ADAM PULSE Knowledge Base
Cybersecurity · Malware · File Analysis

What is malware, and how do you know if a file is malicious?

The short answer: Malware is software or code designed to perform unauthorized, harmful, intrusive, or destructive activity.

A suspicious file cannot always be judged by its filename, icon, extension, or even by whether one antivirus product detects it.

Modern malware detection combines multiple signals, including:

This is why one of the most interesting moments in the honeypot experiment was not simply that an attacker downloaded a file.

It was what happened next.

The file was examined.

Its structure suggested it was a Windows executable.

Its contents appeared intentionally difficult to analyze.

Its fingerprint was checked against malware detection services.

Multiple security engines identified it as malicious.

That gives us an important cybersecurity lesson:

> A suspicious file is evidence to investigate, not something to double click to see what happens.

And an equally important lesson:

> Malware detection is strongest when multiple independent signals tell the same story.

What Is Malware?

Malware is short for malicious software.

NIST describes malware as malicious code covertly inserted with the intent to destroy data, run destructive or intrusive programs, or otherwise compromise the confidentiality, integrity, or availability of data, applications, or operating systems.

Malware is not one specific type of program.

It is a broad category.

What Are the Main Types of Malware?

Common categories include:

A single malicious program may also perform several functions.

The categories are useful for understanding behavior, but malware does not always fit neatly into one box.

What Is a Computer Virus?

A computer virus is malicious code capable of attaching itself to other files or programs and spreading when those files execute.

People often use the word virus to describe all malware.

Technically, viruses are only one category.

What Is a Computer Worm?

A worm is malware capable of propagating across systems or networks, often with limited or no user interaction.

This distinction matters because worms can spread rapidly.

WannaCry became especially disruptive because its ransomware behavior was combined with wormlike propagation capabilities.

What Is a Trojan?

A Trojan disguises malicious functionality as something legitimate or desirable.

A user may believe they are installing:

A utility

An update

A document

A game

or

A business application

while malicious functionality is delivered alongside or instead of the expected program.

The name comes from the Trojan Horse story.

What Is Ransomware?

Ransomware is malware designed to deny access to systems or data, commonly through encryption or other disruptive mechanisms, while demanding payment or another action.

Modern ransomware incidents can involve more than encryption.

Attackers may also:

Ransomware should therefore be treated as an enterprise incident, not simply a file encryption problem.

What Is Spyware?

Spyware is software designed to collect information about users or systems without appropriate authorization.

Depending on the malware, it may seek:

The exact behavior varies.

What Is an Information Stealer?

Information stealing malware is designed to collect valuable information from compromised systems.

Potential targets may include:

This creates an important incident response issue.

Removing the malware may not invalidate credentials or tokens that were already stolen.

What Is a Remote Access Trojan?

A remote access Trojan, commonly called a RAT, can provide unauthorized remote control capabilities.

Depending on the malware and permissions, an attacker may be able to:

The malware essentially turns the victim's device into remotely controlled infrastructure.

What Is a Malware Downloader?

A downloader is malicious software or a script whose primary purpose is to retrieve additional malicious content.

The first malicious file may therefore not contain the entire attack.

Its job may simply be:

Get inside

↓

Connect outward

↓

Download the next stage

This is another reason incident responders investigate network connections after suspicious execution.

What Is a Dropper?

A dropper is malware designed to install or release another malicious payload onto a system.

Downloaders and droppers are related concepts, but a dropper may contain the payload itself while a downloader retrieves additional content from elsewhere.

Attack chains can involve multiple stages.

Why Would an Attacker Download Malware After Breaking Into a Server?

Initial access provides opportunity.

Malware can provide additional capabilities.

An attacker may download software for:

This is why defenders need to investigate both:

How did the attacker enter?

and

What did the attacker bring with them?

How Can You Tell Whether a File Is Malware?

There is no single universal test.

Security teams may examine:

Where the file came from

Who created it

Whether it is digitally signed

Its file type

Its cryptographic hash

Known reputation

Strings inside the file

Embedded resources

Code structure

What it does when executed

What systems it contacts

What files or registry settings it changes

Whether security engines detect it

The strongest conclusions often come from several signals together.

What Is Static Malware Analysis?

Static analysis examines a file without intentionally executing it.

Analysts may inspect:

Static analysis can reveal valuable information while reducing the risk associated with execution.

But sophisticated malware may deliberately hide useful information.

What Is Dynamic Malware Analysis?

Dynamic analysis observes what software does when executed in a controlled environment.

Analysts may watch for:

Dynamic analysis helps answer:

> What does this program actually do?

What Is a Malware Sandbox?

A malware sandbox is an isolated environment used to execute suspicious software while observing its behavior.

A sandbox may record:

The goal is to learn about the file without intentionally exposing ordinary production systems.

Should I Upload a Confidential File to a Public Malware Scanner?

Not automatically.

This is an extremely important business consideration.

Files submitted to third party analysis services may be handled according to that service's terms, privacy policies, sharing arrangements, and product configuration.

A suspicious file may contain:

Organizations should understand the service and their own data handling policies before submitting sensitive files.

> Security analysis should not accidentally become a data disclosure event.

What Is a File Hash?

A file hash is a value mathematically calculated from a file's contents.

Common hashing algorithms used in security contexts include SHA 256.

A hash can function like a digital fingerprint.

If two investigators calculate the same strong hash for the same file, they can use that value to refer to the exact file contents without exchanging the entire file.

Does a File Hash Tell You Whether a File Is Malicious?

No.

A hash itself does not declare:

safe

or

malicious.

It identifies file contents.

Security services can compare the hash with previously analyzed files and threat intelligence.

For example:

Hash

↓

Search reputation database

↓

Known malicious sample found

That is extremely useful.

But:

No match

does not mean

safe.

The file may simply be new or modified.

Why Can Malware Authors Change File Hashes?

Because even small modifications to a file can change its cryptographic hash.

MITRE ATT&CK documents techniques such as binary padding, where adversaries add data to alter a file's on disk representation. This can change the checksum while leaving functionality intact and may help avoid hash based blocklists or static signatures.

This creates a critical lesson:

> A file hash is excellent for identifying a known file. It is not a complete malware detection strategy.

What Is a Malware Signature?

A malware signature is a pattern or characteristic security software can use to recognize known malicious software.

Traditional antivirus products relied heavily on signatures.

Signatures remain valuable.

But attackers can modify malware to make exact matching more difficult.

Modern security therefore increasingly combines signatures with reputation, heuristics, machine learning, behavior, cloud intelligence, and endpoint telemetry.

What Does “66 Out of 72 Antivirus Engines Detected It” Mean?

Multi engine scanning services can compare a file or hash against results from multiple security vendors.

If many independent engines classify the same sample as malicious, that is strong evidence worthy of attention.

But the number should not be interpreted mechanically.

Different engines may:

The key is context.

Is One Antivirus Detection Enough to Prove Malware?

Not always.

False positives occur.

A legitimate administrative utility, uncommon program, newly compiled application, or unusual installer may occasionally trigger a security engine.

One detection should be investigated.

It should not automatically be treated as definitive proof without context.

What If 60 Antivirus Products Detect the Same File?

Confidence becomes much stronger when many reputable, independent detection engines identify the same sample as malicious.

But analysts should still examine:

Security decisions should use evidence rather than one isolated number.

Why Do Antivirus Vendors Give the Same Malware Different Names?

Malware naming is not perfectly standardized.

One vendor may classify a sample by:

Malware family

another by:

Behavior

another by:

Generic detection

and another by:

Campaign or variant.

Therefore, different names do not necessarily mean different files.

Analysts look for consensus across behavior and intelligence.

What Is Malware Obfuscation?

Obfuscation means making code or information harder to understand or analyze.

MITRE ATT&CK documents Obfuscated Files or Information as an adversary technique. Attackers may encrypt, encode, compress, archive, split, or otherwise transform payloads to make detection and analysis more difficult.

Why Do Malware Authors Obfuscate Code?

Because readable malicious code helps defenders.

Clear text might reveal:

Obfuscation can make those clues harder to identify through simple inspection.

Is Obfuscation Always Malicious?

No.

Legitimate software may use packing, compression, code protection, intellectual property protection, or minification.

Obfuscation is therefore a signal.

It is not proof.

Context matters.

What Is Software Packing?

Software packing transforms or compresses an executable so its original contents are reconstructed when the program runs.

Packing can have legitimate uses.

Malware authors can also use packing to make static inspection and signature detection more difficult.

MITRE ATT&CK includes software packing as a subtechnique of obfuscated files or information.

What Is Deobfuscation?

Deobfuscation is the process of reversing or decoding transformations so analysts or software can understand the hidden content.

MITRE ATT&CK separately documents adversary use of deobfuscation or decoding when malicious payloads need to be reconstructed or decoded on the target system.

Why Would Malware Be Encrypted or Encoded?

An attacker may want to hide recognizable strings or payloads while the file is:

The malicious program can later decode or decrypt the necessary content during execution.

This can frustrate simple static inspection.

Can Malware Hide Inside ZIP Files?

Yes.

Malicious files can be distributed through archives.

Attackers may use:

MITRE ATT&CK notes that adversaries may compress, archive, or encrypt payloads to reduce detection.

Why Are Password Protected Attachments Suspicious?

They are not automatically malicious.

Businesses legitimately use encrypted archives.

But attackers may also use password protected archives to prevent email security tools from easily inspecting the contents.

The correct response is not:

Password protected equals malware.

It is:

Unexpected protected attachment deserves context and caution.

Can Malware Pretend to Be a PDF?

A filename can be misleading.

Examples of deceptive naming might include:

invoice.pdf.exe

or a file displayed with an icon intended to resemble a document.

Operating systems and email clients may hide some file extensions depending on configuration.

Users should not rely solely on icons or visible filenames to determine file type.

What Is a File Extension?

The file extension is the suffix after a filename, such as:

.pdf

.docx

.xlsx

.exe

.zip

It provides information about the intended file type.

But extensions can be renamed.

Security tools can inspect the actual internal file structure rather than trusting the filename alone.

What Is a Windows PE File?

PE stands for Portable Executable.

It is a file format used by Windows for executable programs and related binary files.

Malware analysts may inspect PE headers and structures to understand suspicious Windows executables.

A file identified as a Windows executable does not automatically mean it is malicious.

It means analysts now know what type of file they are examining.

Can Windows Malware Infect Linux?

This question needs nuance.

A Windows executable generally cannot simply execute natively on an ordinary Linux environment in the same way it executes on Windows.

But a Linux server can still:

So finding Windows malware on a Linux server may indicate that the server is being abused as infrastructure even if the payload cannot directly infect that Linux host in its current form.

This is a fascinating lesson from the honeypot experiment:

> A compromised server can be useful to an attacker even when the malware found on it was intended for somebody else.

Why Would an Attacker Put Windows Malware on a Linux Server?

Possibilities include:

Attack automation is not always elegant.

Bots can make mistakes.

That does not make the broader compromise harmless.

What Is a False Positive?

A false positive occurs when a security system identifies legitimate activity as malicious or suspicious.

False positives matter because defenders cannot treat every alert as proof.

Good security operations investigate context.

What Is a False Negative?

A false negative occurs when malicious activity is not detected.

This is potentially more dangerous because defenders may believe everything is safe.

Every security tool has limitations.

That is why layered detection matters.

Can Antivirus Detect Every Malware File?

No.

Security products are valuable, but no detection technology is perfect.

Malware can be:

NIST recommends a layered approach to malware prevention and incident handling rather than reliance on a single control.

What Is Behavioral Malware Detection?

Behavioral detection focuses on what software does rather than only what the file looks like.

Potential behaviors might include:

Behavior can remain suspicious even when the malware file itself changes.

Why Is Behavior So Important?

Imagine an attacker modifies a malware file enough to create a completely new hash.

Hash based detection may no longer recognize it.

But the new file still:

Creates the same persistence

Contacts the same type of infrastructure

Attempts credential theft

Disables security tools

Behavioral monitoring provides another opportunity for detection.

What Is EDR?

EDR stands for Endpoint Detection and Response.

EDR platforms monitor activity on endpoints and provide telemetry that can help identify, investigate, and respond to suspicious behavior.

Capabilities vary by vendor, but may include:

Traditional antivirus and EDR overlap in modern products, but the terms describe different historical and operational approaches.

Is EDR the Same as Antivirus?

Not exactly.

Traditional antivirus historically focused heavily on identifying malicious files.

EDR emphasizes ongoing endpoint visibility, behavior, investigation, and response.

Modern security products often combine both.

The important question is not the label.

It is:

What can the organization detect, investigate, contain, and verify?

What Is XDR?

XDR generally stands for Extended Detection and Response.

The concept extends detection and correlation across multiple security data sources, potentially including:

Capabilities and definitions vary by vendor.

The goal is broader context.

What Is a SIEM?

SIEM stands for Security Information and Event Management.

A SIEM collects and analyzes security related logs and events from multiple systems.

Potential sources include:

SIEM can help correlate evidence that would otherwise remain isolated.

Why Does Network Monitoring Matter in Malware Detection?

Malware often communicates.

It may:

Endpoint monitoring asks:

What is happening on the device?

Network monitoring asks:

Who is the device communicating with, and how is network behavior changing?

Both perspectives can be valuable.

What Is an Indicator of Compromise?

An indicator of compromise, or IOC, is evidence associated with potentially malicious activity.

Examples include:

IOCs help defenders search environments for known evidence.

But attackers can change indicators.

What Is a TTP?

TTP stands for:

Tactics

Techniques

and

Procedures.

Instead of focusing only on a particular malware hash, defenders can study attacker behavior.

For example:

Malware hash changes

but

the attacker still creates persistence

still disables security tools

still performs discovery

still contacts command infrastructure.

MITRE ATT&CK organizes many adversary behaviors into tactics and techniques.

IOC vs. TTP: Which Is Better?

Both are useful.

An IOC can be precise:

Find this exact malicious hash.

A TTP can be durable:

Find systems exhibiting this suspicious behavior.

Strong security operations use both.

What Should You Do With a Suspicious File?

Do not casually execute it.

A business process may include:

  1. Preserve the file safely.
  2. Record where it came from.
  3. Record who received or downloaded it.
  4. Capture relevant email, web, endpoint, or server context.
  5. Calculate a hash where appropriate.
  6. Check approved threat intelligence sources.
  7. Use authorized security tooling.
  8. Analyze it in an isolated environment if necessary.
  9. Determine whether it executed.
  10. Identify affected systems.
  11. Contain confirmed compromise.
  12. Investigate related activity.

Qualified security personnel should handle significant malware investigations.

Why “Did Anyone Open It?” Is Such an Important Question

Finding a malicious file and executing a malicious file are different events.

If malware arrived by email but was never executed, the response may differ from a situation where:

User opened attachment

↓

Malware executed

↓

Credentials stolen

↓

Persistence established

↓

Other systems accessed

Incident scope depends on what actually happened.

Does Deleting the Malware File Fix the Problem?

Not necessarily.

If the file already executed, it may have:

Deleting the original file may remove only one artifact.

Should You Trust a Computer After Malware Runs on It?

That depends on the malware, privileges, system role, available evidence, and response capabilities.

For serious compromise, organizations may decide that rebuilding from a known trusted state provides greater assurance than attempting to manually undo every malicious change.

This decision should be made by qualified incident response personnel.

Where USA Telecom and ADAM Fit

USA Telecom and ADAM are not replacements for antivirus, EDR, XDR, SIEM, malware sandboxes, digital forensics, or threat intelligence platforms.

The value can sit in the operational context surrounding security events.

A malware incident may coincide with:

Unexpected device outage

Unusual bandwidth

VPN disruption

Firewall changes

Unexpected outbound communication

Location connectivity changes

Service degradation

Security tooling may identify a malicious process.

Operational monitoring can help answer:

What happened to the business service around the same time?

Security Detection Is Stronger When Signals Connect

Imagine:

Endpoint security: Suspicious executable detected.

Threat intelligence: File hash known as malicious.

Network security: Device contacted suspicious infrastructure.

Identity: Unexpected privileged authentication occurred.

Network monitoring: Location began behaving abnormally.

Ticketing: No approved maintenance exists.

Individually, each signal is useful.

Together, they create a much clearer incident narrative.

> Cybersecurity becomes more useful when alerts become context.

25 Malware Questions Every Business Should Ask

  1. Do we have endpoint security on supported computers and servers?
  2. Are endpoint security tools centrally managed?
  3. Would we know if endpoint protection stopped reporting?
  4. Can users disable security software?
  5. Are malware alerts centrally reviewed?
  6. Who investigates suspicious files?
  7. Do we preserve suspicious files and relevant evidence safely?
  8. Do we know whether a malicious file actually executed?
  9. Can we identify which user executed it?
  10. Can we identify which systems received the same file?
  11. Can we search for a known malicious hash?
  12. Can we identify suspicious outbound connections?
  13. Do endpoint and firewall logs share enough context?
  14. Do we monitor DNS activity where appropriate?
  15. Can we isolate a compromised endpoint?
  16. Are administrator privileges restricted?
  17. Are operating systems and applications patched?
  18. Are unsupported systems still in production?
  19. Are email attachments inspected appropriately?
  20. Are users trained to report suspicious files?
  21. Do we have a safe malware analysis process?
  22. Do we understand the privacy implications of public file scanning services?
  23. Can we rebuild a seriously compromised system from a trusted state?
  24. Are backups protected from malware and ransomware?
  25. Can we correlate malware alerts with identity and network activity?

The Better Question Is Not “Did Antivirus Catch It?”

Ask:

Where did the file come from?

What is it actually?

Has anyone seen this exact file before?

What do multiple security engines say?

Is it obfuscated or packed?

What happens if it executes?

Did it already execute?

What systems did it contact?

What did it change?

Did it establish persistence?

Were credentials exposed?

Did it move elsewhere?

That is malware investigation.

Key Takeaway

The suspicious file in the honeypot story creates one of the most useful cybersecurity teaching moments in the entire series.

A file appeared on the server.

Instead of simply opening it, the investigator examined it.

The file type provided context.

Its structure provided clues.

Its fingerprint could be compared with known intelligence.

Multiple security engines provided additional evidence.

Its obfuscation provided another clue about why analysis could be difficult.

That is how defenders should think.

Not:

One tool says bad, therefore panic.

And not:

One tool says clean, therefore safe.

Instead:

Collect evidence.

Correlate signals.

Understand behavior.

Determine whether execution occurred.

Investigate the surrounding system and network activity.

NIST describes malware as a major external threat to hosts and recommends layered prevention and incident response capabilities. MITRE ATT&CK documents how adversaries deliberately obfuscate files and information to make detection and analysis more difficult.

The business lesson is:

> A malicious file is rarely just a file problem. It can be the beginning, middle, or evidence of a much larger incident.

And the operational lesson is:

> Do not only ask whether security software found malware. Ask what happened before it arrived, what happened after it arrived, and what else changed.

Frequently asked questions

What is malware?

Malware is malicious software or code intended to perform unauthorized, intrusive, destructive, or harmful activity.

What are the main types of malware?

Common categories include viruses, worms, Trojans, ransomware, spyware, information stealers, remote access malware, downloaders, droppers, rootkits, cryptominers, and bot malware.

What is a computer virus?

A virus is malicious code capable of attaching itself to other files or programs and spreading through execution.

What is a worm?

A worm is malware capable of propagating between systems or across networks, often with limited user interaction.

What is a Trojan?

A Trojan disguises malicious functionality as legitimate or desirable software or content.

What is ransomware?

Ransomware is malware designed to deny access to systems or data, commonly through encryption or other disruptive mechanisms, often accompanied by extortion.

What is spyware?

Spyware is software designed to collect information without appropriate authorization.

What is an information stealer?

An information stealer is malware designed to obtain credentials, tokens, cookies, wallets, or other valuable information.

What is a malware sandbox?

A sandbox is an isolated environment used to execute suspicious software and observe its behavior.

What is static malware analysis?

Static analysis examines a suspicious file without intentionally executing it.

What is dynamic malware analysis?

Dynamic analysis observes what a program does when executed in a controlled environment.

What is a file hash?

A file hash is a mathematical fingerprint calculated from file contents.

Does a hash tell me whether a file is malicious?

No. It identifies the file. Reputation and threat intelligence services can determine whether that hash has previously been associated with malware.

Can malware change its hash?

Yes. Small file modifications can produce a different hash.

What is malware obfuscation?

Obfuscation makes malicious code or information more difficult to understand, inspect, or detect.

Why do hackers obfuscate malware?

To make analysis and detection more difficult.

Is an obfuscated file automatically malware?

No. Legitimate software can also use packing and code protection. Context is required.

Can antivirus detect every virus?

No security product detects every malicious file or behavior.

What does multiple antivirus detections mean?

Many reputable engines detecting the same file can provide strong evidence, but results should still be interpreted with context.

What is a false positive?

A false positive is legitimate activity incorrectly identified as malicious.

What is a false negative?

A false negative is malicious activity that a security system fails to detect.

Is EDR the same as antivirus?

Not exactly. EDR emphasizes endpoint telemetry, behavioral detection, investigation, and response, while traditional antivirus historically focused more heavily on malicious file detection.

Can Windows malware exist on a Linux server?

Yes. A Linux server can store, host, relay, or distribute a Windows malicious executable even if that executable does not run natively in the ordinary Linux environment.

Does deleting a malware file remove the infection?

Not necessarily. Malware may have already created persistence, stolen credentials, downloaded additional payloads, or modified the system.

Should I upload suspicious business files to public scanning websites?

Only after understanding the service's data handling policies and your organization's confidentiality, privacy, contractual, and regulatory obligations.

Sources

Editorial note

Cybersecurity risk and the controls appropriate to it vary by organization. Evaluate these recommendations against your own technology environment, business requirements, regulatory obligations, threat profile and risk tolerance.

USA Telecom Consulting LLC is a Service-Disabled Veteran-Owned Small Business running a 24/7 NOC. We monitor networks, circuits and firewalls for regulated and defense-supply-chain organizations.

← More from the ADAM Pulse Knowledge Base