Malware Families and Behavior
You will learn to follow a payload's own life: how it spreads, how and at what level its code runs, what keeps the access alive, and what it is finally for. Interviewers test mechanism, not names.
on this pageshowhide
explore
- Spreading and Staging8 questions
- Clearing the Wormability Bar4 questions
- Loaders and Second Stages4 questions
- Getting Code to Run17 questions
- Living Off the Land4 questions
- Fileless Residence4 questions
- Running in Another Process4 questions
- Rootkits and Signed Drivers5 questions
- Staying Resident and Reachable8 questions
- Persistence Triggersempty
- Command Channel Choice4 questions
- Rendezvous and Fallback4 questions
- Endgame of Quiet Access25 questions
- Pre-Encryption Leverage4 questions
- Extortion as a Service4 questions
- Wipers and Destruction4 questions
- Renting Out the Victim5 questions
- Commodity Stealers4 questions
- The Exfiltration Tax4 questions
questions
page 2 of 2How does an operator chain signed Windows utilities to run a remote scriptlet without dropping a tool?
basics
~20 sBy composing utilities that each do one narrow job: one retrieves remote content, a script host interprets it, and a component entry point turns registering or hosting something into executing it. The chain is what makes it work and what it costs.
Why load someone else's legitimately signed but vulnerable kernel driver?
basics
~20 sBecause it is already signed. Reaching kernel level needs a signing identity the system trusts - scarce, attributable, dead once revoked. A real vendor's signed driver exposing an unchecked memory or process primitive supplies the same crossing for free.
Why can a kernel-mode rootkit lie to a user-mode program but not the reverse?
basics
~20 sBecause each layer composes the answers the layer above receives. Kernel code can edit the process and file lists user mode is handed; a user-mode hook only rewrites what one process sees, while the kernel below keeps the truth.
Why does an operator index and stage documents on the victim's own hosts before exfiltrating?
basics
~20 sHolding read access is not the same as knowing what is worth taking. Enumerating and indexing inside the estate builds a candidate list cheaply, so only the small set the objective needs is archived and moved once.
How does an untargeted infostealer infection become a targeted intrusion months later?
basics
~20 sThrough resale. The operator spreads the build indiscriminately and sells the bundles in volume; a buyer later searches that catalogue for a corporate address and pays for the one that reaches a chosen company. Targeting happens after the theft.
Why does a residential IP address rent by the hour for more than a datacentre one?
basics
~10 sThe product is reputation, not bandwidth. Risk models score a consumer ISP address as ordinary and a hosting range as suspect, so the same request is accepted from one and refused from the other.
How does an exploit that crashes the service one attempt in five limit a worm's spread?
basics
~20 sEvery failure subtracts a host from the pool that all infected nodes share. A host killed on the first attempt against it is never recruited by anyone, so per-attempt success caps total reach and cuts the number of hosts each infected node can pass the code to.
An operator injects into a user's browser tab to blend traffic; the user closes it. What just happened to their code?
basics
~20 sIt died with the process. Memory-only injection has no life of its own — when the user closes the browser, the host exits and the payload is gone. To survive, the operator needs a separate trigger that re-injects on each new session, or must accept a longer-lived host that is worse cover.
A change board asks: can we just block mshta, rundll32 and regsvr32 on the admin jump host?
basics
~20 sSplit the list rather than answer yes or no. The HTML application host is often genuinely removable; the library-export and component-registration binaries are load-bearing for installation and configuration, so a blanket block breaks delegated administration and gets reversed.
Which ransomware preconditions do you remove on the backup and virtualisation management path?
basics
~20 sWork back from what the operation cannot substitute: one identity that administers both the fleet and the backup system, retention any authenticated caller can shorten, and a management console reachable from the ordinary network. Removing those three makes the endgame far more expensive.
An access broker listed your VPN account for sale weeks before the extortion - how were you chosen?
basics
~20 sYou were selected twice by two different parties: a broker picked you because your access was sellable, then a buyer picked your listing because the price fitted their margin. Neither selection was about you specifically.
No malware ran, yet a cloud estate is unrecoverable: how does destruction work through the control plane?
basics
~10 sEvery step is an authorised API call by an entitled identity: delete the objects and snapshots, strip versioning and unlocked retention, then destroy the customer-managed key everything was encrypted under. Nothing to patch.
A first-stage loader's check-in to its staging server returned an empty response. What does that prove?
basics
~20 sVery little, and not that the chain was harmless. The serving decision is made on the operator's side from the facts the loader reported, so a non-matching requester is served nothing by design. It proves no capability landed here.
Ransomware affiliates buy access on economics - what do you tell a board that hardening will change?
basics
~20 sCommit to what the economics support: hardening takes you out of the cheap inventory volume buyers shop from, so it genuinely diverts them. It does not deter a crew whose payout is priced against your revenue.
Finance wants a spend cap rather than remediation after cryptomining in your cloud account. What do you argue?
basics
~20 sA cap bounds the invoice, not the access. It converts an intrusion into a budgeted cost line while the credential that created the capacity stays live and resellable. Price the next buyer's objective, not this month's overspend.
An executive wants to pay a note you believe is attached to a wiper. How do you own that call?
basics
~20 sState the claim, its confidence and what would falsify it, then argue sequencing rather than payment: preserving a copy of the ciphertext is cheap, while pausing the rebuild is the delay the note was written to buy.
A business owner refuses a fleet-wide block on disk-image attachments. Which control class removes this loader chain instead?
basics
~20 sWork from the chain's preconditions and pick the one whose exception list has a willing owner. Application control removes the final precondition whatever the container, but it is a programme measured in quarters, so scope the narrow blocks meanwhile.
How does implant code get out through a forward proxy that demands authentication?
basics
~20 sIt borrows the logged-on user. The platform's own HTTP stack already knows the configured proxy and answers its challenge with the session's Kerberos ticket or NTLM response, so the channel leaves as that user with no password ever typed.
How can a Linux process execute a binary that has no name in any filesystem?
basics
~20 sThe kernel can create an anonymous, memory-backed file that has a descriptor but no directory entry. Bytes are written into it and executed from that descriptor, so the running image has no path and dies with the process.
What capability does an operator give up by driving rundll32 or mshta instead of their own tool?
basics
~20 sOnly the binary's designed behaviour is available. There is no arbitrary system call, the argument surface is capped and awkward, error handling is nearly absent, the process ends when the utility's job ends, and nothing in the chain provides persistence.
Why does a ransomware encryptor cipher only a fraction of each file?
basics
~20 sFor throughput. Ciphering a header or chunks at a fixed stride makes structured files unusable at a fraction of the input and output cost, so a whole datastore finishes inside one window. The trade accepted is that some content survives intact.
Is a bandwidth-sharing SDK bundled in a free app malware if the user accepted the licence?
basics
~20 sStrictly, no: it does exactly what a disclosed licence says, and that is the business model. But consent from whoever clicked accept is not consent from the device's owner, and at the exit it is indistinguishable from a compromised node.
A wiper overwrote a disk's first sector: why is the machine dead but the data is not?
basics
~20 sThe first sector of an MBR disk holds boot code and the four-entry partition table — the map, not the contents. Overwrite it and nothing can find or start the volume, while every file cluster is still physically present.
Why can a worm sweep a local /24 but not generate random addresses on an IPv6 /64?
basics
~20 sDensity. A /24 holds 254 usable addresses and a busy segment fills a good share of them, so sweeping all of them is trivial. A /64 holds about 18 quintillion addresses for perhaps a few hundred devices, so a random draw effectively never lands on one.
As a registrar's abuse engineer, do you suspend 30,000 pre-computed botnet domains?
basics
~20 sMostly no, and never on the list alone. A registrar can act only on names it sponsors, with evidence and legal cover. Most of a crop is unregistered or held elsewhere, and acting early just moves the population one rung down.
How do you decide on a vulnerable-driver blocklist when enforcing it breaks a production driver?
basics
~20 sTreat it as a scoped purchase, not a switch. Enforce everywhere the driver is not needed, scope a narrow exception for the machine class that needs it, name an owner who accepts the residual risk, and date it.
The business refuses to block the sanctioned cloud storage everyone uploads to - what do you change instead?
basics
~20 sAttack the dependency an operator cannot substitute: how much one standing identity may read and how easily the estate reveals what is worth taking. The carrier stays open; the value of any single compromised or trusted account falls.
A contractor's personal laptop holds corporate access and you cannot mandate anything on it - what do you change?
basics
~20 sChange what the device is allowed to hold, not the device: credentials that cannot be copied out of hardware, or a brokered session so the personal machine holds only a view. Where neither fits, price in a supplied managed device.
showing 31–58 of 58