CHFI · domain
Malware Forensics
Malware Forensics covers identifying, containing, and analyzing malicious code on Windows systems using forensic tooling. Questions present exhibits of command output, memory dumps, or infected workstations and ask you to conclude the malware type, persistence mechanism, or next investigative step. Expect scenarios on ransomware, trojans, and pop-up/adware infections with artifacts from live response and memory analysis.
Focused practice
Practice Malware Forensics questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Malware Forensics
You must analyze live response output and memory dumps to identify malware type, persistence, and infection vector, then recommend containment. The single most important thing is correlating process, network, and autorun artifacts to confirm malicious activity rather than guessing from symptoms alone.
Interpreting netstat, tasklist, and autoruns output to spot malicious processes and persistence
Using Volatility plugins like pslist, netscan, and malfind on acquired memory dumps
Identifying ransomware indicators such as encrypted file extensions and ransom notes
Tracing initial infection vectors from email attachments and downloaded installers
Watch out for
Common Malware Forensics exam traps
- ▸Assuming a slow system with high network use is malware without correlating process, connection, and autorun artifacts
- ▸Confusing legitimate Windows processes with malware solely by name instead of checking path, hash, and parent process
- ▸Relying only on disk artifacts and ignoring volatile memory evidence that reveals injected code and active connections
Question index
All Malware Forensics questions (11)
Click any question to see the full explanation, or start a practice session above.
An organization suspects a stealthy malware infection on a critical server. Traditional antivirus and EDR solutions have not detected anything. Which forensic approach would be most effective in identifying the malware, given that it likely resides only in memory?
Hard2A forensic examiner is analyzing a potentially malicious Portable Executable (PE) file recovered from a compromised host. The examiner uses PEStudio to inspect the file and notices that the Import Address Table (IAT) contains only two functions: LoadLibraryA and GetProcAddress. Which of the following does this most likely indicate?
Medium3Refer to the exhibit. During a malware investigation, a forensic analyst runs the commands shown. What is the most likely conclusion?
Medium4You are investigating a Windows 10 workstation that exhibits slow performance and frequent pop-ups. The user reports that the system started acting strangely after installing a 'PDF Converter' from an email attachment. You suspect malware. You have captured a memory dump using FTK Imager and a network capture during the infection. In the memory dump, you find a suspicious process 'conhost.exe' running from a non-standard location (C:\Users\Public\Temp). The process has an open handle to a file named 'config.ini' in the same directory. The network capture shows periodic HTTPS connections to 'malicious.com' on port 443 from the workstation's IP. Using Volatility, you extract the process's command line: 'conhost.exe -hidden -log C:\Users\Public\Temp\output.log'. Which of the following is the BEST immediate course of action to contain the threat and preserve evidence?
Hard5You are a forensic analyst investigating a Windows workstation that shows signs of malware infection. The user reports that the system is slow, network activity is high, and several files have been encrypted with a .encrypted extension. A ransom note named README.txt has been left on the desktop demanding payment. You have acquired a memory dump using FTK Imager and a disk image using dd. You need to identify the malware family and gather indicators of compromise (IOCs). Which of the following is the MOST appropriate first step?
Easy6During malware analysis, an investigator finds that a suspicious process is injecting code into a legitimate system process (e.g., explorer.exe). Which technique is being used?
Medium7You are a forensic analyst investigating a suspected malware infection on a Windows 10 workstation. The user reports that the system has been slow and that unexpected pop-ups appear. You have acquired a memory dump and a disk image. During analysis, you find a suspicious process named 'svch0st.exe' running with PID 4567. The process has loaded several DLLs, including 'wininet.dll' and 'ws2_32.dll'. You also find that the process has an active TCP connection to an external IP address 203.0.113.5 on port 4444. In the disk image, you find an executable file at C:\Users\Public\svch0st.exe with a creation date that matches the start of symptoms. The file's hash is not in any known malware database. You decide to perform dynamic analysis by running the file in a sandbox. However, the sandbox environment has no network connectivity. The executable runs but does not exhibit any malicious behavior. What should you do next to determine if the file is malicious?
Medium8Refer to the exhibit. An investigator is examining a disk image using TSK. The output from 'fls' shows the directory structure. What is the significance of the entry 'V/V 113-128-1: $OrphanFiles'?
Hard9A forensic investigator is examining a suspicious file and wants to determine its true file type regardless of its extension. The investigator runs the 'file' command on the file and receives the output 'PE32 executable (GUI) Intel 80386, for MS Windows'. However, the file has a .txt extension. What is the most likely explanation for this discrepancy?
Easy10Based on the exhibit, what is the most likely indication of malware persistence?
Medium11A forensic analyst is investigating a malware incident on a Windows system and suspects that the malware uses process injection to execute malicious code within a legitimate process. The analyst has acquired a memory dump of the system. Which two of the following techniques should the analyst use to detect and analyze process injection? (Choose two.)
HardOther domains
All CHFI exam domains
Frequently asked questions
- What does the Malware Forensics domain cover on the CHFI exam?
- You must analyze live response output and memory dumps to identify malware type, persistence, and infection vector, then recommend containment. The single most important thing is correlating process, network, and autorun artifacts to confirm malicious activity rather than guessing from symptoms alone.
- How many questions are in this domain?
- This page lists all 11 Malware Forensics questions in the CHFI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Malware Forensics questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.