chandran","year":"2025","journal-title":"IEEE Access"},{"key":"ref_8","first-page":"68","article-title":"Comparing Hybrid Tool for Static and Dynamic Object-Oriented Metrics","volume":"10","author":"Malik","year":"2019","journal-title":"Int. J. Adv. Comput. Sci. Appl. (IJACSA)"},{"key":"ref_9","first-page":"75","article-title":"Behavioural Analysis of Malware by Selecting Influential API Through TF-IDF API Embeddings","volume":"16","author":"Panda","year":"2025","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"ref_10","unstructured":"\u00c7atak, F.O. (2019). Mal-API-2019. Mendeley Data V2, Elsevier."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Pandian, A.P., Anakath, A.S., Kannadasan, R., Ravikumar, K., and Abdul Kareem, D. (2024, January 22\u201323). Forensic Investigation of Malicious Activities in Digital Environments. Proceedings of the 2024 4th International Conference on Data Engineering and Communication Systems (ICDECS), Bangalore, India.","DOI":"10.1109\/ICDECS59733.2023.10502503"},{"key":"ref_12","unstructured":"Siva Surya, R., Varuneshan, R., and Heltin Genitha, C. (2025, January 11\u201313). Designing a Static Malware Analysis Framework for Detecting Malicious Malware Code with Ghidra. Proceedings of the 2025 3rd International Conference on Self Sustainable Artificial Intelligence Systems (ICSSAS), Erode, India."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1186\/s42400-019-0031-1","article-title":"Creeper: A tool for detecting permission creep in file system access controls","volume":"2","author":"Parkinson","year":"2019","journal-title":"Cybersecurity"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1109\/MSECP.2003.1236233","article-title":"The Morris worm: A fifteen-year perspective","volume":"1","author":"Orman","year":"2003","journal-title":"IEEE Secur. Priv."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1109\/MC.1999.769438","article-title":"Melissa Virus Creates a New Type of Threat","volume":"32","author":"Garber","year":"1999","journal-title":"Computer"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Mohaisen, A., and Alrawi, O. (2013, January 13\u201317). Unveiling Zeus: Automated classification of malware samples. Proceedings of the 22nd International Conference on World Wide Web (WWW \u201813 Companion), Rio de Janeiro, Brazil.","DOI":"10.1145\/2487788.2488056"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"672","DOI":"10.3390\/fi4030672","article-title":"Stuxnet: What Has Changed?","volume":"4","author":"Denning","year":"2012","journal-title":"Future Internet"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"6","DOI":"10.1016\/S1361-3723(18)30084-8","article-title":"Learning the lessons of WannaCry","volume":"2018","author":"Adams","year":"2018","journal-title":"Comput. Fraud. Secur."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Alkhadra, R., Abuzaid, J., AlShammari, M., and Mohammad, N. (2021, January 6\u20138). Solar Winds Hack: In-Depth Analysis and Countermeasures. Proceedings of the 2021 12th International Conference on Computing Communication and Networking Technologies (ICCCNT), Kharagpur, India.","DOI":"10.1109\/ICCCNT51525.2021.9579611"},{"key":"ref_20","first-page":"55","article-title":"Ransomware as a Predator: Modelling the Systemic Risk to Prey","volume":"4","author":"Axon","year":"2023","journal-title":"Digit. Threat."},{"key":"ref_21","first-page":"38","article-title":"Ransomware: Why it\u2019s growing and how to curb its growth","volume":"3","author":"Jaffe","year":"2024","journal-title":"Appl. Cybersecur. Internet Gov."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"159","DOI":"10.1080\/23738871.2024.2357092","article-title":"Ransomware as a threat to peace and security: Understanding and avoiding political worst-case scenarios","volume":"9","author":"Hansel","year":"2024","journal-title":"J. Cyber Policy"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Gomes, V., Reis, J., and Alturas, B. (2020, January 24\u201327). Social Engineering and the Dangers of Phishing. Proceedings of the 2020 15th Iberian Conference on Information Systems and Technologies (CISTI), Seville, Spain.","DOI":"10.23919\/CISTI49556.2020.9140445"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Gallagher, S., Gelman, B., Taoufiq, S., V\u00f6r\u00f6s, T., Lee, Y., Kyadige, A., and Bergeron, S. (2024). Phishing and Social Engineering in the Age of LLMs. Large Language Models in Cybersecurity, Springer.","DOI":"10.1007\/978-3-031-54827-7_8"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Barcan, A., Badoi, M., Nedianu, G., Ciochiu, D., Traistaru, C., and Enescu, N. (2024, January 19\u201320). Advanced Persistent Threats. Proceedings of the 2024 23rd RoEduNet Conference: Networking in Education and Research (RoEduNet), Bucharest, Romania.","DOI":"10.1109\/RoEduNet64292.2024.10722615"},{"key":"ref_26","first-page":"39","article-title":"Advanced Persistent Threat Attack Detection Systems: A Review of Approaches, Challenges, and Trends","volume":"5","author":"Buchta","year":"2024","journal-title":"Digit. Threat."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"387","DOI":"10.1007\/s11277-022-09960-z","article-title":"Cloud Security Threats and Solutions: A Survey","volume":"128","author":"Butt","year":"2022","journal-title":"Wirel. Pers. Commun."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Pitkar, H. (2025). Cloud Security Automation Through Symmetry: Threat Detection and Response. Symmetry, 17.","DOI":"10.3390\/sym17060859"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Pallakonda, A., Kaliyannan, K., Sumathi, R.L., Raj, R.D.A., Yanamala, R.M.R., Napoli, C., and Randieri, C. (2025). AI-Driven Attack Detection and Cryptographic Privacy Protection for Cyber-Resilient Industrial Control Systems. IoT, 6.","DOI":"10.3390\/iot6030056"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Brohi, S., and Mastoi, Q.-U.-A. (2025). AI Under Attack: Metric-Driven Analysis of Cybersecurity Threats in Deep Learning Models for Healthcare Applications. Algorithms, 18.","DOI":"10.3390\/a18030157"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Mohamed Mohideen, M.A., Nadeem, M.S., Hardy, J., Ali, H., Tariq, U.U., Sabrina, F., Waqar, M., and Ahmed, S. (2024). Behind the Code: Identifying Zero-Day Exploits in WordPress. Future Internet, 16.","DOI":"10.3390\/fi16070256"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Berrios Vasquez, S.I., Hermosilla Monckton, P.A., Leiva Mu\u00f1oz, D.I., and Allende, H. (2025). Zero-Day Threat Mitigation via Deep Learning in Cloud Environments. Appl. Sci., 15.","DOI":"10.3390\/app15147885"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Shastry, A.S., Shreyas, M.P., Karthik, R., Chinmaya, B.N., Chethana, H.T., and Sarkar, S. (2025, January 14\u201316). A Comprehensive Linux Log Dataset with Root Cause and Remediation for Security Analysis. Proceedings of the 2025 5th International Conference on Pervasive Computing and Social Networking (ICPCSN), Salem, India.","DOI":"10.1109\/ICPCSN65854.2025.11036038"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Jeyaram, A., and Muthukumaravel, A. (2024, January 6\u20137). Detect, Analyze, Act: Advancing Cybersecurity Investigations with Data Engineering and AI. Proceedings of the 2024 Asian Conference on Intelligent Technologies (ACOIT), Kolar, India.","DOI":"10.1109\/ACOIT62457.2024.10939915"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"3715086","DOI":"10.1155\/int\/3715086","article-title":"A Resilience Recovery Method for Complex Traffic Network Security Based on Trend Forecasting","volume":"2025","author":"Hong","year":"2025","journal-title":"Int. J. Intell. Syst."},{"key":"ref_36","unstructured":"abuse.ch (2025, August 24). MalwareBazaar. Available online: https:\/\/bazaar.abuse.ch\/."},{"key":"ref_37","unstructured":"VirusTotal (2025, August 15). VirusTotal\u2014Free Online Virus, Malware and URL Scanner. Available online: https:\/\/www.virustotal.com\/."},{"key":"ref_38","unstructured":"GNU File (2025, August 15). File\u2014Determine File Type. Available online: https:\/\/www.darwinsys.com\/file\/."},{"key":"ref_39","unstructured":"GNU Binutils Strings (2025, August 15). Strings\u2014Print the Strings of Printable Characters in Files. Available online: https:\/\/sourceware.org\/binutils\/docs\/binutils\/strings.html."},{"key":"ref_40","unstructured":"Vector 35 (2025, August 15). Binary Ninja\u2014Reverse Engineering Platform. Available online: https:\/\/binary.ninja\/."},{"key":"ref_41","unstructured":"Winitor (2025, August 15). Pestudio\u2014Malware Analysis Tool. Available online: https:\/\/www.winitor.com\/."},{"key":"ref_42","unstructured":"YARA (2025, August 15). YARA\u2014The Pattern Matching Swiss Knife for Malware Researchers. Available online: https:\/\/virustotal.github.io\/yara\/."},{"key":"ref_43","unstructured":"wxHexEditor (2025, August 15). wxHexEditor\u2014Free Hex Editor. Available online: https:\/\/sourceforge.net\/projects\/wxhexeditor\/."},{"key":"ref_44","unstructured":"Censys (2025, August 15). Censys\u2014Search Engine for Internet-Connected Devices. Available online: https:\/\/censys.io\/."},{"key":"ref_45","unstructured":"Shodan (2025, August 15). Shodan\u2014The Search Engine for the Internet of Things. Available online: https:\/\/www.shodan.io\/."},{"key":"ref_46","unstructured":"Microsoft Sysinternals (2025, August 15). Process Monitor (Procmon). Available online: https:\/\/learn.microsoft.com\/en-us\/sysinternals\/downloads\/procmon."},{"key":"ref_47","unstructured":"Microsoft Sysinternals (2025, August 15). Sysmon\u2014System Monitor. Available online: https:\/\/learn.microsoft.com\/en-us\/sysinternals\/downloads\/sysmon."},{"key":"ref_48","unstructured":"Wireshark Foundation (2025, August 15). Wireshark\u2014Network Protocol Analyzer. Available online: https:\/\/www.wireshark.org\/."},{"key":"ref_49","unstructured":"Regshot (2025, August 15). Regshot\u2014Registry Compare Utility. Available online: https:\/\/sourceforge.net\/projects\/regshot\/."},{"key":"ref_50","unstructured":"Mandiant (2025, August 15). FakeNet-NG\u2014Dynamic Network Analysis Tool. Available online: https:\/\/github.com\/mandiant\/flare-fakenet-ng."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Widiyasono, N., Selamat, S.R., Rizal, R., Fidayan, A., Mulyani, S.R., and Risnanto, S. (2024, January 17\u201318). Advanced Malware Analysis Methods: Behaviour-Based Detection and Reverse Engineering. Proceedings of the 2024 18th International Conference on Telecommunication Systems, Services, and Applications (TSSA), Bali, Indonesia.","DOI":"10.1109\/TSSA63730.2024.10864310"},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Choudhary, V., Singh, S., Atrey, S., Kumar, A., and Kalita, S. (2025, January 7\u20138). A Custom Sandbox for Malware Threat Analysis to Safeguard Infrastructure. Proceedings of the 2025 3rd International Conference on Disruptive Technologies (ICDT), Greater Noida, India.","DOI":"10.1109\/ICDT63985.2025.10986311"},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Rahman, R.U., Acharya, A., Deb, S., and Panchal, P. (2025, January 7\u20139). Dynamic Forensic Analysis of CryptBot Malware. Proceedings of the 2025 IEEE 14th International Conference on Communication Systems and Network Technologies (CSNT), Bhopal, India.","DOI":"10.1109\/CSNT64827.2025.10967635"},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Sinha, A.K., and Sai, S. (2023, January 6\u20138). Integrated Malware Analysis Sandbox for Static and Dynamic Analysis. Proceedings of the 2023 14th International Conference on Computing Communication and Networking Technologies (ICCCNT), Delhi, India.","DOI":"10.1109\/ICCCNT56998.2023.10306805"},{"key":"ref_55","unstructured":"Pratama, Y., Munzi, R.S., Mustafa, A.B., and Kharisma, I.L. (2025). Static Malware Detection and Classification Using Machine Learning: A Random Forest Approach. Eng. Proc., 107."},{"key":"ref_56","first-page":"1","article-title":"Analisis Perilaku Malware Menggunakan Pendekatan Analisis Statis dan Dinamis","volume":"4","author":"Khalda","year":"2025","journal-title":"J. Sains Nalar Dan Apl. Teknol. Inf."},{"key":"ref_57","doi-asserted-by":"crossref","unstructured":"Syeda, D.Z., and Asghar, M.N. (2024). Dynamic Malware Classification and API Categorisation of Windows Portable Executable Files Using Machine Learning. Appl. Sci., 14.","DOI":"10.3390\/app14031015"}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/98\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,11]],"date-time":"2025-11-11T09:43:25Z","timestamp":1762854205000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/98"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,10]]},"references-count":57,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["jcp5040098"],"URL":"https:\/\/doi.org\/10.3390\/jcp5040098","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,10]]}}}