When comparing two malware samples, which observation indicates they are different variants of the same malware family rather than identical files?
Identical MD5 and SHA-256 hashes
Same file size and timestamp
Different PE file types (one EXE, one DLL)
Same section names, APIs, and strings but different hashes
This question is part of this quiz :
Cyber Quiz Day 46