CHFI Mobile and Malware Forensics Practice Question
A malware analyst is analyzing a suspicious executable. Which THREE of the following are valid indicators of compromise (IoCs) that can be extracted from static analysis of the PE file? (Select THREE)
⚠ Common exam trap
EC-Council often tests the distinction between static and dynamic analysis, trapping candidates who confuse runtime artifacts (like registry or file system changes) with data extractable from the PE file itself without execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IP addresses from embedded strings
Option A is correct because static analysis of a PE file routinely includes extracting embedded strings, and hardcoded IP addresses or URLs found in the binary are classic network-based IoCs that can be used for blocking and detection. Option C is correct because the MD5 hash of the file is a cryptographic file-based IoC computed directly from the sample without executing it, allowing analysts to pivot in threat-intelligence platforms and write hash-based detection rules. Option E is correct because the PE import table is parsed statically, and the list of imported DLLs and functions (e.g., CreateRemoteThread, VirtualAllocEx, WinINet APIs) reveals capabilities and is a valid host/behavioral IoC used in YARA and hunting rules. Option B is not correct because registry keys modified during execution can only be observed through dynamic analysis (e.g., Procmon, Regshot), not from static inspection of the PE file. Option D is not correct because file paths created during execution are also runtime artifacts revealed by dynamic analysis or sandboxing, not extractable from the static structure of the executable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IP addresses from embedded strings
Why this is correct
IP addresses embedded in the binary are static indicators because a strings extraction (e.g., `strings` or `floss`) can reveal them directly from the file bytes without executing the sample. These addresses often point to hardcoded command-and-control servers, and can be correlated with threat-intel feeds or observed network traffic. The malware analyst can triage the sample purely from static artifacts, making this a valid static IoC.
- ✗
Registry keys modified during execution
Why it's wrong here
Registry keys modified during execution are dynamic indicators because they only become observable when the sample runs and the malware's behavior alters the host system. Extracting them requires executing the binary in a sandbox or using API-monitoring tools, which is not part of static file analysis. Since the question targets indicators obtainable from the binary itself, registry modifications are not static IoCs.
- ✓
MD5 hash of the file
Why this is correct
The MD5 hash is a static identifier computed by applying the MD5 message-digest algorithm to the entire file, producing a unique 128-bit value that changes if even a single byte is modified. It is obtained purely from the file's byte content, requiring no execution, and is used to query malware repositories such as VirusTotal. This makes an MD5 hash a definitive static indicator of compromise for file identification and correlation.
- ✗
File paths created during execution
Why it's wrong here
File paths created during execution are dynamic indicators because they are artifacts left on disk when the malware runs its payload, and they must be observed with filesystem monitoring or process tracing in a controlled environment. These paths are not encoded in the PE headers or recoverable by static parsing; they depend on runtime conditions such as the current user profile directories and the malware's installation routine. Thus, they are inappropriate as static indicators.
- ✓
List of imported DLLs and functions
Why this is correct
The list of imported DLLs and functions resides in the portable-executable import table, which records dynamic-link library dependencies and the functions the malware can invoke, such as `CreateProcess` or `InternetOpenUrl`. Parsing this table from the PE headers is a static analysis step that reveals the API surface and helps infer the sample's capabilities without executing it. Because the import table is stored in the file itself and directly accessible, these imports constitute a static indicator.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.