During a memory analysis of a compromised host, an analyst finds that 'svchost.exe' is running from 'C:\Users\Public\svchost.exe' instead of 'C:\Windows\System32\svchost.exe'. The process has injected code into a legitimate 'explorer.exe' process. What technique is being observed?
Trap 1: WMI persistence
WMI persistence stores event subscriptions in the WMI repository, leaving no process running from C:\Users\Public. It is tempting because WMI can execute code, but that suits fileless persistence via __EventFilter and CommandLineEventConsumer, not a masqueraded binary injecting into explorer.exe.
Trap 2: Process hollowing
Process hollowing replaces the image of a legitimately created suspended process, so the executable path would remain the original one. Here the binary runs from an abnormal path and injects into explorer.exe, which describes process injection or masquerading, not hollowing; hollowing would be the answer if the path stayed System32.
Trap 3: DLL side-loading
DLL side-loading plants a malicious DLL beside a legitimate executable that loads it, so the running binary keeps its trusted path. It is tempting because it also abuses trusted processes, but that suits hijacked DLL search order, not a relocated svchost.exe injecting into explorer.exe.
- A
WMI persistence
Why it fails: WMI persistence stores event subscriptions in the WMI repository, leaving no process running from C:\Users\Public. It is tempting because WMI can execute code, but that suits fileless persistence via __EventFilter and CommandLineEventConsumer, not a masqueraded binary injecting into explorer.exe.
- B
DLL injection
DLL injection loads malicious code into another process's address space, which matches the injected code found inside legitimate explorer.exe. The masquerading svchost.exe path is a separate indicator, but the injected code in explorer.exe is the defining evidence of DLL injection.
- C
Process hollowing
Why it fails: Process hollowing replaces the image of a legitimately created suspended process, so the executable path would remain the original one. Here the binary runs from an abnormal path and injects into explorer.exe, which describes process injection or masquerading, not hollowing; hollowing would be the answer if the path stayed System32.
- D
DLL side-loading
Why it fails: DLL side-loading plants a malicious DLL beside a legitimate executable that loads it, so the running binary keeps its trusted path. It is tempting because it also abuses trusted processes, but that suits hijacked DLL search order, not a relocated svchost.exe injecting into explorer.exe.