Network monitoring alerts show that a malicious binary on an infected host is actively scanning neighboring subnets over TCP port 445 and automatically exploiting a remote code execution vulnerability on adjacent systems. The malware spreads from machine to machine across the network without requiring any user action, social engineering, or credential theft, after which it encrypts local files and issues a ransom prompt. Which of the following malware classifications best describes this threat?
- WormCevap
- BTrojan
- CRootkit
- DLogic bomb
Cevap
The threat is best classified as a Worm because it self-propagates across subnets via network vulnerabilities without requiring user intervention.
The correct answer identifies the malware as a worm because the primary indicator of compromise is autonomous, network-wide self-propagation via unpatched vulnerability exploitation without requiring user interaction.
Adım Adım Çözüm
Anahtar Kavram
Worm propagation vs Trojan and fileless delivery mechanisms