A security analyst is examining a Windows 10 host and suspects that an attacker has established persistence using a scheduled task. The analyst runs 'schtasks /query /fo LIST /v' and observes a task named 'WindowsUpdateCheck' with the action 'C:\Users\Public\update.exe' and a trigger set to run every 5 minutes. Which of the following best describes the attacker's technique?
Scheduled tasks are a common persistence mechanism. The task name 'WindowsUpdateCheck' mimics a legitimate update check, but the action points to a binary in C:\Users\Public, which is an unusual location for a legitimate update executable. The frequent trigger (every 5 minutes) ensures the malware runs regularly, maintaining persistence and possibly beaconing to a command-and-control server.
Why this answer
Scheduled tasks are frequently abused by attackers to establish persistence. The task name 'WindowsUpdateCheck' is designed to look benign, but the executable path in C:\Users\Public and the 5-minute interval are suspicious. Attackers use such tasks to ensure their malware runs regularly, even after reboots.
Analysts should investigate the binary and the task's origin.
Exam trap
The trap here is assuming that a task with a legitimate-sounding name is safe, but the executable path and frequency are key indicators of malicious intent.