What is malware?¶
Malware is software or code used for unauthorised, harmful or deceptive activity.
It may steal information, give remote control, persist on a system, encrypt files, disrupt services or abuse computing resources.
For an investigation, the useful questions are not simply “is this malware?” but:
Was it present, did it run, what did it actually do, and what evidence did that behaviour create?
Malware labels often overlap¶
Terms such as:
- Trojan;
- spyware;
- downloader;
- ransomware;
- backdoor;
- infostealer
may describe purpose, behaviour or delivery rather than mutually exclusive categories.
One sample can fit several labels.
Separate presence, execution and effect¶
A simple model is:
A malicious file can be present without ever executing.
What evidence might you see?¶
Useful sources can include:
- file path and hash;
- download/source information;
- process and parent process;
- command line;
- memory;
- network connections;
- persistence changes;
- registry/configuration changes;
- files accessed or modified;
- security-tool telemetry;
- specialist malware analysis.
Capability is not the same as observed behaviour¶
A specialist may determine that the malware can steal browser credentials.
That does not prove the function ran successfully in this incident.
Likewise, execution does not prove every capability succeeded.
Malware is not the only way attackers operate¶
Legitimate administration tools, scripts and built-in system utilities can also be misused.
Absence of a traditional malware file does not mean there was no malicious activity.
Does finding malware prove it was executed? is the natural next step.
The practical point is: describe malware through supported presence, execution and observed behaviour. Product labels and theoretical capability are useful context, but the incident evidence should show what actually happened.