Courseiva

CHFI Mobile and Malware Forensics Practice Question

During malware analysis, an analyst discovers that a sample uses a technique to modify its own code at runtime to evade signature detection. Which anti-forensic technique does this describe?

⚠ Common exam trap

The CHFI exam often tests the distinction between encryption as a general concept and packing/obfuscation as a specific anti-forensic technique that combines encryption with runtime code modification to evade static signature detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Packing/Obfuscation

The technique of modifying code at runtime to evade signature detection is known as packing or obfuscation. Packers compress or encrypt the original executable and wrap it with a small stub that decompresses or decrypts the code in memory during execution, thereby altering the static file signature. This runtime modification allows the malware to bypass signature-based antivirus and forensic tools that rely on static analysis of the binary on disk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Log wiping

    Why it's wrong here

    Log wiping is an anti-forensics technique used to erase system or application logs, such as clearing Windows Event Logs with tools like wevtutil or PowerShell commands, to remove traces of malicious activity. This process affects only log files and metadata, leaving the malware's binary and runtime code untouched. In this scenario, the analyst observed the sample modifying its own code at execution time, which is a runtime, code-level transformation entirely distinct from deleting or altering log entries. Therefore, while log wiping may be part of an evasion strategy, it does not account for self-modifying behavior.

  • ✓

    Packing/Obfuscation

    Why this is correct

    Self-modifying code is a hallmark of packing and obfuscation, as malicious samples often decrypt, decompress, or rewrite their own instruction stream in memory before execution. This runtime mutation is exactly what packers like UPX or custom crypters achieve by using a stub that unpacks the original code into memory, so the on-disk representation appears static while the executing image evolves. Such behavior directly matches the analyst's observation, making packing/obfuscation the correct answer because the code's self-modification is a deliberate obfuscation technique designed to evade static signatures and hinder analysis.

  • ✗

    Encryption

    Why it's wrong here

    Encryption is a data-protection mechanism that transforms plaintext into ciphertext using algorithms like AES or XOR, but it does not inherently modify the executable code segments that are being run. While malware may encrypt its payload, configuration strings, or communication channels, self-modifying code specifically involves rewriting instructions at runtime, which is a different level of alteration within the execution context. The observed sample is changing its own machine code as it runs, not merely decrypting data for use. Thus, encryption can be a supporting tool, but it does not explain the runtime code mutation seen by the analyst.

  • ✗

    Timestomping

    Why it's wrong here

    Timestomping is a file-forensics evasion technique that alters a file's creation, modification, and access timestamps using tools like SetMACE or touch commands, making malicious artifacts appear older or matching legitimate system files. This modifies metadata stored in the file system, not the actual code content or in-memory instructions of the malware. A sample that changes its own code during execution is performing active code mutation in memory, which is fundamentally different from changing timestamp values on disk. Consequently, while timestomping is another anti-forensics method, it is unrelated to self-modifying behavior and cannot be the correct answer.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.