Some of these kind of malwares only appear to be a legit program .exe when they try to connect.

The real source could be in the Registry or in a legit .dll file that Windows uses, where all it needs is a pointer or two to wreak its havoc.

Therefore, binary compare would not work, as both files would be identical.


--Mac