Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a malicious file?

A malicious file is a file used to deliver, contain or support harmful or unauthorised activity.

Its filename and icon are only presentation. The useful evidence is the file's actual content, where it came from, how it moved through the system and whether anything opened, loaded or executed it.

Imagine an email carrying Delivery note.zip. The archive contains a file displayed as Delivery note.pdf, but examination identifies executable content. A mail gateway stores one copy, the browser or mail application writes another into Downloads, and Microsoft Defender later moves matching bytes into quarantine.

Those locations may describe one delivery sequence rather than three separate attacks.

Stage Recognisable artefact What it contributes
Email delivery Native message, attachment name, Message-ID and attachment hash Connects the file to the message and recipient
Saved or extracted copy Path, actual format, size, hash and creation context Shows where the content became available on the device
Security detection Product event, action and result Shows how the security tool classified and handled it
Process activity Image path, hash, parent process and time Tests whether that copy was launched
Later behaviour Child processes, connections and changed files Shows what followed execution

The hash is a strong way to connect identical bytes across these records. It does not identify the author, controller or person who used the file.

Record the object before interpreting it

Preserve the original safely and retain:

  • the full original name and path;
  • actual file type as well as the visible extension;
  • size and cryptographic hashes;
  • relevant filesystem times and the system that supplied them;
  • acquisition source and method;
  • digital-signature information where present;
  • security detections and actions; and
  • links to the message, download, process or removable media that delivered it.

Do not rename, open or resave the evidential original merely to discover what it is. Work from an appropriately preserved copy using the authorised examination route.

File type, content and use answer different questions

A document, script, shortcut, library, installer or archive can all be malicious. A legitimate executable can also be copied or invoked as part of harmful activity.

This means three propositions should remain separate:

IdentityWhat are these bytes?Format, hash, signature and analysis describe the object.
DeliveryHow did it arrive?Email, browser, removable media, remote session or another process.
UseWhat happened to it?Saved, extracted, loaded, executed, blocked or deleted.

A misleading extension may explain why a person trusted the item, but it does not prove execution. A valid software signature may support origin and integrity, but it does not make every use authorised. The execution question still requires process, memory or resulting-system evidence.

Use the file to join the wider incident

A well-preserved file can provide useful pivots:

  • the same hash in an email gateway, endpoint and quarantine record;
  • an embedded URL or configuration value that appears in network records;
  • a signer, build detail or internal name that helps compare related samples;
  • a process path that joins the file to execution telemetry; and
  • content or configuration that helps a specialist explain capability.

These links can establish delivery and relationships between artefacts even when the final human attribution remains open.

A sound account of a malicious file identifies the object, preserves where it came from and keeps delivery, execution and effect as separate findings. That makes the file useful evidence without asking its name, icon or antivirus label to prove more than it can.

Technical sources - checked 27 September 2026
Reference: CIM-062Cyber Incidents & Offender Methods