本文へ移動
cccskills
無料GitHub で公開

performing-static-pe-analysis

Extracts structure and indicators from a Windows PE file without executing it: headers, sections, imports/exports, resources, entropy, and embedded strings to infer capability and packing. Activates for requests to statically analyze a PE, EXE, or DLL, or inspect imports and headers.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md3.5 KB
  • LICENSE340 B
  • references/api-reference.md1.4 KB
  • scripts/analyst.py4.1 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Performing Static PE Analysis

When to Use

  • You have a Windows executable or DLL and need to infer its capabilities before (or instead of) detonation.
  • You want to assess packing, suspicious imports, timestamps, and embedded resources.
  • You are gathering features for YARA authoring or detection.

Do not use import tables alone to conclude behavior — packed samples hide imports until runtime. If imports are sparse and entropy is high, move to unpacking.

Prerequisites

  • pefile (pip install pefile) and optionally capa/PEStudio for deeper capability ID.
  • The sample in neutralized form inside the lab.

Safety & Handling

  • Static only: parse the file, never run it. Keep the neutralized extension.

Workflow

Step 1: Parse headers and metadata

python scripts/analyst.py analyze sample.bin

Note the compile timestamp (often forged), subsystem (GUI/console), machine type (x86/x64), and whether it is a DLL.

Step 2: Review sections and entropy

Per-section entropy reveals packing. A tiny .text plus a huge high-entropy section, or non-standard section names (UPX0, .themida), indicate a packer:

.text   entropy 6.4  (normal code)
UPX1    entropy 7.95 (packed)

Step 3: Classify imports

Group imported APIs into behavioral buckets:

Injection : VirtualAllocEx, WriteProcessMemory, CreateRemoteThread   [T1055]
Network   : InternetOpen, HttpSendRequest, WinHttpConnect            [T1071]
Crypto    : CryptEncrypt, CryptAcquireContext                        [T1486]
Persistence: RegSetValueEx, CreateService                            [T1547/T1543]

A sample importing only LoadLibrary/GetProcAddress is resolving APIs dynamically — a packing/evasion tell.

Step 4: Inspect resources and strings

Look for embedded PEs in resources (droppers), config blobs, and notable strings (URLs, mutex names, paths).

Step 5: Check signing

Verify the Authenticode signature: unsigned, self-signed, or revoked certificates are suspicious for software claiming to be legitimate.

Validation

  • Section entropy and import counts agree (packed → few imports + high entropy).
  • Suspicious import buckets correspond to plausible behavior.
  • Embedded PE detection is confirmed by an MZ/PE header inside a resource.

Pitfalls

  • Trusting the compile timestamp as a real build date — it is trivially forged.
  • Concluding "benign" because imports look ordinary; the import table may be a stub for a packed payload.
  • Ignoring TLS callbacks, which can run code before the entry point.

References

  • See references/api-reference.md for the analyzer and import classification map.
  • Microsoft PE Format spec and pefile (linked in frontmatter).

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する