Soru

Zorluk: ZorMalware Types and Indicators of Compromise

A security technician investigating an isolated endpoint alert reviews host telemetry and memory capture files. The triage report indicates that a persistent process executing from `%APPDATA%` invokes the system API `SetWindowsHookEx` to intercept keystrokes, while simultaneously establishing an encrypted reverse shell back-connect over TCP port 443 to a remote host. The process modifies system registry run keys for boot persistence, but shows no network scanning or self-replication capabilities across local SMB shares. Which of the following malware classifications and technical indicators accurately describe this malicious activity? (Select TWO.)

  1. The threat exhibits Remote Access Trojan (RAT) behavior by establishing an outbound reverse shell for remote interactive control.Cevap
  2. The host telemetry reveals keylogger functionality through the application API hook designed to capture user keystrokes.Cevap
  3. C
    The malware operates as a self-propagating network worm by actively exploiting SMB service vulnerabilities across adjacent subnets.
  4. D
    Implementing network perimeter firewall blocking rules will fully eradicate the persistent malware artifact from the infected host.

Cevap

The threat is characterized by Remote Access Trojan (RAT) behavior due to its reverse shell capability, and keylogger functionality indicated by the API hook for keystroke interception.
The scenario highlights two distinct behaviors: establishing an interactive reverse shell (which identifies a Remote Access Trojan) and leveraging input hooking APIs like SetWindowsHookEx to intercept user keystrokes (which indicates keylogger functionality).

Adım Adım Çözüm

1
Analyze the telemetry regarding remote control and network traffic.
The persistent process establishes an outbound reverse shell back-connect over port 443, enabling remote adversary interaction, which defines Remote Access Trojan (RAT) functionality.
Identifying the primary operational objective of the network traffic establishes malware categorization.
2
Analyze the process API calls and host artifact telemetry.
The process uses SetWindowsHookEx to hook input events, identifying keystroke logging (keylogger/spyware) capabilities.
API hooking of user input functions directly correlates to keylogging behavior.
3
Evaluate distractor choices regarding propagation and remediation controls.
Worm behavior requires autonomous propagation, which is absent here. Perimeter firewall rules block external communication but do not perform host remediation or registry cleanup.
Differentiating malware propagation mechanisms and selecting proper host eradication versus network isolation controls avoids common operational misconceptions.

Anahtar Kavram

Malware Indicators of Compromise (RAT, Keylogger, Trojan vs Worm)
Tahmini Süre:2m 0s
Bu soruyu puanla