Courseiva

CHFI Mobile and Malware Forensics Practice Question

During dynamic analysis of a malware sample, an analyst observes the following: creation of a mutex named `Global\{9A2D7E1C-3F4B-4A5E-9B8C-1D2E3F4A5B6C}`, a registry key under `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` named `WindowsUpdate`, and outbound TCP traffic to `203.0.113.5:443`. Which THREE of the following indicators of compromise (IoCs) should be documented?

⚠ Common exam trap

The CHFI exam often tests the distinction between static IoCs (like file hashes) and dynamic IoCs (like network traffic, mutex names, and registry modifications) to see if candidates understand that dynamic analysis focuses on behavioral artifacts, not file-level attributes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Outbound TCP to `203.0.113.5:443`

Option A is correct because the observed outbound TCP connection to 203.0.113.5:443 is a network-based IoC that can be used for detection, blocking, and threat hunting, and the specific IP and port should be documented exactly as observed. Option C is correct because the mutex name Global\{9A2D7E1C-3F4B-4A5E-9B8C-1D2E3F4A5B6C} is a host-based IoC; mutexes are often unique to a malware family or campaign and can be used to identify infection or prevent reinfection. Option E is correct because the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate is a persistence IoC, since the Run key causes the named value to execute at user logon and should be documented for detection and remediation. Option B is not among the observed dynamic behaviors listed in the scenario, even though a sample hash is useful context, and Option D is a legitimate Windows system file path that is not an IoC in this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Outbound TCP to `203.0.113.5:443`

    Why this is correct

    The outbound TCP connection to 203.0.113.5 on port 443 is a classic command-and-control indicator observed during network-level monitoring. Even though this IP falls in the RFC 5737 TEST-NET-3 range often used for documentation, it represents the actual endpoint the malware contacted in the sandbox, demonstrating the value of capturing live connections for threat hunting.

  • ✗

    SHA256 hash of the malware sample

    Why it's wrong here

    A SHA256 hash is a static file artifact, not an observed behavior in dynamic analysis. Dynamic analysis focuses on actions such as network connections, process creation, or registry modifications, all of which are observable in real time. Therefore, the hash cannot be selected as one of the three observed behavioral indicators.

  • ✓

    Mutex name `Global\{9A2D7E1C-3F4B-4A5E-9B8C-1D2E3F4A5B6C}`

    Why this is correct

    The named mutex Global\{9A2D7E1C-3F4B-4A5E-9B8C-1D2E3F4A5B6C} is a unique synchronization object created by the malware to prevent multiple instances of itself from running. Analysts capture this during dynamic analysis by monitoring handles or using tools like Process Monitor. Because the GUID-based name is hard-coded and not commonly found in legitimate software, it acts as a precise fingerprint for detecting this specific malware across other hosts.

  • ✗

    File path `C:\Windows\System32\notepad.exe`

    Why it's wrong here

    The path C:\Windows\System32\notepad.exe is a legitimate, digitally signed Windows component that is frequently loaded by benign programs and even by other malware to run shellcode with a trusted binary. In the observed behaviors, there is no indication that the malware created, modified, or sideloaded this file, so it lacks the specificity required for a reliable IoC. Using a generic system path as an indicator would generate numerous false positives in a real enterprise environment.

  • ✓

    Registry key `HKCU\...\Run\WindowsUpdate`

    Why this is correct

    The registry value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a well-known persistence location that causes a program to execute at each user logon. The malware masquerades as 'WindowsUpdate' to blend in with legitimate maintenance tasks, but the creation or modification of such a value during dynamic analysis is a direct behavioral IoC. It shows the malware's attempt to maintain persistence, a critical indicator for incident response and remediation.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.