Some Malicious PE Stats, (Thu, Aug 27th)
ID: d19b95c6-f16e-5e9b-8e21-a960fc506c09
STIX ID: report--d19b95c6-f16e-5e9b-8e21-a960fc506c09
Feed Name: SANS ISC Diary
This report presents a large-scale statistical analysis of PE files (downloaded from MalwareBazaar, 2020-02-24 to 2026-07-08) using pefile to extract Rich Header, CLR metadata, and heuristic signatures; it summarizes counts for architectures, Rich Header presence, top linker versions and MSVC builds, and identifies likely compiler/toolchain usage (MSVC, GCC/MinGW, Delphi, Go, Rust, etc.), concluding that 32-bit malware remains prevalent and newer languages like Go and Rust are still uncommon in the dataset.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
