17-C Flashcards
What is malware?
Software that does something bad from the perspective of the system owner
What are the main categories of malware according to vector?
- Viruses
- Boot sector viruses
- Trojans
- Worms
- Fileless malware
What is a virus?
Concealed within the code of an executable process image stored as a file on disk
What do boot sector viruses infect?
The boot sector code or partition table on a disk drive
Define a Trojan.
Malware concealed within an installer package for software that appears to be legitimate
How do worms spread?
By replicating between processes in system memory and exploiting vulnerable client/server software
What is fileless malware?
Malicious code that uses the host’s scripting environment to create new processes in memory
What is a backdoor in the context of malware?
A method allowing a threat actor to access a PC and upload/exfiltrate data files
What are the primary functions of spyware?
- Perform browser reconfigurations
- Monitor local application activity
- Take screenshots
- Activate recording devices
What is a keylogger?
Spyware that records keystrokes to steal confidential information
What is a rootkit?
Malware that operates with high privileges, often concealing its presence
What is ransomware?
A type of malware that tries to extort money from the victim
What is crypto-ransomware?
Ransomware that encrypts files, making them inaccessible without a decryption key
What is cryptojacking?
The hijacking of a host’s resources to perform cryptocurrency mining
List some performance symptoms of malware infection.
- Computer fails to boot
- Slow performance at startup
- Inability to access network or internet
What are common application symptoms of malware?
- Security-related applications stop working
- OS updates fail
- Applications crash frequently
What file system errors might indicate malware infection?
- Missing or renamed files
- Additional executable files with similar names to system files
- Altered file permissions
What does redirection in a browser indicate?
When a user is sent to a different page than intended, often mimicking the target page
What causes certificate warnings in a browser?
- Self-signed certificates
- FQDN mismatch
- Expired or revoked certificates
What is the first step in the best practices for malware removal?
Investigate and verify malware symptoms
Fill in the blank: A key component of malware removal is to _______ infected systems.
[quarantine]
True or False: Most malware is discovered via manual inspection rather than automated scanning.
False
What should be done after remediating infected systems?
Enable System Restore and create a restore point in Windows
What is the purpose of enabling System Restore in Windows?
To create restore points that allow users to revert their system to a previous state.