Soru

Zorluk: OrtaMalware Types and Indicators of Compromise

An endpoint detection and response telemetry report identifies an unapproved background process establishing persistence via a scheduled task named SystemHealthCheck. Memory inspection confirms the payload performs API hooking into explorer.exe to capture user credentials typed into web browsers and collect window titles, while establishing encrypted outbound connections to an external command-and-control server. Which of the following technical characteristics and malware classifications directly align with this observed incident? (Select TWO.)

  1. Spyware performing credential harvesting and active user activity monitoringCevap
  2. Persistence mechanism utilization via host system scheduling utilitiesCevap
  3. C
    Self-propagating worm capabilities leveraging network share vulnerabilities across subnets
  4. D
    Inline firewall protocol filtering as the primary remediation control for process memory injection

Cevap

The correct responses are the option identifying spyware credential harvesting and monitoring, and the option identifying persistence via scheduling utilities.
The scenario details keylogging and telemetry collection through API hooking in explorer.exe, which is characteristic of spyware. Additionally, using scheduled tasks to ensure execution across reboots represents host persistence.

Adım Adım Çözüm

1
Analyze the observed host telemetry capabilities.
Process memory hooking into explorer.exe to log keystrokes and capture application window titles maps directly to spyware and keylogger malware functionality.
Spyware gathers sensitive user input and telemetry silently without user authorization.
2
Identify host-level persistence indicators.
The creation of a OS scheduled task (SystemHealthCheck) ensures ongoing execution across system reboots.
Scheduled tasks are standard persistence vectors used by malware to survive system restart.
3
Evaluate and rule out incorrect malware classifications and remediation controls.
The telemetry does not demonstrate self-replicating subnet scanning (worm behavior), nor can an inline network firewall mitigate internal host memory injection.
Differentiating malware behavior and matching appropriate host endpoint controls prevents misdiagnosis.

Anahtar Kavram

Spyware Indicators of Compromise and Host Persistence
Bu soruyu puanla