Courseiva
Malware Forensics →easyMultiple Choice

CHFI Malware Forensics Practice Question

You are a forensic analyst investigating a Windows workstation that shows signs of malware infection. The user reports that the system is slow, network activity is high, and several files have been encrypted with a .encrypted extension. A ransom note named README.txt has been left on the desktop demanding payment. You have acquired a memory dump using FTK Imager and a disk image using dd. You need to identify the malware family and gather indicators of compromise (IOCs). Which of the following is the MOST appropriate first step?

⚠ Common exam trap

EC-Council often tests the principle of 'triage before deep analysis'—candidates mistakenly choose sandboxing (B) or static analysis (C) first, but the exam expects you to start with the most accessible, high-value IOC source (the ransom note) to quickly identify the malware family.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Extract the ransom note and search for known ransomware identifiers such as Bitcoin wallet addresses or contact email.

The ransom note (README.txt) is a primary source of ransomware identifiers such as Bitcoin wallet addresses, contact emails, or Tor payment site URLs. Extracting these IOCs from the note allows you to quickly cross-reference known ransomware families (e.g., Ryuk, Maze, LockBit) via threat intelligence feeds, which is the most efficient first step in malware forensics before deeper analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Extract the ransom note and search for known ransomware identifiers such as Bitcoin wallet addresses or contact email.

    Why this is correct

    Ransom notes typically contain unique attribution artifacts—Bitcoin/cryptocurrency wallet addresses, victim IDs, Tor payment portal URLs, or contact emails—that can be cross-referenced against threat intelligence feeds (e.g., Abuse.ch, NoMoreRansom, or vendor reports) to pinpoint the exact ransomware family and, often, the specific variant and version. Extracting and parsing these identifiers is non-destructive, requires no special tooling, and gives the analyst a focused search target before investing time in malware dynamic analysis. This IOC-led approach is the fastest way to transition from an unknown incident to a known threat profile, enabling immediate acquisition of family-specific decryption tools, YARA rules, and network indicators.

  • ✗

    Run the malware sample in a sandbox environment to observe its behavior.

    Why it's wrong here

    Sandboxing the malware sample is a valid later step, but as a first action it violates basic forensic triage because the ransomware binary may not have been properly recovered, isolated, or hashed from the evidence image; running an unvalidated sample risks accidental re-infection or incomplete behavioral capture due to sandbox evasion. The ransom note, by contrast, contains non-executable textual IOCs that immediately identify the family without needing to execute unknown code. Moreover, behavioral analysis should be performed on the actual sample extracted from the memory dump or disk image, not as a substitute for reading the victim's leave-behind note, and doing so prematurely could bypass the low-risk intelligence coup the note provides.

  • ✗

    Perform static analysis of the encrypted files to determine the encryption algorithm used.

    Why it's wrong here

    Static analysis of encrypted files is largely an exercise in frustration because the ciphertext yields little to no useful information about the encryption algorithm or the key—most modern ransomware use hybrid cryptography (e.g., AES for bulk data and RSA or ECC for key wrapping), and without the private key or known plaintext, you cannot recover meaningful data or derive variant indicators from the file contents alone. The encrypted files' extensions or headers might hint at a family, but those are far less specific than the unique wallet addresses and contact data in the ransom note. The correct investigative step is to leverage the note's embedded identifiers to look up the known encryption scheme from public threat research, rather than attempting to reverse-engineer the algorithm from ciphertext.

  • ✗

    Immediately disconnect the system from the network and power it off to preserve evidence.

    Why it's wrong here

    While disconnecting the network is a sound containment measure, immediately powering off the system is contraindicated because you have already captured a memory dump—the most volatile evidence—and a hard shutdown will destroy transitional data, such as encryption keys lingering in RAM, running process state, and open network connections, that could be crucial for decryption. A forensic analyst should perform orderly shutdown procedures only after all volatile evidence has been collected and after documenting the system state; halting the system first would also lose any ransomware artifacts still only in memory, including the in-memory malware code itself. Since the memory dump is already taken, the next logical step is not to power off but to examine easily accessible non-volatile artifacts like the ransom note to progress the investigation without evidence loss.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.