Malware Forensics Flashcards
6 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Malware Forensics flashcards as text
A malware analyst is performing static analysis on a suspicious executable. The analyst notes that the file has a very small import address table (IAT) but a section with unusually high entropy. What is the most likely reason for these characteristics?
Answer: The malware is packed or encrypted to obfuscate its true code.
Packers compress or encrypt a malware's original code. The resulting binary has a small unpacking 'stub' with few imports, which is responsible for decompressing/decrypting the real malicious code in memory. The packed section itself appears random, leading to high entropy, which is a classic indicator of this obfuscation technique.
A CHFI is conducting dynamic analysis of a suspected ransomware sample in an isolated, sandboxed environment. Which of the following actions would be the primary focus of the analyst's monitoring to confirm the malware's classification and behavior?
Answer: Observing rapid and widespread file read/write/rename operations, especially with a new file extension being added.
Dynamic analysis focuses on observing the malware's behavior at runtime. The defining characteristic of ransomware is its encryption of user files. Therefore, monitoring for high-volume file system I/O, particularly operations that involve reading original files and writing newly encrypted versions (often with a specific extension), is the most direct way to observe and confirm its malicious intent.
An investigator is analyzing a compromised Windows machine and needs to determine how a piece of malware achieves persistence across reboots. Which of the following is one of the most common registry keys an analyst should examine for malicious entries?
Answer: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
The `HKLM\SYSTEM\CurrentControlSet\Services` registry key is a fundamental location where Windows services are defined. Malware frequently creates a new service pointing to its executable to ensure it is launched automatically by the operating system at startup, often with high privileges. While other locations can be used for persistence, this is a primary and critical location to investigate.
During a memory forensics analysis using a tool like Volatility, an investigator lists all running processes from a memory dump. The output shows a suspicious process named `svc-host.exe`, which is a common misspelling of the legitimate `svchost.exe`. This finding is an example of which malware analysis technique?
Answer: Masquerading
Masquerading is a technique where malware disguises itself by using a name that is very similar to a legitimate system file or process. The goal is to deceive system administrators or investigators who are performing a quick review, causing them to overlook the malicious process.
A forensic analyst suspects a system is infected with a sophisticated kernel-mode rootkit. The analyst runs `tasklist` on the live system and sees no malicious processes. However, after acquiring a memory dump and analyzing it with Volatility, a hidden process is discovered. This discrepancy is most likely caused by the rootkit performing what action?
Answer: Using Direct Kernel Object Manipulation (DKOM) to unlink its process from the active process list.
Kernel-mode rootkits can directly manipulate the kernel's data structures. By using DKOM, a rootkit can remove the `EPROCESS` block of its process from the doubly-linked list of active processes that the kernel maintains. User-mode tools that rely on standard APIs to list processes will not see the malware, but memory forensics tools that parse these raw kernel structures directly can still find the unlinked process.
Which of the following best describes the primary goal of performing reverse engineering on a malware sample during a forensic investigation?
Answer: To understand the malware's precise functionality, algorithms, and capabilities by analyzing its disassembled code.
Reverse engineering involves disassembling or decompiling a binary to analyze its assembly code. The ultimate goal is to understand exactly what the program does, how its algorithms work (e.g., encryption routines, C2 communication protocols), and what its full capabilities are. This provides a much deeper understanding than static or dynamic analysis alone.