Malware
File hash
Also called SHA-256, MD5.
File hash is a fixed-length fingerprint computed from a file's bytes. Change one byte and the hash changes completely, so it identifies an exact file.
How it is measured
Run `shasum -a 256 file` or an equivalent. SHA-256 gives a 64-character hex string; MD5 gives 32 but is weak against deliberate collisions. Compare the result against a known-good value from the vendor or against a known-bad value from a threat report.
Hashes match only identical files. A malware author who recompiles or adds one byte creates a new hash, so a hash match tells you something is known, not that something unknown is safe.
Worked example
A WordPress admin downloads `contact-form-7.5.9.zip` from the plugin repository and wants to check a server copy. She hashes `wpcf7-admin.js` on the server and gets a value that does not match the file in the fresh download. A diff shows an extra line that loads a script from a strange host.
The same hash is later found in a public report of a plugin-injection campaign, which confirms the infection.
How it differs
A file hash names one exact file. An indicator of compromise is any evidence of an attack, and a hash is only one kind; domains, IPs, and registry keys are others. YARA rules match patterns inside files, so they catch variants that a hash misses. A hash is precise but brittle; a rule is flexible but riskier.
Common errors
Using MD5 as proof of authenticity. Assuming a different hash means a different malware family. Comparing hashes of files taken from different versions. Forgetting that packed or recompiled samples have new hashes. Pasting a hash into a tool and treating no result as clean.
In practice
For the core of your CMS and each plugin, keep or fetch official checksums and compare against the server. Verify any download you install by hash when the vendor publishes one. Treat a mismatch as an event to investigate, not a quirk.