CHFI Mobile and Malware Forensics Practice Question
During a malware analysis, a suspicious executable is detected. The analyst runs `strings` on the binary and finds references to `SOFTWARE\Microsoft\Windows\CurrentVersion\Run` and a URL `http://evil.com/beacon`. What does this indicate?
⚠ Common exam trap
EC-Council often tests the distinction between persistence mechanisms (like registry Run keys) and other malware behaviors (like file infection or privilege escalation), so candidates mistakenly associate any registry reference with file infection or confuse a URL with an exploit payload.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The malware establishes persistence and communicates with a remote server
The presence of a registry key reference to `SOFTWARE\Microsoft\Windows\CurrentVersion\Run` indicates the malware is configured to launch automatically at system startup, establishing persistence. The embedded URL `http://evil.com/beacon` suggests the malware will make outbound HTTP requests to a remote command-and-control (C2) server for beaconing or data exfiltration. Together, these artifacts confirm persistence and remote communication, making option C correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The malware is a file infector that modifies system binaries
Why it's wrong here
A file infector propagates by appending or prepending its payload to legitimate executables, modifying machine code so that the host triggers the virus when run. No such alteration of PE files, libraries, or system binaries was observed in the sandbox; instead, the artifact merely dropped a Run registry value and opened a socket, which is behavioral evidence of persistence and C2, not binary infection.
- ✗
The malware uses a mutex for synchronization
Why it's wrong here
A mutex is a kernel object used to prevent concurrent execution of multiple malware instances; analysts typically detect it via strings, handle listings, or deadlock behavior. Here, no mutex-related strings or duplicate-process anomalies were found, and the artifact's observed actions—registry manipulation and outbound network traffic—indicate a logic focused on persistence and remote control rather than inter-process synchronization.
- ✓
The malware establishes persistence and communicates with a remote server
Why this is correct
The executable created a Run registry key (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) to ensure it launches on every user logon, and it resolved and contacted an external URL, exfiltrating data or receiving commands. This combination of an autostart mechanism and a remote communication channel is the classic signature of a backdoor or RAT, making persistence and C2 the correct characterization of its behavior.
- ✗
The malware performs privilege escalation via a known vulnerability
Why it's wrong here
Privilege escalation would typically require exploitation of a known vulnerability (e.g., a kernel CVE) or an insecure service configuration, which would manifest as specific API calls, token manipulation, or exploit payload strings. This sample's analysis showed no such indicators—no vulnerability signatures, no unusual privilege token changes, and no exploit code—so elevating privileges was not among its observed objectives.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.