skip to content

Malware Families and Behavior

You will learn to follow a payload's own life: how it spreads, how and at what level its code runs, what keeps the access alive, and what it is finally for. Interviewers test mechanism, not names.

on this pageshow

explore

questions

page 2 of 2

How does an operator chain signed Windows utilities to run a remote scriptlet without dropping a tool?

level: middleimportance: should knowfreq 61%

basics

~20 s

By composing utilities that each do one narrow job: one retrieves remote content, a script host interprets it, and a component entry point turns registering or hosting something into executing it. The chain is what makes it work and what it costs.

open as a page

Why load someone else's legitimately signed but vulnerable kernel driver?

level: middleimportance: should knowfreq 47%

basics

~20 s

Because it is already signed. Reaching kernel level needs a signing identity the system trusts - scarce, attributable, dead once revoked. A real vendor's signed driver exposing an unchecked memory or process primitive supplies the same crossing for free.

open as a page

Why can a kernel-mode rootkit lie to a user-mode program but not the reverse?

level: middleimportance: should knowfreq 61%

basics

~20 s

Because each layer composes the answers the layer above receives. Kernel code can edit the process and file lists user mode is handed; a user-mode hook only rewrites what one process sees, while the kernel below keeps the truth.

open as a page

Why does an operator index and stage documents on the victim's own hosts before exfiltrating?

level: middleimportance: should knowfreq 45%

basics

~20 s

Holding read access is not the same as knowing what is worth taking. Enumerating and indexing inside the estate builds a candidate list cheaply, so only the small set the objective needs is archived and moved once.

open as a page

How does an untargeted infostealer infection become a targeted intrusion months later?

level: middleimportance: should knowfreq 46%

basics

~20 s

Through resale. The operator spreads the build indiscriminately and sells the bundles in volume; a buyer later searches that catalogue for a corporate address and pays for the one that reaches a chosen company. Targeting happens after the theft.

open as a page

Why does a residential IP address rent by the hour for more than a datacentre one?

level: middleimportance: should knowfreq 46%

basics

~10 s

The product is reputation, not bandwidth. Risk models score a consumer ISP address as ordinary and a hosting range as suspect, so the same request is accepted from one and refused from the other.

open as a page

How does an exploit that crashes the service one attempt in five limit a worm's spread?

level: middleimportance: should knowfreq 45%

basics

~20 s

Every failure subtracts a host from the pool that all infected nodes share. A host killed on the first attempt against it is never recruited by anyone, so per-attempt success caps total reach and cuts the number of hosts each infected node can pass the code to.

open as a page

An operator injects into a user's browser tab to blend traffic; the user closes it. What just happened to their code?

level: seniorimportance: should knowfreq 45%

basics

~20 s

It died with the process. Memory-only injection has no life of its own — when the user closes the browser, the host exits and the payload is gone. To survive, the operator needs a separate trigger that re-injects on each new session, or must accept a longer-lived host that is worse cover.

open as a page

A change board asks: can we just block mshta, rundll32 and regsvr32 on the admin jump host?

level: seniorimportance: should knowfreq 52%

basics

~20 s

Split the list rather than answer yes or no. The HTML application host is often genuinely removable; the library-export and component-registration binaries are load-bearing for installation and configuration, so a blanket block breaks delegated administration and gets reversed.

open as a page

Which ransomware preconditions do you remove on the backup and virtualisation management path?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Work back from what the operation cannot substitute: one identity that administers both the fleet and the backup system, retention any authenticated caller can shorten, and a management console reachable from the ordinary network. Removing those three makes the endgame far more expensive.

open as a page

An access broker listed your VPN account for sale weeks before the extortion - how were you chosen?

level: seniorimportance: should knowfreq 44%

basics

~20 s

You were selected twice by two different parties: a broker picked you because your access was sellable, then a buyer picked your listing because the price fitted their margin. Neither selection was about you specifically.

open as a page

No malware ran, yet a cloud estate is unrecoverable: how does destruction work through the control plane?

level: seniorimportance: should knowfreq 46%

basics

~10 s

Every step is an authorised API call by an entitled identity: delete the objects and snapshots, strip versioning and unlocked retention, then destroy the customer-managed key everything was encrypted under. Nothing to patch.

open as a page

A first-stage loader's check-in to its staging server returned an empty response. What does that prove?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Very little, and not that the chain was harmless. The serving decision is made on the operator's side from the facts the loader reported, so a non-matching requester is served nothing by design. It proves no capability landed here.

open as a page

Ransomware affiliates buy access on economics - what do you tell a board that hardening will change?

level: principalimportance: should knowfreq 38%

basics

~20 s

Commit to what the economics support: hardening takes you out of the cheap inventory volume buyers shop from, so it genuinely diverts them. It does not deter a crew whose payout is priced against your revenue.

open as a page

Finance wants a spend cap rather than remediation after cryptomining in your cloud account. What do you argue?

level: principalimportance: should knowfreq 32%

basics

~20 s

A cap bounds the invoice, not the access. It converts an intrusion into a budgeted cost line while the credential that created the capacity stays live and resellable. Price the next buyer's objective, not this month's overspend.

open as a page

An executive wants to pay a note you believe is attached to a wiper. How do you own that call?

level: principalimportance: should knowfreq 38%

basics

~20 s

State the claim, its confidence and what would falsify it, then argue sequencing rather than payment: preserving a copy of the ciphertext is cheap, while pausing the rebuild is the delay the note was written to buy.

open as a page

A business owner refuses a fleet-wide block on disk-image attachments. Which control class removes this loader chain instead?

level: principalimportance: should knowfreq 33%

basics

~20 s

Work from the chain's preconditions and pick the one whose exception list has a willing owner. Application control removes the final precondition whatever the container, but it is a programme measured in quarters, so scope the narrow blocks meanwhile.

open as a page

How does implant code get out through a forward proxy that demands authentication?

level: middleimportance: nice to knowfreq 34%

basics

~20 s

It borrows the logged-on user. The platform's own HTTP stack already knows the configured proxy and answers its challenge with the session's Kerberos ticket or NTLM response, so the channel leaves as that user with no password ever typed.

open as a page

How can a Linux process execute a binary that has no name in any filesystem?

level: middleimportance: nice to knowfreq 32%

basics

~20 s

The kernel can create an anonymous, memory-backed file that has a descriptor but no directory entry. Bytes are written into it and executed from that descriptor, so the running image has no path and dies with the process.

open as a page

What capability does an operator give up by driving rundll32 or mshta instead of their own tool?

level: middleimportance: nice to knowfreq 34%

basics

~20 s

Only the binary's designed behaviour is available. There is no arbitrary system call, the argument surface is capped and awkward, error handling is nearly absent, the process ends when the utility's job ends, and nothing in the chain provides persistence.

open as a page

Why does a ransomware encryptor cipher only a fraction of each file?

level: middleimportance: nice to knowfreq 32%

basics

~20 s

For throughput. Ciphering a header or chunks at a fixed stride makes structured files unusable at a fraction of the input and output cost, so a whole datastore finishes inside one window. The trade accepted is that some content survives intact.

open as a page

Is a bandwidth-sharing SDK bundled in a free app malware if the user accepted the licence?

level: middleimportance: nice to knowfreq 26%

basics

~20 s

Strictly, no: it does exactly what a disclosed licence says, and that is the business model. But consent from whoever clicked accept is not consent from the device's owner, and at the exit it is indistinguishable from a compromised node.

open as a page

A wiper overwrote a disk's first sector: why is the machine dead but the data is not?

level: middleimportance: nice to knowfreq 33%

basics

~20 s

The first sector of an MBR disk holds boot code and the four-entry partition table — the map, not the contents. Overwrite it and nothing can find or start the volume, while every file cluster is still physically present.

open as a page

Why can a worm sweep a local /24 but not generate random addresses on an IPv6 /64?

level: middleimportance: nice to knowfreq 38%

basics

~20 s

Density. A /24 holds 254 usable addresses and a busy segment fills a good share of them, so sweeping all of them is trivial. A /64 holds about 18 quintillion addresses for perhaps a few hundred devices, so a random draw effectively never lands on one.

open as a page

As a registrar's abuse engineer, do you suspend 30,000 pre-computed botnet domains?

level: principalimportance: nice to knowfreq 20%

basics

~20 s

Mostly no, and never on the list alone. A registrar can act only on names it sponsors, with evidence and legal cover. Most of a crop is unregistered or held elsewhere, and acting early just moves the population one rung down.

open as a page

How do you decide on a vulnerable-driver blocklist when enforcing it breaks a production driver?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

Treat it as a scoped purchase, not a switch. Enforce everywhere the driver is not needed, scope a narrow exception for the machine class that needs it, name an owner who accepts the residual risk, and date it.

open as a page

The business refuses to block the sanctioned cloud storage everyone uploads to - what do you change instead?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Attack the dependency an operator cannot substitute: how much one standing identity may read and how easily the estate reveals what is worth taking. The carrier stays open; the value of any single compromised or trusted account falls.

open as a page

A contractor's personal laptop holds corporate access and you cannot mandate anything on it - what do you change?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Change what the device is allowed to hold, not the device: credentials that cannot be copied out of hardware, or a brokered session so the personal machine holds only a view. Where neither fits, price in a supplied managed device.

open as a page

showing 31–58 of 58