Ch. 14 Flashcards
What type of malware analysis involves the execution of malware to examine its conduct and impact on system resources and network?
Dynamic analysis
What is a common technique used to distribute malware on the web with tactics such as keyword stuffing, doorway pages, page swapping, and adding unrelated keywords to get higher search-engine ranking for malware pages?
Blackhat SEO
What is a common technique used to distribute malware on the web by mimicking legitimate institutions in an attempt to steal passwords, credit cards, and bank account data?
Spear phishing sites
What is a static malware analysis technique that uses unique hash values to help investigators recognize files that are sensitive to tracking and identify similar programs from a database?
File fingerprinting
What is a common technique used to distribute malware on the web when an attacker exploits flaws in browser software to install malware just by merely visiting a webstie?
Drive-by downloads
Which type of dynamic malware analysis involves monitoring process, examining event logs, looking for connected ports, examining DNS entries, and other forms of monitoring?
Observing runtime behavior
What tool for Windows shows real-time file system, registry, and process/thread activity and combines the features of two Sysinternals utilities, Filemon and Regmon?
Process Monitor