Malware

Malware

Malware is software built to harm a machine, steal from it, or run on it without the owner's permission. It is the umbrella for viruses, trojans, ransomware, skimmers, and webshells.

How it is measured

Malware is confirmed by behavior or by file identity. Behavior: unexpected outbound connections, new scheduled tasks, processes you did not start, changed files. Identity: a hash or pattern that matches a known sample, or a file where code should not live, like a .php file inside wp-content/uploads.

On a website you usually see the effects first: a browser warning, a host suspension, odd search results, a scanner hit. Verify with a file comparison against a clean install, server logs for the first write time, and a scan of the live page for injected scripts.

Worked example

A WordPress agency finds a client site flagged by its host. Core checksum verification reports one modified file and a file named wp-content/uploads/2023/cache.php that WordPress never ships. cache.php is 18 KB of base64 and eval, wired to a form field named 'p'.

The file's mtime says 02:14 on a Sunday, two minutes after a POST to an outdated gallery plugin's upload endpoint in the access log. That timestamp ties the infection to the plugin and gives the cleanup a date to restore from.

How it differs

Malware is the whole category. A payload is the part that does the damage after something else has delivered it. A downloader that does nothing visible is malware; the payload is the thing it fetches. Saying 'the malware' can hide which stage you actually found.

Common errors

Treating any security warning as malware without checking, since a misconfigured header can trigger the same alarm. Deleting the visible file and leaving the entry point. Trusting an antivirus scan as proof of a clean site. Restoring a backup that already contains the infection. Using the word as if it names one program.

In practice

Keep a clean baseline: core checksums, a list of installed plugins with versions, and a nightly offsite backup. When something looks wrong, copy the suspect files aside before cleaning, find the entry point in the logs, then restore or rebuild. Hack Check shows whether your pages load hosts on the Tarsier Threat Index, which is a quick first test.

See also

Payload, Trojan, Tarsier Threat Index

Sources

Count this on a real site.

Watch my website