Courseiva

Identifying Malware Persistence Mechanisms in Dynamic Analysis

During a malware analysis session, an analyst uses Process Monitor (Procmon) to observe a suspicious executable. Which of the following behavioral indicators would MOST strongly suggest the malware is attempting to establish persistence?

⚠ Common exam trap

EC-Council often tests the distinction between runtime indicators (network connections, mutexes, temp files) and persistence mechanisms (registry Run keys, scheduled tasks, startup folders), so candidates mistakenly pick outbound connections or mutexes as persistence when they are not.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Writing to HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Writing to HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a classic persistence mechanism because Windows automatically launches programs listed in this registry key at user logon. Process Monitor capturing a write to this key directly indicates the malware is configuring itself to run on startup, which is the strongest evidence of persistence among the options.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Making outbound TCP connections to an IP address

    Why it's wrong here

    Making an outbound TCP connection to an IP address is a network artifact that typically indicates command-and-control (C2) beaconing, data exfiltration, or remote command delivery. Persistence, by contrast, requires a mechanism that causes the malware to be re-executed automatically after a reboot or user logon, such as a service, scheduled task, or startup registry key. A single outbound connection is ephemeral and does not by itself re-launch the process, so it is a behavioral indicator rather than a persistence mechanism.

  • ✗

    Creating a named mutex

    Why it's wrong here

    Creating a named mutex is a common synchronization technique used by malware to signal that an instance is already running, preventing multiple simultaneous infections or duplicate execution. A mutex is a kernel object that is automatically destroyed when the creating process exits, so it provides no mechanism to restart the malware after a reboot or logon. The presence of a mutex simply reflects runtime state, not an autostart persistence method.

  • ✓

    Writing to HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    Why this is correct

    Writing to HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a classic persistence technique because entries under this key are executed automatically each time the logged-in user starts a Windows session. This location is attractive to malware since it requires no elevated privileges to modify and survives reboots, allowing the malicious payload to re-launch on every user logon. Removing the registry value eliminates the persistence, which is why it is monitored by tools like Sysinternals Autoruns.

  • ✗

    Creating files in the %TEMP% directory

    Why it's wrong here

    Creating files in the %TEMP% directory is a typical runtime activity used for unpacking components, dropping additional payloads, or staging data for later execution, but it does not establish a path to automatic execution. The %TEMP% folder is user-writable, frequently cleaned by the system and utilities, and files placed there are not automatically executed at startup or logon. Without an associated autostart entry or trigger, temp file creation is an execution artifact, not a persistence mechanism.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on CHFI

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A malware analyst is performing dynamic analysis of a suspected trojan in a sandbox environment. Which of the following behaviours are strong indicators that the malware is establishing persistence on the infected system? (Select THREE.)

hard
  • ✓ A.Creating a scheduled task that runs at system startup
  • ✓ B.Creating a Windows service named 'UpdateService'
  • C.Connecting to an IP address on port 443
  • ✓ D.Writing a value to HKCU\Software\Microsoft\Windows\CurrentVersion\Run
  • E.Creating a mutex named 'Global\MyMutex'

Why A: Option A is correct because creating a scheduled task configured to trigger at system startup (e.g., via schtasks or the Task Scheduler COM API with a boot/logon trigger) is a classic persistence mechanism that ensures the trojan executes automatically after reboots. Option B is correct because registering a Windows service (e.g., through CreateService or sc.exe) allows the malware to be launched by the Service Control Manager at boot, providing durable, privileged persistence. Option D is correct because writing a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run causes the referenced executable to be launched automatically at user logon, a well-known autostart persistence location. Option C is not a persistence indicator; an outbound connection to port 443 typically reflects command-and-control or exfiltration activity, not survival across reboots. Option E is not a persistence indicator either; creating a named mutex such as Global\MyMutex is commonly used for single-instance enforcement or anti-analysis/anti-sandbox checks, not for maintaining execution on the host.

Variation 2. During dynamic analysis of a malware sample, an analyst uses Process Monitor to monitor file system activity. The malware creates a file named 'C:\Users\Admin\AppData\Roaming\svchost.exe'. What does this likely indicate?

medium
  • A.The malware is a legitimate Windows update
  • B.The malware is extracting an archive
  • C.The malware is cleaning up temporary files
  • ✓ D.The malware is attempting to achieve persistence by placing a copy in a user directory

Why D: The creation of a file named 'svchost.exe' in the user's AppData\Roaming directory is a classic persistence technique. By placing a copy of itself with the name of a legitimate Windows system process (svchost.exe) in a user-writable location, the malware aims to execute automatically at startup (e.g., via a registry Run key or scheduled task) while evading suspicion. This is not a legitimate Windows update, as system files reside in C:\Windows\System32, not in a user profile directory.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.