What is a malicious file?¶
A malicious file is a file used to deliver, contain or support harmful or unauthorised activity.
Its filename and icon are only presentation. The useful evidence is the file's actual content, where it came from, how it moved through the system and whether anything opened, loaded or executed it.
One attachment can create several related copies¶
Imagine an email carrying Delivery note.zip. The archive contains a file displayed as Delivery note.pdf, but examination identifies executable content. A mail gateway stores one copy, the browser or mail application writes another into Downloads, and Microsoft Defender later moves matching bytes into quarantine.
Those locations may describe one delivery sequence rather than three separate attacks.
| Stage | Recognisable artefact | What it contributes |
|---|---|---|
| Email delivery | Native message, attachment name, Message-ID and attachment hash | Connects the file to the message and recipient |
| Saved or extracted copy | Path, actual format, size, hash and creation context | Shows where the content became available on the device |
| Security detection | Product event, action and result | Shows how the security tool classified and handled it |
| Process activity | Image path, hash, parent process and time | Tests whether that copy was launched |
| Later behaviour | Child processes, connections and changed files | Shows what followed execution |
The hash is a strong way to connect identical bytes across these records. It does not identify the author, controller or person who used the file.
Record the object before interpreting it¶
Preserve the original safely and retain:
- the full original name and path;
- actual file type as well as the visible extension;
- size and cryptographic hashes;
- relevant filesystem times and the system that supplied them;
- acquisition source and method;
- digital-signature information where present;
- security detections and actions; and
- links to the message, download, process or removable media that delivered it.
Do not rename, open or resave the evidential original merely to discover what it is. Work from an appropriately preserved copy using the authorised examination route.
File type, content and use answer different questions¶
A document, script, shortcut, library, installer or archive can all be malicious. A legitimate executable can also be copied or invoked as part of harmful activity.
This means three propositions should remain separate:
A misleading extension may explain why a person trusted the item, but it does not prove execution. A valid software signature may support origin and integrity, but it does not make every use authorised. The execution question still requires process, memory or resulting-system evidence.
Use the file to join the wider incident¶
A well-preserved file can provide useful pivots:
- the same hash in an email gateway, endpoint and quarantine record;
- an embedded URL or configuration value that appears in network records;
- a signer, build detail or internal name that helps compare related samples;
- a process path that joins the file to execution telemetry; and
- content or configuration that helps a specialist explain capability.
These links can establish delivery and relationships between artefacts even when the final human attribution remains open.
A sound account of a malicious file identifies the object, preserves where it came from and keeps delivery, execution and effect as separate findings. That makes the file useful evidence without asking its name, icon or antivirus label to prove more than it can.