An endpoint detection and response telemetry report identifies an unapproved background process establishing persistence via a scheduled task named SystemHealthCheck. Memory inspection confirms the payload performs API hooking into explorer.exe to capture user credentials typed into web browsers and collect window titles, while establishing encrypted outbound connections to an external command-and-control server. Which of the following technical characteristics and malware classifications directly align with this observed incident? (Select TWO.)
- Spyware performing credential harvesting and active user activity monitoringCevap
- Persistence mechanism utilization via host system scheduling utilitiesCevap
- CSelf-propagating worm capabilities leveraging network share vulnerabilities across subnets
- DInline firewall protocol filtering as the primary remediation control for process memory injection
Cevap
The correct responses are the option identifying spyware credential harvesting and monitoring, and the option identifying persistence via scheduling utilities.
The scenario details keylogging and telemetry collection through API hooking in explorer.exe, which is characteristic of spyware. Additionally, using scheduled tasks to ensure execution across reboots represents host persistence.
Adım Adım Çözüm
Anahtar Kavram
Spyware Indicators of Compromise and Host Persistence