Skip to content

Analyze an EXE or DLL in Your Browser, Without Running It

Step-by-step static triage of Windows executables with the free PE Parser: load files or a ZIP, read indicators, compare builds and export results.

Published on Updated on 4 min read

TL;DR. The PE Parser reads Windows executables the way pestudio, PE-bear or Detect It Easy do — headers, imports, resources, signature, strings — but in a browser tab, for a whole batch at once, and without uploading or running anything. Here is a 15-minute triage using the built-in synthetic sample.

Step 1: Load the files

Open the home page and drop your files, a folder or a ZIP. Executables are recognised by their MZ header, so a payload renamed .dat is still found. Each file is parsed by Rust code compiled to WebAssembly in its own Web Worker: nothing leaves the machine and nothing is executed. To follow along, click Try a sample: five harmless files from a fictional intrusion — two builds of m64.exe, a signed m64core.dll and a small .NET SyncConfig.exe, whose code is a single ret, plus wupd.exe, a real UPX-packed build of a program that only prints a greeting.

Step 2: Scan the batch table

The workspace opens full screen (Esc to leave). The table shows one row per file: type, compile time, size, imphash, indicator counts and detections. Sort by Worth a look. The two m64.exe builds share an imphash and are labelled family 1 — the same tool built twice, nine days apart (imphash and friends).

With several files loaded, the time range bar filters by compile, debug or signing time; the density strip shows when the files were built, and the range is kept in the page URL so a link reopens the same view.

Step 3: Open a file and read its indicators

Click C/ProgramData/Intel/m64.exe. The overview shows identity (x64, GUI, entry point in .text), hashes with copy buttons, the PDB path C:\build\m64\Release\m64.pdb, and the times. The banner counts high and medium indicators. The Indicators tab explains each one — imported injection APIs, a UPX1 section that is writable and executable with entropy near 8, a TLS callback, 4 KB appended after the last section, OriginalFilename = synchelper.exe on a file named m64.exe. Every item says why it is worth a look and when it is normal.

Step 4: Check signature, sections and imports

  • Sections: permissions, raw and virtual sizes, entropy bar per section (detecting packed executables).
  • Imports: per DLL, with behaviour tags; WS2_32.dll ordinal 115 is shown as WSAStartup.
  • Resources: version information, manifest, icon, string table, dialog captions.
  • Strings: ASCII and UTF-16 with offsets and categories — the sample holds documentation-range IP addresses, .example URLs, a Run key path and a harmless Base64 PowerShell string decoded to Write-Output 'synthetic sample'.
  • Signature: open m64core.dll. The hash matches, the signed attributes match and the RSA signature verifies — but the certificate is self-signed, so it identifies nobody (Authenticode offline).
  • Payloads: open wupd.exe. It is packed with UPX, so the tool decompresses it as data (nothing runs) and adds wupd.exe!upx, the rebuilt program, with its real imports and compiler. Its overlay also hides a XOR-encoded DLL: the Payloads tab shows it is m64core.dll, byte for byte — the dropper and what it dropped, linked.
  • Headers & directories: raw DOS, COFF and optional header fields, data directories, Rich header entries decoded to Visual Studio releases, debug, TLS, load configuration and relocations.

The Compare view puts two files side by side: header fields, sections (same, changed, only in one), imports, exports and resources, plus the TLSH distance. The two m64.exe builds have identical imports and different code and data.

Step 6: Export

The Export menu offers an inventory CSV (hashes, times, signer, indicators; formula-injection safe), the full JSON report, a sha256sum-style list for intelligence lookups, imports and exports, and strings. Exports follow the current view and time range, and the range appears in the file names.

The tool is static: it unpacks UPX itself, but other packers have to be unpacked elsewhere, certificate chains are not validated, and indicators are pointers, not verdicts.

Related articles

What matters in a Windows PE file when you triage a suspicious EXE, DLL or driver: headers, sections, imports, resources, signature and overlay.
Find and copy suspicious EXE, DLL and SYS files from a Windows host or image without running them: PowerShell, Velociraptor, disk images and pitfalls.
Where a Windows executable stores its times, which ones can be trusted, how reproducible builds and timestomping show up, and how to use them.