Designing a Static Malware Analysis Framework for Detecting Malicious Malware Code with Ghidra
Siva Surya R, R Varuneshan, C. Heltin Genitha · 2025
Malware analysis is an integral part of cybersecurity, however traditional signature-based detection techniques are inadequate for advanced obfuscation techniques. This paper proposes a static malware analysis framework for identifying malicious code, using Ghidra. The proposed malware analysis framework decompiles malware samples automatically in order to extract features, while reviewing control flow, scanning opcodes, or extracting embedded strings. Additionally, the system uses integrated tools such as VirusTotal API and PEview to validate or classify signatures and analyze file structure. An experimental evaluation of the proposed framework showed an 89% success rate of malware detection that outperformed the performance of traditional signature based methods (72%) and had a lower false-positive rate (7%) than heuristic based methods (15%) under specific conditions. Results suggest that the proposed framework is effective towards the identification of obfuscated malware while being reliable. Unlike earlier traditional techniques, the system user-friendly utilizes Ghidra's improved, advanced capabilities of decompilation and scripts to offer more precision and automation. The solution provides improvement in cybersecurity with an effective, scalable, and automated, static approach to malware analysis.