What distinguishes static malware analysis from dynamic execution?
It deletes the file before collecting any evidence.
It runs the sample directly on a production host.
It observes only live network connections from the malware.
It examines file properties, structure, and embedded content without running the sample.