← All CHFI Flashcard Decks

Malware Forensics Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Malware Forensics flashcards as text
  1. A malware sample uses the Heaven's Gate technique on a 64-bit Windows system. What is the primary purpose of this technique?

    Answer: Switching from 32-bit to 64-bit execution to bypass WOW64 API hooks

    Heaven's Gate allows 32-bit malware running under WOW64 to directly invoke 64-bit code, bypassing 32-bit API hooks placed by security products in the WOW64 layer.

  2. Which Volatility 3 plugin would an investigator use to extract network connections (including those in CLOSE_WAIT and TIME_WAIT states) from a Windows memory image?

    Answer: windows.netscan

    windows.netscan scans memory pools for network structures and recovers connections in various TCP states including those that windows.netstat would miss.

  3. During malware triage, an analyst finds a PE file whose .text section has an entropy value of 7.8 out of 8. This MOST likely indicates:

    Answer: The code section is packed or encrypted

    Entropy near 8.0 in a PE code section indicates highly randomized data, which is characteristic of packing, encryption, or compression applied to hide the true payload.

  4. A forensic analyst is examining a macOS system suspected of running malware. Which location should be checked FIRST for user-level persistence launch agents?

    Answer: ~/Library/LaunchAgents/

    ~/Library/LaunchAgents/ stores per-user launch agents that run when the user logs in; malware without root access commonly places plist persistence files here.

  5. An investigator is analyzing a botnet C2 protocol and finds that the malware generates domain names using the current date as a seed for a pseudo-random algorithm. This is BEST described as:

    Answer: Domain generation algorithm (DGA)

    A Domain Generation Algorithm (DGA) uses a seed value such as the current date to algorithmically produce large numbers of potential C2 domain names, making takedowns difficult.

  6. A CHFI investigator recovers a file from a Linux system that has been deleted but whose inode has not yet been reallocated. Which command can recover the file content using its inode number?

    Answer: debugfs -R 'cat ' /dev/sdX

    debugfs is an ext2/3/4 filesystem debugger that can read data blocks associated with a specific inode, enabling direct recovery of deleted file content.

  7. During malware analysis, you find that a sample uses atom bombing — writing shellcode to the global atom table and using callback functions to execute it. Which Windows mechanism does this abuse?

    Answer: NtQueueApcThread with GlobalAddAtom for code injection without WriteProcessMemory

    Atom bombing injects code by writing shellcode into the global atom table and using NtQueueApcThread to queue an APC that copies and executes the atom data in the target process without calling WriteProcessMemory.