Skip to main content
Tutorials5 min read• July 2024

Why Extension Names Lie: Understanding Magic Bytes & Raw Header Inspection

David Chen
David Chen
Systems Security Architect & Threat Forensics Researcher
File extensions like .jpg or .pdf are merely hints for desktop operating systems. Attackers and malware authors frequently trick users by renaming malicious executable binaries (.exe) to innocent document extensions (.pdf or .jpg). To reliably detect what a file actually is, operating systems, security scanners, and AnyFileX read the first 4 to 32 bytes of the file—known as **Magic Bytes** or **File Signatures**. ### Examples of Common Magic Byte Signatures: - **PDF Documents**: `25 50 44 46 2D` (`%PDF-`) - **PNG Images**: `89 50 4E 47 0D 0A 1A 0A` (`PNG`) - **ZIP Archives**: `50 4B 03 04` (`PK..`) - **Windows Executables (EXE/DLL)**: `4D 5A` (`MZ`) When you upload a file to AnyFileX's File Identifier, our WebAssembly engine checks these magic bytes directly in your browser memory, guaranteeing accurate format detection regardless of file name.