CHFI Mobile and Malware Forensics Practice Question
A security analyst is reviewing output from a Cuckoo Sandbox analysis of a suspicious executable. The report shows that the process created a mutex named 'Global\GLOBAL_MUTEX_123' and modified the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\. Which behavioral indicator is MOST evident?
⚠ Common exam trap
EC-Council often tests the distinction between user-level persistence (HKCU Run) and system-level persistence (HKLM Run or services), and candidates may confuse the registry modification with privilege escalation or C2 activity because they see 'Run' and assume it implies higher privileges or network communication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Persistence mechanism
The modification of the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a classic persistence mechanism. This key is automatically processed by Windows Explorer at user logon, causing any executable listed there to run. Combined with the mutex creation (which prevents multiple instances), the behavioral indicator is clearly an attempt to establish persistence on the host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Command and control communication
Why it's wrong here
C2 communication requires observable network artifacts such as DNS requests, HTTP/S calls, IRC, or beaconing traffic to a remote server. The described output centers on a modification to the HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key, which is a local change with no accompanying packet captures, domain names, or connection logs. Without an outbound connection or command-channel trace, classifying any activity as command and control is unsupported by this evidence.
- ✓
Persistence mechanism
Why this is correct
The Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a well-known autorun persistence location that executes a designated binary every time the targeted user logs on. By adding a value here, malware ensures it survives reboots and is relaunched automatically, a behavior that directly maps to the MITRE ATT&CK technique T1547.001 (Registry Run Keys / Startup Folder). In a sandbox report, seeing this registry modification is strong evidence the sample is establishing persistence, making this the correct classification.
- ✗
Anti-debugging technique
Why it's wrong here
Anti-debugging techniques are typically implemented through specific API imports or checks such as IsDebuggerPresent, NtQueryInformationProcess with ProcessDebugPort, or timing anomalies to detect breakpoints. A mutex, even if present, is used primarily for anti-multiple-instance protection or ensuring a single infection, not for thwarting debuggers. The observed registry write to the Run key is unrelated to detecting debugger presence, and the stem provides no evidence of debugger-aware behavior such as exception-based tricks or timing checks.
- ✗
Privilege escalation
Why it's wrong here
Privilege escalation requires the malware to elevate from the current user token to a higher integrity level, admin or SYSTEM, usually via an exploit, UAC bypass, or service abuse. Writing a value to HKCU\Software\...\Run operates entirely within the current user's registry hive and needs no elevated privileges, so it cannot by itself demonstrate any attempt to increase access rights. Without any loaded kernel driver, token manipulation, or event showing UAC/admin access, there is no basis to conclude privilege escalation occurred.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.