The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Dropper detection

Prev Next

By default, the Intelligent Virtual Execution - Server appliance detects droppers in submitted malware samples. A dropper is a file that may have installed additional types of malware in your system. A dropper is not associated with any file extensions, and it is often part of a spearphishing attempt.

Dropper detection compares the hashes of submitted malware samples against a list of known MD5 checksums. If a file matches the first ten checksums, the detection feature identifies the file as a dropper. The Intelligent Virtual Execution - Server appliance sends the matched files to the Dynamic Threat Intelligence (DTI) cloud for further analysis.

The Intelligent Virtual Execution - Server appliance returns static analysis results to the originating sensor, where the information can be viewed at the Alerts > Alerts page of the sensor Web UI (or the Alerts > Web MPS > Alerts page of the Central Management System Web UI, if the sensor is under Central Management System management).