Problem
You perform an acquisition of a live computer system, which is infected with malware. You find a malicious file named malware.exe and you hash it. VirusTotal confirmed that the file is indeed malicious. Two minutes later the file is renamed to secret_malware.exe. You re-hash the file after the name has changed. Do you expect the hash to be different or the same? Why or why not?