Soru

Zorluk: OrtaMalware Types and Indicators of Compromise

A security analyst reviews host logs and process telemetry from an endpoint suspected of infection. The analyst notices unauthorized background screen captures being saved to a hidden directory and outbound HTTP POST requests transmitting encrypted archives to an unrated external IP address on port 443. Which of the following malware classifications and primary capabilities are indicated by these observed technical artifacts? (Select TWO.)

  1. Spyware functioning to monitor user activity and gather sensitive data without authorizationCevap
  2. Command and control exfiltration mechanisms delivering captured data to remote attacker infrastructureCevap
  3. C
    A self-propagating worm exploiting local network vulnerabilities to infect neighboring hosts
  4. D
    Inline firewall filtering rules blocking unauthorized incoming network traffic

Cevap

The observed indicators demonstrate spyware capabilities monitoring endpoint activity (capturing screen state) alongside command and control data exfiltration mechanisms transferring collected archives outbound over HTTP POST.
The combination of covert background screen captures and outbound encrypted POST traffic aligns directly with spyware monitoring behavior combined with command and control data exfiltration capabilities.

Adım Adım Çözüm

1
Analyze host activity and process behaviors
Identified unauthorized screen captures saved locally, indicative of spyware monitoring.
Spyware stealthily captures screen state, keystrokes, or personal credentials without user consent.
2
Analyze network telemetry and exfiltration channels
Identified encrypted outbound HTTP POST requests to an external IP address.
Exfiltrating staged local files over encrypted web protocols to unknown IP addresses indicates active command and control communications.

Anahtar Kavram

Spyware telemetry and command and control exfiltration indicators of compromise
Bu soruyu puanla