Malware Analysis Flashcards

1
Q

Downloader

A

Used to download the primary malware or additional tools
Ex- Office documents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Dropper

A

Similar to Downloader but has the malware embedded within and will not rely upon retrieval from the internet, although the dropped payload may.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Loaders

A

Used to download additional malware, will likely persist on the host and use a variety of techniques for command and control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Boot Integrity

A

Using a secure method to boot a system and verify the integrity of the OS and loading mechanism

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

UEFI

A

Unified Extensible Firmware Interface
Specification for a software program that connects a computer’s firmware to its OS
Installed at time of manufacturing and is the first program that runs when a computer is turned on
Checks to see what hardware components the device has, wakes them up, and hands them over to the OS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Measured Boot

A

Checks each startup component, including the firmware all the way to the boot drivers
Stores this info in the TPM and can send it to a trusted server that can objectively assess the PC’s health

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Boot Attestation

A

Enables a remote platform to measure and report its system state in a secure way to a third party

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Code Signing

A

Process of digitally signing executables and scripts to confirm the software author can guarantee that the code has not been altered or corrupted since it was signed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly