Static Malware Analyzer
Run Malware analysis on our infrastructure so you don't have to scan it locally!
The Malware Analyzer performs static malware checks on files that you upload. Upload a file and receive a threat report covering static malware analysis, including checking for malicious strings, running our yara data set against the file, checking for inconsistent file entropy, and checking for executable packing.
What It Analyzes
- File Type Detection — Checks if the file extension matches the magic bytes detected in the file for file type identification.
- Yara Rule Match Scan — Checks for Yara matches leveraging our internal database of yara rules.
- IOC Extraction — Extracts common IOCs (IP addresses, emails, URLs, encoded strings). NOTE: THIS IS NOISY AND NOT INCLUDED IN OUR COMPLETE SCAN, PLEASE USE EXPLICITLY.
- Entropy Analysis — Detects potentially embedded code by checking for differences in randomness throughout the file.
- Malicious String Detection - Checks for common malicious strings leveraged in malware (NOTE: MAY BE NOISIER THAN RUNNING OUR STANDARD YARA RULE SET)
- Portable Executable Section Analysis - Checks for code packing in portable executables.
How to Use
- Navigate to the Static Malware Analyzer page.
- Drag and drop a file onto the upload area, or click "Select File" to browse.
- Select which explicit checks you would like to run, or if you select nothing it will run all checks.
- Review the file name in the confirmation area, then click Submit for Analysis.
- Once processing completes, click View Report to see the full threat analysis, or find it in your Account Overview.
File Requirements (SAAS only restriction) — Maximum file size: 4.5 MB.
How to Use - API
This API is designed to be plugged in to automation tools to allow for automatic static malware threat analysis. Please note, there is a limit of 600 requests in a 10 minute period for your acount.
- Ensure you have provisioned an API key
- Leverage the /runs endpoint to submit your request. This will be a POST request using form data for the request data including the file. A sample curl command is provided below. Please note, if you want to check the cost of running the tool, you would include checkCost=true. This flag will make it so the analysis does not run and only the cost of the run is returned.
The sub-check flags may be passed individually to only run those specific checks. If no flags are passed then all checks are run except for IOC extraction.
curl --location 'https://dapi.bluelanternsecurity.io/runs' \
--header 'Authorization: [YOUR API KEY]' \
--form 'tool="STATICMALWAREANALYZER"' \
--form 'checkCost="false"' \
--form 'file=@"[YOUR FILE]"' \
--form 'check_malicious_strings="True"' \
--form 'check_extract_iocs="True"' \
--form 'check_sections="true"' \
--form 'check_yara="true"' \
--form 'check_entropy="true"'
- After submission you will be provided a job ID that you will use in the subsequent call to fetch the results data. The jobID response will look as follows:
{
"message": "Requested Analysis Job Created",
"result": {
"jobId": "[JOB ID HERE]"
}
}
- The following curl request (after analysis is completed in approx. 30 seconds) will look as follows:
curl --location 'https://api.bluelanternsecurity.io/results' \
--header 'Content-Type: application/json' \
--header 'Authorization: [YOUR API KEY]' \
--data '{
"jobId":"[YOUR JOB ID]"
}'
- The results will look as follows (IOC section redacted for size):
{
"message": "results retrieved",
"result": {
"job_id": "[YOUR JOB ID]",
"filename": "[YOUR FILE NAME]",
"analyzed_at": "2026-03-17T16:19:49.775451+00:00",
"status": "Completed",
"Status": 200,
"results": [
{
"file": "[TMP FILE NAME]",
"file_size": 85768,
"file_type": null,
"yara_matches": [],
"malicious_strings": {
"strings_count": 1431,
"ascii_strings_count": 1431,
"utf16_strings_count": 0,
"red_flags": {}
},
"extract_iocs": {
"strings_count": 1431,
"ascii_strings_count": 1431,
"utf16_strings_count": 0,
"classified_strings": {
...
}
},
"sections": null,
"whole_file_entropy": 5.17,
"checks_enabled": [
"entropy",
"extract-iocs",
"malicious-strings",
"sections",
"yara"
],
"total_cost": 22
}
]
}
}