Malware

Payload

Payload is the harmful part of an attack: the code that steals, encrypts, mines, or opens access after the delivery step is done. Whatever got it onto the machine is only the courier.

How it is measured

Separate the stages when you analyze an incident. The delivery: phishing mail, injected script, vulnerable upload. The dropper or loader that fetches things. Then the payload, which you identify by what it does: file encryption, card capture, credential theft, a webshell you can talk to.

Find it by following the chain. The loader's network request, file writes, and scheduled jobs usually point to the payload's location. Record its hash, size, path, and first-seen time, and keep a sample for analysis.

Worked example

An accountant opens invoice.docm. A macro runs a PowerShell one-liner that downloads a 312 KB file named update.dat from a compromised blog and saves it to AppData. The macro and the one-liner are dropper stages; update.dat decodes to an info-stealer that reads browser-saved logins.

The responder notes three artifacts: the document, the script, the stealer. Removing the document does nothing; the stealer is already running as a scheduled task. The passwords saved in the browser are what need rotating.

How it differs

A dropper delivers and installs something; the payload is the thing delivered. A loader may fetch a different payload next week without changing itself. Removing the dropper leaves a payload that is already running, and removing the payload leaves a dropper that can fetch another.

Common errors

Calling the first-stage script the whole infection. Cleaning the payload while leaving the persistence that reinstalls it. Assuming the payload is the same for every victim, when operators often tailor it. Reading a scanner's 'trojan' label as proof of what the payload does. Deleting without saving a sample.

In practice

In any cleanup, write down each stage separately: how it arrived, what ran, what persists, and what data it could touch. Revoke the credentials the payload could read, not just the file it left. Keep the sample so you can search other systems for it.

See also

Dropper, Loader, Malware

Sources

Count this on a real site.

Watch my website