CHFI Mobile and Malware Forensics Practice Question
A security analyst observes a process on a Windows system creating a mutex named "Global\{5B9E4E7E-8B2C-4F6D-A1A3-F2C8D9E0A1B2}" shortly after execution. The analyst also notes outbound connections to an IP address 203.0.113.50 on port 4444. Which malware behaviour indicator is MOST clearly demonstrated?
⚠ Common exam trap
EC-Council often tests the distinction between behavioral indicators (like mutex and network connections) and specific malware capabilities (like encryption or persistence), leading candidates to confuse a single-instance safeguard with anti-debugging or persistence techniques.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Single-instance execution safeguard and command and control communication
The mutex name 'Global\{5B9E4E7E-8B2C-4F6D-A1A3-F2C8D9E0A1B2}' is a well-known technique used by malware to ensure only one instance of itself runs on the system, preventing conflicts or multiple infections. The outbound connection to 203.0.113.50 on TCP port 4444 is a classic indicator of command and control (C2) communication, as port 4444 is commonly associated with reverse shells and C2 traffic (e.g., Metasploit default). Together, these two behaviors directly demonstrate single-instance execution safeguard and C2 communication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Anti-debugging technique through timing checks
Why it's wrong here
Anti-debugging via timing checks detects debuggers by measuring elapsed time between instructions, typically using APIs like GetTickCount, QueryPerformanceCounter, or rdtsc, while a debugger's single-stepping inflates these intervals. Mutex creation is an inter-process synchronization primitive used to ensure a single running instance, not a timing-sensitive debugger defense, and the observed outbound connection has no relation to debug detection. Therefore, this option misclassifies the observable behaviors.
- ✓
Single-instance execution safeguard and command and control communication
Why this is correct
The named mutex is a classic single-instance safeguard: malware creates a distinctive mutex (e.g., a hardcoded name) so that if a second copy starts, it detects the existing mutex and exits, preventing duplicate infections or conflicting state. The concurrent outbound network connection is a strong indicator of command-and-control communication, as the process attempts to establish a channel to an external server for instructions or data exfiltration. Together, these two behaviors align with the observed evidence, making this the correct interpretation.
- ✗
File encryption using a hardcoded AES key
Why it's wrong here
File encryption using a hardcoded AES key would manifest as enumerating target directories (e.g., GetFiles/FindFirstFile), reading file contents, and writing encrypted versions, often with an appended extension, while also invoking cryptographic APIs like CryptEncrypt or BCryptEncrypt. The described process only creates a mutex and initiates an outbound connection; there is no indication of file system traversal, file writes, or crypto API usage. Without those I/O and cryptographic artifacts, labeling it as AES-based file encryption is unsupported.
- ✗
Persistence mechanism via registry run keys
Why it's wrong here
Persistence through registry run keys involves modifying the auto-start location via RegSetValueEx on keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\...\RunOnce, ensuring the binary launches at logon or system boot. The observed indicators—a mutex and an outbound connection—do not include registry writes, service creation, or scheduled task registration. As no persistence-related system modification is evidenced, this option does not match the analyst's observations.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.