Some Malicious PE Stats
Executive Summary
The author shares a Python script that uses the pefile library to parse PE headers of malicious binaries, extracting metadata such as compiler information and architecture (32‑bit vs 64‑bit). The script builds on earlier statistics about 64‑bit versus 32‑bit malware and provides deeper insights into the tools used to build malicious PE files. The post references Detect It Easy and was posted on the SANS Internet Storm Center.
Intelligence Metadata - Source Publisher: SANS Internet Storm Center - Published Date: 2026-08-28T07:04:13+00:00 - Category: threat-intel
Original Description: During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware[1]. Can we go a bit further? I (vibe-)coded a Python script based on the pefile library[2] to extract some info from the PE headers. Indeed, the PE file format contains a lot of metadata! They can be accessed using a lot of tools, li...
"There never was a good knife made of bad steel."
— Benjamin Franklin