Courseiva
Malware Forensics →mediumMultiple Choice

CHFI Malware Forensics Practice Question

Exhibit

Refer to the exhibit.

C:\> tasklist /svc
Image Name                     PID Services
========================= ======== ============================================
svchost.exe                   1236 CryptSvc, Dnscache, LmHosts, EventSystem
svchost.exe                   1344 W32Time, WdiServiceHost
svchost.exe                    768 BFE, MpsSvc
notepad.exe                   1456 N/A
svchost.exe                    524 SessionEnv, TermService, UmRdpService
rundll32.exe                  1500 N/A

C:\> netstat -ano | findstr :4444
  TCP    0.0.0.0:4444           0.0.0.0:0              LISTENING       1500

C:\> wmic process where processid=1500 get executablepath
ExecutablePath
C:\Windows\System32\rundll32.exe

Refer to the exhibit. During a malware investigation, a forensic analyst runs the commands shown. What is the most likely conclusion?

⚠ Common exam trap

EC-Council often tests the ability to correlate netstat output (port and PID) with tasklist output (PID and process name) to identify suspicious process-port pairs, and the trap here is assuming that svchost.exe is always the culprit when a backdoor is present, when in fact rundll32.exe is a common masquerading host for injected code.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rundll32.exe with PID 1500 is likely a backdoor listening on port 4444.

The netstat output shows a listening connection on port 4444 associated with PID 1500, which the tasklist command identifies as rundll32.exe. Port 4444 is a common backdoor port (often used by Metasploit or other RATs), and rundll32.exe is a legitimate Windows binary frequently abused by malware to host malicious code (e.g., via DLL sideloading or reflective injection). The combination of an unusual listening port and a process that is not a typical network service (like svchost.exe) strongly indicates a backdoor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Svchost.exe processes are hosting legitimate Windows services; no malware is present.

    Why it's wrong here

    While it is true that Windows routinely runs multiple svchost.exe instances to host a variety of legitimate system services, the exhibit shows a network socket bound to port 4444, which is not a standard service port. Any process, including svchost.exe, listening on port 4444 is highly anomalous and typically indicates a backdoor or command-and-control channel. This option simply dismisses the suspicious connection, so it fails to recognize the evidence of compromise.

  • ✗

    The malware has injected code into svchost.exe using a reflective DLL injection tool.

    Why it's wrong here

    Reflective DLL injection is a sophisticated technique that loads a malicious DLL entirely from memory into a process without touching disk, but there is no indication in the exhibit that svchost.exe has been injected in this manner. The observed suspicious traffic and listening socket are attributed to rundll32.exe with PID 1500, not to svchost.exe. Thus, this option incorrectly attributes the infection to the wrong process and misreads the network evidence.

  • ✗

    The malware is using port 4444 for Windows Update communications.

    Why it's wrong here

    Windows Update communicates over HTTP/HTTPS, typically using TCP ports 80 and 443, to reach Microsoft's servers; it never uses port 4444. Port 4444 is a common default for Metasploit payloads, EternalBlue exploits, and other remote-access Trojans. Therefore, this option is factually impossible because the port usage does not align with Windows Update's known networking behavior.

  • ✓

    Rundll32.exe with PID 1500 is likely a backdoor listening on port 4444.

    Why this is correct

    rundll32.exe is a legitimate Windows binary used to load and execute functions exported from DLLs, but by default it does not create network listeners. When a rundll32 process is observed listening on TCP port 4444—a port heavily associated with Metasploit and backdoor payloads—it strongly suggests that the process has loaded a malicious DLL that opens a remote command shell. The combination of an unusual process acting as a network server on a non-standard port is classic evidence of a backdoor.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.