What Type of Malware Mimics svchost.exe and Lacks Digital Signature?
During a forensic investigation, you find a file named 'svch0st.exe' in the startup folder. The file has a suspicious icon and was downloaded from an untrusted source. Analysis shows it opens a backdoor on port 4444 and sends system information to a remote server. Which THREE best describe this malware and its characteristics?
⚠ Common exam trap
Many exam-takers confuse a RAT with a worm or virus, but the key differentiator is that a RAT provides remote access without self-replication, while worms spread automatically and viruses require a host file to replicate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It functions as a remote access Trojan (RAT)
Option A is correct because a program that covertly opens a backdoor on port 4444 and accepts remote commands is functioning as a remote access Trojan (RAT), giving an attacker interactive control of the host. Option B is correct because the file masquerades as a legitimate executable (svch0st.exe mimicking svchost.exe), was downloaded from an untrusted source, and hides malicious functionality, which is the defining behavior of a Trojan horse. Option E is correct because the malware sends system information to a remote server, which is data exfiltration over the network to an attacker-controlled endpoint. Option C is not correct because nothing in the scenario indicates self-mutating code or signature changes on each execution, which would be required for a polymorphic virus. Option D is not correct because there is no evidence of self-replication or automatic propagation across the network, which is the defining trait of a worm.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It functions as a remote access Trojan (RAT)
Why this is correct
A Remote Access Trojan (RAT) like 'svch' establishes a covert communication channel, often a backdoor, allowing an attacker to remotely control the compromised system. It facilitates unauthorized access to files, execution of commands, and monitoring of user activity, effectively turning the victim's machine into a remote puppet. This capability to open a backdoor and send information is a hallmark of RAT functionality, enabling persistent and stealthy control.
- ✓
It is classified as a Trojan horse
Why this is correct
This file is classified as a Trojan horse because it deceptively masquerades as a legitimate system process, 'svchost.exe', to trick users or system administrators into executing it. Unlike viruses or worms, a Trojan horse does not self-replicate but relies on social engineering or other vulnerabilities for initial infection. Its malicious payload, once executed, then performs unauthorized actions under the guise of a benign program.
- ✗
It is a polymorphic virus that changes its signature each time it runs
Why it's wrong here
This file is not a polymorphic virus because there is no indication it modifies its own code or encryption key with each execution to evade signature-based detection. Polymorphic viruses dynamically alter their internal structure while retaining their original functionality, creating numerous unique variants. The observed behavior of 'svch' aligns with a static Trojan, which maintains a consistent signature unless manually updated by an attacker.
- ✗
It is a worm that replicates across the network automatically
Why it's wrong here
The file 'svch' is not a worm because it lacks the inherent self-replication mechanisms necessary to spread autonomously across a network without user intervention. Worms actively exploit network vulnerabilities or protocols to propagate themselves to other systems, often without requiring a host file. This particular malware, functioning as a Trojan, requires execution on the target system and does not possess the capability to independently spread to other machines.
- ✓
It is capable of exfiltrating data to a remote server
Why this is correct
The file 'svch' is indeed capable of exfiltrating data, meaning it can illicitly transfer sensitive information from the compromised system to a remote server controlled by the attacker. This typically involves collecting system configurations, user credentials, personal files, or other valuable data. The ability to send this collected information to an external command-and-control server is a critical function for many malicious payloads, including RATs, enabling intelligence gathering and further exploitation.
Go deeper
Related to this question
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.