Feature Extraction and Analysis of Portable Executable Malicious File
Manojkumar T Kamble, Sridevi · 2022 Second International Conference on Computer Science, Engineering and Applications (ICCSEA) · 2022
Malware is intentionally developed software to harm the working of a computer system. Modern malware is designed with mutation, and encryption characteristics, which increases a large number of different kinds of malware samples every day and these features made malware more active and robust against antivirus software. The portable executable file is a format or data structure of executable, DLL, object, and other files which are used by the Windows operating system. PE file format has a set of information that is used by windows operating system machines for executing the files. The PE file format has a header part and this part acts as metadata for all the tables because this header consists of all the details about the data which is stored in the PE file. The malware authors target the PE file header for spreading maliciousness and hacking the particular system. Malware uses these portable executable files for storing and spreading malicious contents. Most benign or malicious files use portable executable file format for storing and executing their.exe and other supporting files in the windows computer system. So to overcome all these problems, in this paper, dissection, and features have been extracted from malicious PE files.