Malware Forensics Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Malware Forensics flashcards as text
A wiper malware overwrites the first 512 bytes of every connected drive. What critical structure is it targeting?
Answer: Master Boot Record (MBR)
The Master Boot Record occupies the first 512 bytes of a disk and contains the bootloader code and partition table; overwriting it renders the system unbootable.
A forensic analyst discovers that malware is using DNS TXT records to receive commands. This is an example of which C2 technique?
Answer: DNS tunneling for command-and-control
DNS tunneling encodes C2 commands and data within DNS query/response fields such as TXT records, allowing covert communication that often bypasses firewall rules permitting DNS traffic.
During memory forensics with Volatility, which plugin would BEST detect a userland rootkit that has unlinked a process from the EPROCESS doubly linked list?
Answer: psscan
psscan scans raw memory pools for EPROCESS structures rather than walking the linked list, so it finds processes hidden by DKOM that have been unlinked from the list.
A malware sample achieves persistence by adding an entry under HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run using a living-off-the-land binary. Which binary would be LEAST expected in this context?
Answer: taskmgr.exe
taskmgr.exe is the Task Manager and is not a LOLBin commonly abused for script execution or payload loading; regsvr32, mshta, and wscript are classic LOLBins used for persistence.
A mobile malware sample on Android requests the READ_SMS and SEND_SMS permissions. From a forensic perspective, which threat category does this MOST indicate?
Answer: Banking trojan intercepting OTP SMS codes
Banking trojans commonly abuse SMS permissions to intercept one-time passwords sent by banks for two-factor authentication, forwarding them to the attacker.
An investigator finds a suspicious DLL in C:\Windows\System32 that is loaded by svchost.exe but does not appear in any Microsoft catalog. The BEST first step to assess this DLL is to:
Answer: Submit its SHA-256 hash to VirusTotal and check its digital signature
Checking the hash against VirusTotal and verifying the code-signing certificate are non-destructive, rapid triage steps that establish whether the DLL is known malicious before deeper analysis.
A forensic image of a compromised host shows that the malware modified the hosts file to redirect antivirus update domains to 127.0.0.1. What is the forensic artifact path for the Windows hosts file?
Answer: C:\Windows\System32\drivers\etc\hosts
The Windows hosts file is located at C:\Windows\System32\drivers\etc\hosts and is a common target for malware to block security tool updates by overriding DNS resolution.