A security analyst reviews host logs and process telemetry from an endpoint suspected of infection. The analyst notices unauthorized background screen captures being saved to a hidden directory and outbound HTTP POST requests transmitting encrypted archives to an unrated external IP address on port 443. Which of the following malware classifications and primary capabilities are indicated by these observed technical artifacts? (Select TWO.)
- Spyware functioning to monitor user activity and gather sensitive data without authorizationAnswer
- Command and control exfiltration mechanisms delivering captured data to remote attacker infrastructureAnswer
- CA self-propagating worm exploiting local network vulnerabilities to infect neighboring hosts
- DInline firewall filtering rules blocking unauthorized incoming network traffic
Answer
The observed indicators demonstrate spyware capabilities monitoring endpoint activity (capturing screen state) alongside command and control data exfiltration mechanisms transferring collected archives outbound over HTTP POST.
The combination of covert background screen captures and outbound encrypted POST traffic aligns directly with spyware monitoring behavior combined with command and control data exfiltration capabilities.
Step-by-Step Solution
Key Concept
Spyware telemetry and command and control exfiltration indicators of compromise