Courseiva

CHFI Mobile and Malware Forensics Practice Question

During a forensic examination of a Windows system infected with ransomware, the analyst finds that the file timestamps (creation, modification, access) for several critical system files have been altered to match legitimate Windows files. Which anti-forensic technique is MOST likely being used?

⚠ Common exam trap

EC-Council often tests the distinction between timestomping (altering file timestamps) and log wiping (removing event logs), so the trap here is that candidates may confuse 'log wiping' with any timestamp-related manipulation, but log wiping specifically targets event logs, not file metadata.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Timestomping

Timestomping is the deliberate alteration of file timestamps (creation, modification, access) to mislead forensic investigators. In this scenario, the ransomware modified critical system file timestamps to match legitimate Windows files, which is the hallmark of timestomping. This technique is commonly used to evade timeline analysis and hide the true sequence of malicious activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data hiding via ADS

    Why it's wrong here

    Data hiding via Alternate Data Streams (ADS) is an NTFS feature that allows additional data streams to be attached to a file, such as 'file.txt:hidden.exe'. While this can conceal malicious payloads from casual directory listings, it does not modify file timestamps; the original timestamps remain intact. Forensic examiners can detect ADS using tools like streams.exe or through NTFS parsing, making it a distinct technique from timestamp alteration.

  • ✗

    Steganography

    Why it's wrong here

    Steganography involves embedding secret data within other benign files, such as images or audio, by altering their binary content (e.g., LSB substitution). This technique hides the existence of the data itself, but it does not touch file system metadata like MAC times (Modify, Access, Change). Timestamps are preserved unless deliberately changed, and steganalysis focuses on statistical anomalies in the carrier file, not timestamp forensics.

  • ✗

    Log wiping

    Why it's wrong here

    Log wiping specifically targets event logs, such as Windows Event Logs (e.g., Security.evtx), by clearing entries or selectively deleting records to remove traces of an attacker's actions. It does not affect file system timestamps on user files or executables; it only manipulates log files themselves. Therefore, while log wiping is an anti-forensic activity, it is not the technique for modifying file timestamps to evade analysis.

  • ✓

    Timestomping

    Why this is correct

    Timestomping is an anti-forensic technique that deliberately alters a file's timestamps—such as creation, modification, and access times—typically on NTFS by modifying $STANDARD_INFORMATION or $FILE_NAME attributes. Attackers use it to make malicious files appear old, legitimate, or to match expected system activity, thereby evading investigative timelines. Detection often relies on inconsistencies between MFT attributes, USN journal entries, or comparing timestamps against volume shadow copies and prefetch data.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.