• Home
  • Search
  • Malware Analysis and Static Call Graph Generation with Radare2
  • Cite Icon2
  • https://doi.org/10.24193/subbi.2023.1.01Copy DOI Icon

Malware Analysis and Static Call Graph Generation with Radare2

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

"A powerful feature used in automated malware analysis is the static call graph of the executable file. Elimination of sandbox environment, fast scan, function call patterns beyond instruction level information – all of these motivate the prevalence of the feature. Processing and storing the static call graph of malicious samples in a scaled manner facilitates the application of complex network analysis in malware research. IDA Pro is one of the leading disassembler tools in the industry and can generate the call graph via GenCallGdl and GenFuncGdl APIs – a tool which was used in our previous works. In this paper an alternative analysis method is presented using another disassembler tool, Radare2, an open-source Unixbased software, which is also frequently used in this domain. Radare2 has Python support (among other languages), via the r2pipe package, thus enabling full scalability on Linux-based servers using containerized solutions. This paper offers a detailed technical description on how to use Radare2 to generate the static call graph of a PE file and a thorough comparison with the output of IDA Pro, as well as a public dataset on which the experiments were carried out. 2010 Mathematics Subject Classification. 68P25, 68P30. 1998 CR Categories and Descriptors. D.4.6 [Security and Protection]: Subtopic – Invasive software. Key words and phrases. malware analysis, static call graph, radare2, IDA Pro."

Similar Papers
  • Research Article

Malware Analysis Education Meets LLMs: Understanding Student Use of LLMs in Malware Analysis Education

  • Jan 01, 2026
  • International Journal of Information and Education Technology
  • Orçun Çetin +1
  • Book Chapter
  • Citations4

An Improved Method to Unveil Malware’s Hidden Behavior

  • Jan 01, 2018
  • Qiang Li +5
  • Conference Article
  • Citations111

Identifying Dormant Functionality in Malware Programs

  • Jan 01, 2010
  • Paolo Milani Comparetti +5
  • PDF
  • Research Article
  • Citations5

ModDiff: Modularity Similarity-Based Malware Homologation Detection

  • May 16, 2023
  • Electronics
  • Huaqi Sun +3
  • PDF
  • Conference Article
  • Citations13

RapidVMI: Fast and multi-core aware active virtual machine introspection

  • Aug 17, 2021
  • Thomas Dangl +2
  • Conference Article
  • Citations3

Automated Malware Analysis Framework with Honeynet Technology in Taiwan Campuses

  • Dec 01, 2012
  • Yi-Lang Tsai +2
  • PDF
  • Research Article
  • Citations1

The use of simulation training module to train surgical residents in the focused assessment with sonography for trauma (FAST)

  • Jun 19, 2019
  • South-East Asian Journal of Medical Education
  • P. Shetty +2
  • Conference Article
  • Citations76

Graph Embedding Based Familial Analysis of Android Malware using Unsupervised Learning

  • May 01, 2019
  • Ming Fan +6
  • Conference Article
  • Citations24

Place-centric Visual Urban Perception with Deep Multi-instance Regression

  • Oct 19, 2017
  • Xiaobai Liu +4
  • Conference Article
  • Citations1

A PV-DM-based feature fusion method for binary malware clustering

  • May 27, 2022
  • Hairen Gui +3
  • Research Article
  • Citations1

Dual Channel Among Task and Contribution on OSS Communities: An Empirical Study

  • Aug 01, 2021
  • International Journal of Software Engineering and Knowledge Engineering
  • Yu Zhang +4
  • Research Article
  • Citations1

Two Trends in Mobile Malware: Financial Motives and Transitioning from Static to Dynamic Analysis

  • Mar 01, 2013
  • International Journal of Intelligent Computing Research
  • Emre Erturk
  • Research Article
  • Citations7

Open source map matching with Markov decision processes: A new method and a detailed benchmark with existing approaches

  • Oct 18, 2023
  • Transactions in GIS
  • Adrian Wöltche
  • Research Article
  • Citations1

The Application of Social Network Analysis to Economic and Regional Development: Tertiary Educational Attainment by Sex and Nuts 2 Regions

  • Aug 01, 2023
  • Studies in Business and Economics
  • Pagona Filenta +1
  • Research Article
  • Citations1

An Analysis of the Adoption of Open Source Software by Local Public Administrations: Evidence from the Emilia-Romagna Region of Italy

  • Jul 01, 2010
  • SSRN Electronic Journal
  • Francesco Rentocchini +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.