skip to content

Malware Families and Behavior

You will learn to follow a payload's own life: how it spreads, how and at what level its code runs, what keeps the access alive, and what it is finally for. Interviewers test mechanism, not names.

on this pageshow

explore

questions

page 1 of 2

Why does an implant pick HTTPS to a permitted destination over a hard-coded IP on a custom port?

level: juniorimportance: must knowfreq 72%

answer

  1. the path has to already exist
  2. nothing new is opened on the way out
  3. it travels with everyone else's browsing
  4. blocking cost decides whether it survives

basics

~20 s

Because the path already exists. In a fully proxied estate an arbitrary address on an odd port has no route outward at all, while port 443 to a destination the organisation already permits needs no new opening and looks like ordinary browsing.

solid answer

~50 s

The carrier is chosen before the first outbound request, and the code does not get to invent a path. In an estate where every request must traverse a forward proxy and only the internal resolver may speak outward, a compiled-in address on a custom port simply never leaves: nothing forwards it, and the operator loses the foothold they just worked to get. HTTPS to a destination the business already reaches - a large hosting or content-delivery domain, a service the organisation is contractually obliged to permit - uses the path that exists, needs nothing opened, and arrives mixed in with the same requests every employee makes. It is also block economics: a compiled-in address costs the operator nothing and dies at the first block, while a destination the victim cannot afford to stop reaching survives being noticed.

go deeper

for a junior

Be ready to say why an outbound path has to already exist before code can use it, and why 443 to a well-known destination is the cheapest such path in a corporate network.

for a middle

Explain what the proxy mediates on that path, and why a compiled-in address on a custom port never leaves a fully proxied estate rather than merely being noticed.

for a senior

Show the block economics: judge which destinations your organisation could realistically stop reaching, and argue why address blocking only prices out the cheap end of the market.

for a principal

Own the tradeoff between an allow-listed egress posture and the business friction it creates, and be able to state exactly what residual channel each exception accepts.

### The choice, and when it is made A command channel is the path from code on a victim host back to whoever is operating it. The choice of *carrier* - which protocol, which port, which destination - is made when the implant is built, before it has ever spoken to its operator. Everything else about the intrusion is negotiable later; this is not, because a foothold that cannot reach out is worth nothing. ### Why arbitrary egress is a dead end Consider an estate with no direct outbound path at all: every web request must traverse an authenticating forward proxy, and the internal resolver is the only thing permitted to talk to the outside world. Code that opens a socket to `203.0.113.10:4444` in that estate does not get filtered - it gets *nowhere*. There is no default route for it, no device configured to relay it, and no fallback. The operator loses the host silently. This is why carrier choice is a design constraint rather than a stealth preference. The implant has to use a path the estate maintains for its own reasons: HTTP through the proxy, or name resolution through the resolver. Those are the two doors, and both are held open by the business, not by the attacker. ### What a permitted destination actually buys Three things, and they are different from each other: 1. **A route.** Port 443 to a name in a category the proxy allows is relayed because relaying it is the proxy's job. Nothing has to be opened, disabled, or reconfigured on the victim's side. 2. **Company.** The same destination is being reached all day by real users and real software updaters. The implant's requests are not the only ones going there, which raises the cost of separating them from everything else. 3. **Block resistance.** This is the part candidates usually miss. A destination is only useful for as long as the victim tolerates it. A throwaway address costs nothing to abandon *and* nothing to block. A destination the organisation is contractually or operationally obliged to reach cannot be closed without breaking the business, so blocking it is a decision with a price attached. ### The economics behind the two ends of the market The contrast is sharp. Commodity crimeware compiles in an address or a cheap throwaway name. It is disposable by design: the operator expects to lose implants and compensates with volume. Against a fully proxied estate it often never connects once. A well-resourced operator pays for the other side of that trade. They acquire presence on infrastructure the victim already permits - shared hosting, a large provider, a service the organisation is obliged to reach - and accept the constraints that come with it: shared tenancy, provider policy, the risk of the account being pulled, ongoing cost and re-registration. What they buy is a channel that survives being identified, because the counter-move costs the victim something. This is what *well-resourced* predicts in practice. Not exotic code - infrastructure the defender cannot cheaply take away. ### The control class that bites Blocking an address is a tax on the cheap end of the market. It works against the compiled-in destination and does nothing against the operator who can buy another permitted-looking one. The control class that removes what this technique depends on is the one that removes *arbitrary permitted egress*: default-deny outbound with an allow-listed set of destinations, so that landing on something inside the list stops being free. That posture has a real business cost, which is exactly why most estates do not have it and why the technique keeps working. ### What the choice does not buy A permitted destination does not make the request unmediated. It still goes through the proxy, it still names a destination, and it still has to be authenticated on the way out in an estate that demands it. The operator gains permission, not invisibility - and confusing those two is the most common error in reasoning about this.

  • What does the operator give up by using a large shared hosting destination instead of their own address?
    Control and predictability. The destination is shared with real customers, can be reassigned or pulled by the provider without warning, and has to be paid for or re-registered. They also inherit the provider's own limits on request size, rate and content. What they buy for that is a path the victim already permits and cannot cheaply close.
  • Which control class actually takes away what this choice depends on?
    One that removes arbitrary permitted egress, not one that blocks an address. Under default-deny outbound with an allow-listed destination set, choosing a permitted carrier stops being free - the operator has to land on something already inside the list. Blocking single addresses only prices out the commodity end of the market, because a resourced operator buys another permitted-looking destination.

A courier who can only leave through the staffed front door does not cut a hole in the wall - they walk out carrying the same kind of parcel everyone else is carrying.

saying these in an interview costs you the question

  • Says the implant just opens a socket to any address it likes
  • Thinks HTTPS hides the destination from the proxy
  • Assumes an unusual port is stealthier than 443
  • Treats blocking one address as removing the channel

context

open as a page

What does calling malware 'fileless' actually claim about it, and what does it not claim?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Fileless claims only that the code which ran was never a normal executable file launched from disk; it arrived as data and became code in memory. It does not claim that nothing was written to disk.

open as a page

Why does an operator already running as a user inject into that user's browser instead of opening its own connection?

level: juniorimportance: must knowfreq 70%

basics

~20 s

The operator's own process has no business reaching the internet, and its traffic carries no user identity. Running inside the user's browser borrows that person's session, proxy settings and usual destinations, so the outbound traffic looks like their ordinary browsing rather than a strange new program phoning out.

open as a page

Why does an operator run their payload through a signed Windows system binary rather than dropping an EXE?

level: juniorimportance: must knowfreq 78%

basics

~20 s

Because the binary already carries the vendor's trust and is already installed. Nothing attacker-authored arrives as an executable, no install rights are needed, and the run collides with the administration the estate performs every day.

open as a page

Does installing a rootkit give an adversary the privilege level it hides at?

level: juniorimportance: must knowfreq 68%

basics

~20 s

No. A rootkit conceals activity at a level the adversary already controls. Loading a kernel driver or writing firmware needs administrative privilege first, so concealment is something an intrusion buys after it has won, never a route to winning.

open as a page

We block USB drives and personal webmail - can a bulk copy still leave a SaaS document tenant?

level: juniorimportance: must knowfreq 58%

basics

~20 s

Blocking removable media and personal webmail closes two exits, not the class of exit. A bulk copy leaves through the sanctioned cloud storage, sharing links and sync the business itself requires and cannot switch off.

open as a page

Why does a commodity infostealer run once and never install persistence?

level: juniorimportance: must knowfreq 62%

basics

~20 s

Because the operator is paid per install, not per victim. One pass copies the browser profile and other saved material into an archive, uploads it and exits. Staying would add cost and exposure for material already taken.

open as a page

Why don't restorable backups remove a ransomware crew's leverage over you?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Because a copy of the data was taken before anything was encrypted. Restoring files ends the outage but not the threat to publish or sell what was already read, and the backup system itself is attacked early, not last.

open as a page

In ransomware-as-a-service, what work does the affiliate do that the developer never touches?

level: juniorimportance: must knowfreq 72%

basics

~20 s

The developer builds and maintains the encryptor, the builder and the affiliate panel and rents it out. The affiliate runs the intrusion itself - entry, spread, staging, launch - and keeps the larger share of whatever is paid.

open as a page

Why does a cryptomining implant keep its host healthy and leave the data alone?

level: juniorimportance: must knowfreq 60%

basics

~10 s

The asset is the machine's capacity, not its contents. Mining only pays while the host stays up, so the operator avoids anything that would get it rebuilt: no encryption, no visible theft, no crash.

open as a page

A ransom note on unreadable files: what actually decides ransomware versus a wiper?

level: juniorimportance: must knowfreq 55%

basics

~20 s

Whether anyone still holds a key that can reverse it. Ransomware keeps a per-victim key to sell back; a wiper overwrites data or generates a key and throws it away. The note is decoration and costs the operator nothing.

open as a page

Why does malware delivery usually split into a small first-stage loader and a separate second stage?

level: juniorimportance: must knowfreq 72%

basics

~10 s

The two halves have different price tags. The first stage is cheap and disposable, built to survive one arrival. The capable second stage is fetched only once the host looks worth spending it on.

open as a page

What must be true for malware to spread host to host with no user action?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Four things at once: the next host exposes a service the spreading code can satisfy on its own, no step waits on a person, attempts succeed often enough to keep finding new hosts, and the code can name candidates to try.

open as a page

Why can whoever holds a malware sample pre-register its generated C2 domains?

level: middleimportance: must knowfreq 48%

basics

~20 s

Because the generator is deterministic. Algorithm plus seed — usually the current date and a constant compiled in — produces the same names for the implant and for anyone running the sample forward, so future names are computable, not secret.

open as a page

Why do ransomware affiliates hit the backup estate and hypervisor console before encrypting?

level: middleimportance: must knowfreq 58%

basics

~20 s

Both change the arithmetic before the demand exists. Damaging the second copy removes the alternative to paying, and one virtualisation console reaches thousands of guests at once, so an entire estate falls in a single pass instead of host by host.

open as a page

Why do two intrusions with the identical ransomware build show completely different tradecraft?

level: middleimportance: must knowfreq 58%

basics

~20 s

Because the encryptor is a rented product shared by many affiliates, while the intrusion is each affiliate's own work. Identical payload with divergent entry and movement is the predicted signature of a service model, not a contradiction to explain away.

open as a page

Why ship a first stage inside an ISO or a password-protected archive rather than as the file itself?

level: middleimportance: must knowfreq 58%

basics

~20 s

Containers buy two different things and candidates name only one. An encrypted archive hides contents from inspection in transit. A mounted disk image historically launders the internet-zone marking, so the file inside runs as if never downloaded.

open as a page

Your proxy re-originates TLS on every outbound session - why doesn't that remove command and control?

level: seniorimportance: must knowfreq 56%

basics

~20 s

Interception yields plaintext only where the endpoint trusts the interception authority and does not pin, and exempt populations exist by design. Even where it works, the recovered body can be encrypted by the implant itself - and the destination was permitted anyway.

open as a page

Why is 'the payload was memory-only, so the reboot cleared it' usually the wrong conclusion?

level: seniorimportance: must knowfreq 58%

basics

~20 s

Memory-only describes the executable, not the residence. The body is normally parked as data with something durable to invoke it, so a reboot fires the trigger rather than removing it. And the way in stays open.

open as a page

You're told injecting into a user's browser 'escalated' the operator's privileges. On a shared desktop, is that right?

level: seniorimportance: must knowfreq 60%

basics

~20 s

No. Injecting into a process at the same integrity level escalates nothing — the operator already held that user's rights. It buys the user's identity on outbound traffic, a permitted egress path and a plausible lifetime. Privilege is spent only when the operator crosses into a different user's session.

open as a page

We reimaged the disk, so the rootkit is gone - when is that claim wrong?

level: seniorimportance: must knowfreq 55%

basics

~10 s

Reimaging is only sound above the level the implant occupies. Reinstalling the system volume can leave a boot component in the EFI System Partition; replacing the disk leaves platform-flash and option-ROM implants untouched.

open as a page

Why does 'a real theft would show up as a huge transfer' miss an espionage operator?

level: seniorimportance: must knowfreq 52%

basics

~20 s

Size intuition only catches the objective that is inherently bulky. An espionage objective is usually tens of megabytes - one design, one term sheet - and the price its operator pays is weeks of time on target, not bandwidth.

open as a page

Why does rebuilding an infostealer-infected contractor laptop not close the exposure?

level: seniorimportance: must knowfreq 50%

basics

~20 s

Rebuilding removes the code, not the copy. The archive left minutes after infection and has its own life - sold, resold, re-used - so exposure is clocked from resale and reuse, not from the infection date.

open as a page

You removed the mining workloads from a metered cloud account, so why does the bill keep climbing?

level: seniorimportance: must knowfreq 55%

basics

~20 s

Because the miner was the product, not the access. The credential and the exposed path that placed it are untouched, so capacity is created again, and the loss accrues until that credential is rotated and the path closed.

open as a page

Fully patched, so nothing is wormable - where does that reviewer's claim break?

level: seniorimportance: must knowfreq 58%

basics

~20 s

Patch state addresses one route to one precondition. A spreader that logs in with a valid reused credential exploits nothing and is fully wormable on a patched estate, while a critical-rated flaw that needs someone to open a file is not wormable at any severity.

open as a page

Why does malware ship with more than one command-and-control address?

level: juniorimportance: should knowfreq 55%

basics

~20 s

Because the first address gets seized, suspended or switched off, and an implant that cannot reach its operator is dead code. Fallback paths are the operator's insurance against losing an entire installed base to one removal.

open as a page

How does an internal DNS resolver carry commands for a host with no outbound path?

level: middleimportance: should knowfreq 44%

basics

~20 s

The host never talks outside. It asks the internal resolver, which recurses on its behalf; the name asked for is attacker-chosen data, and the operator's own authoritative server answers it. Bytes cross both ways through a permitted intermediary.

open as a page

Fast flux rotates hundreds of addresses behind one name — what is the fixed point?

level: middleimportance: should knowfreq 38%

basics

~20 s

The name's delegation. Addresses churn every few minutes among disposable relay hosts and, under double flux, the nameservers move too — but the parent zone's delegation of that name is single, static and held at the registry.

open as a page

What does an operator gain and lose by storing a payload as data for an installed interpreter?

level: middleimportance: should knowfreq 52%

basics

~20 s

Gain: nothing on disk is a program, so hash blocking and executable allowlists have nothing to grab. Loss: it runs only where that interpreter already exists and is permitted, with capability capped by the language.

open as a page

In process hollowing, what must an operator do to a suspended host before the payload can run?

level: middleimportance: should knowfreq 55%

basics

~20 s

Hollowing starts a legitimate process suspended so it never actually runs, unmaps its original image from memory, writes the payload in its place, fixes the payload's relocations to wherever it landed, repoints the primary thread's entry at the payload, then resumes. The process ends up running code it was never loaded with.

open as a page

showing 1–30 of 58