Skip to content
ScopefileGet the app

Module 7Domain 3 of 9System Hacking Phases and Attack Techniques

Malware threats and how they are analyzed

CEH Malware Threats, Module 7, covers how malicious software is classified, analyzed and stopped: eight families told apart by what they need to spread and what they cost the victim, the split between static and dynamic analysis, and the first control that answers each family.

Exam
312-50
Domain
3 of 9
Domain weight
15%
This file
~6%
Targets
17

The malware families, defined by what they need

Virus
Code that attaches to a host file, boot record or document and runs when that host runs. It needs someone or something to execute the infected host, so it spreads only as fast as files are shared.
Worm
Standalone code that copies itself across a network with no host file and no user action. It needs unpatched network-facing services and flat networks; the effect is fast spread and a drain on bandwidth.
Trojan
A program that looks useful and carries a hidden malicious function. It needs the user to install or run it willingly, and it does not replicate on its own.
Rootkit
Software whose job is concealment: it tampers with the operating system at user, kernel, boot or firmware level so other malicious components stay hidden. It needs administrative or kernel privilege; the effect is a host that reports itself clean.
Ransomware
Malware that encrypts or locks data and demands payment, often adding a threat to publish stolen files. MITRE files the encryption step as Data Encrypted for Impact (T1486). It needs broad write access to data; the effect is lost availability.
Spyware and keyloggers
Software that records activity, keystrokes or credentials and sends them out. It needs a compromised endpoint and costs confidentiality, often with no visible symptom at all.
Fileless malware
Malicious code that lives in memory and works through built-in administration and scripting tools instead of a dropped executable. It needs trusted utilities that are allowed to run without limits, and it leaves little on disk for file scanning to inspect.
APT
An advanced persistent threat is a long-running, targeted intrusion by a well-resourced group. It needs to stay unnoticed for months; the effect is sustained data theft from one chosen organization.

Telling the families apart from symptoms

Classifying a family from what an analyst observes comes down to three questions: did it need a host file, did it need a person to act, and which part of confidentiality, integrity and availability did the victim lose?

  • Many machines infected in minutes, nobody opened anything: worm. Expect connection attempts fanning out from internal hosts.
  • Every victim opened the same shared document or program: virus, and a macro virus when the host is an office file.
  • Software that does what it promised plus something extra: trojan. The clue is that the user installed it on purpose.
  • Host tools report nothing, but an outside scan, a memory image or a boot from clean media shows extra processes, ports or files: rootkit.
  • A ransom note and files that no longer open: ransomware. This one announces itself.
  • Quiet, steady data loss with no disruption: spyware or a keylogger on one device; stretch the timeline to months against a single target and the answer becomes APT.
  • Suspicious work done by built-in admin or scripting tools, and no new program on disk: fileless.

The full side-by-side of replication, persistence and delivery for each family lives on virus vs worm vs trojan and the rest of the malware family.

Samples stay in the lab, inside the scope

Live samples belong in an isolated lab, cut off from production and reset to a clean snapshot after each run, and only where an engagement contract or employer policy allows it. Running an unknown sample on a production host, or moving it outside the agreed scope, breaks both containment and the rules of engagement.

Static against dynamic analysis

The two analysis methods Module 7 names, side by side
QuestionStatic analysisDynamic analysis
Is the sample run (differs)No. The file is examined at restYes, inside an isolated sandbox or lab VM
What you learn (differs)File type, hashes, embedded strings, imported functions, file structureProcesses started, files and registry keys changed, network destinations contacted
What it misses (differs)Anything hidden by encryption or decided only at run timeCode paths that wait for a trigger the lab never supplies, such as a date
Risk to your environment (differs)LowHigher; needs containment and a snapshot reset
What defenders get out of it (differs)Hashes and strings for detection rulesIndicators to block and hunt across the fleet
Done in an isolated, authorized labYesYes

Tinted rows marked ≠: the two differ.

Rule of thumb: analysis that never executes the sample is static, whichever tool performs it.

Family, weakness, first control, signal

Six families against the weakness they need, the first control and the signal to watch
Matrix of six malware families with the weakness each relies on, the first control that closes it and the signal a defender watches for. Rootkit paired with a host view that disagrees with an outside view is highlighted.WeaknessFirst controlDefender seesVirusUsers run infectedfilesAnti-malware, macrolimitsSame file on eachvictimWormExposed, unpatchedservicesPatch, segmentFan-out between hostsTrojanUsers installanythingAllowlisting, noadminExtra function in atoolRootkitAdmin or kernelrightsSecure boot, leastprivilegeHost and outsidedisagreeRansomwareBroad write accessLeast privilege onsharesRansom noteFilelessUnlimited admin toolsConstrain scriptenginesAdmin tools, odd work

Drill Module 7

Take these once the matrix makes sense. The wrong-option notes sort out the near neighbors from the list above.

Answered 0/17Hits 0

T-01

During an assessment, traditional antivirus produces no alerts, but an Endpoint Detection and Response (EDR) solution flags rapid, sequential file modifications. Which conclusion is MOST accurate regarding the endpoint's status?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASignature-based antivirus only catches known patterns, so its silence does not prove the endpoint is clean.
  2. BCorrect: rapid sequential file modifications are a behavioral sign of ransomware or similar activity that signature-based tools can miss.
  3. COS telemetry and patching do not typically rewrite large numbers of user files in rapid succession.
  4. DDismissing the alert as indexing without investigation is risky; background indexing reads files rather than modifying them rapidly.
T-02

A security analyst suspects a fileless malware infection on a workstation. To resolve an active performance issue, the user rebooted the system. What is the primary operational consequence of this reboot?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: fileless malware often lives only in memory, so a reboot erases processes, injected code and network state that responders need to capture first.
  2. BA reboot does not delete Windows event logs, which persist on disk across restarts.
  3. CA reboot may trigger persistence an attacker already set up, but the key forensic consequence is losing volatile memory evidence.
  4. DRebooting a workstation has no effect on remote attacker infrastructure such as staging servers.
T-03

In the context of malware threats, which of the following tools combines a keylogger executable with a legitimate-looking PDF document?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA crypter encrypts or obfuscates malware to evade antivirus detection rather than combining it with another file.
  2. BCorrect: a wrapper, also called a binder, combines a malicious executable with a legitimate file so the victim sees the document while the payload runs.
  3. CAn obfuscator makes code harder to read or analyze but does not bundle it with a decoy document.
  4. DAn injector inserts code into running processes rather than packaging malware together with a legitimate file.
T-04

An alert indicates rapid, mass file-change events across several network drives. Which specific telemetry marker most strongly suggests this is a scheduled administrative task rather than active ransomware?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: activity from a known service account that matches its usual network baseline points to scheduled administration rather than an intruder.
  2. BDeleting volume shadow copies is a hallmark of ransomware preparing to block recovery, so it points toward an attack.
  3. CChanged file headers plus dropped text files describe encryption with ransom notes, a strong ransomware indicator.
  4. DUniformly encrypted files with a new extension are typical ransomware output, not routine administrative work.
T-05

Which incident response action should be taken immediately to stop the spread of a ransomware attack on a corporate network?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AShutting down every server causes widespread outage and destroys volatile evidence; containment should be targeted.
  2. BCorrect: isolating the infected system from the network contains the spread while preserving it for investigation.
  3. CDisabling all accounts disrupts the entire business and does not stop malware already running on infected hosts.
  4. DNotifying users matters for awareness, but it does not technically contain an active infection.
T-06

A high-entropy binary alert triggers on an endpoint. Before automatically isolating the host and declaring the packed file malicious, which contextual metadata should an analyst check FIRST?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: legitimate installers are often packed and high-entropy, so a valid digital signature and known deployment pattern can quickly rule out a false positive.
  2. BReflective DLL injection is an attack technique to look for later, not contextual metadata to check before deciding.
  3. CBeaconing analysis is useful during investigation but is not the quickest first check on whether a packed binary is a legitimate installer.
  4. DShellcode execution from memory is evidence of compromise you might find later, not initial metadata to validate the alert.
T-07

Which security measure ensures data availability in case of data corruption caused by ransomware?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APassword complexity makes accounts harder to guess, but it cannot restore data that ransomware has encrypted.
  2. BDDoS protection keeps services reachable under traffic floods, not data recoverable after corruption.
  3. CFirewall rules may limit how ransomware spreads, but they do not recover files once they are encrypted.
  4. DCorrect: regular backups, ideally offline or immutable, let organizations restore corrupted data without paying a ransom.
T-08

An attacker uses reflective DLL injection, writing no files to disk. Which detection strategy is MOST effective for identifying this specific in-memory payload execution?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AWatching the timing of normal outbound connections may catch beaconing later, but it does not observe the in-memory loading itself.
  2. BCorrect: Event Tracing for Windows can expose suspicious API call sequences, such as memory allocation and remote thread creation, typical of in-memory loading.
  3. CHash-based allowlisting checks files before execution, so a payload that never touches disk is not evaluated by it.
  4. DStatic file scanning only inspects files on disk, which this technique avoids entirely.
T-09

Implementing application whitelisting, regularly updating antivirus software, and conducting frequent security audits are countermeasures that can defend against what?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APrivilege escalation is addressed more directly by least privilege, patching and configuration hardening than by antivirus updates.
  2. BCorrect: allowlisting stops unapproved executables, updated antivirus catches known threats, and audits reveal weak spots, together forming a malware defense.
  3. CPhishing is countered mainly through user awareness, email filtering and authentication controls rather than application allowlisting.
  4. DDoS attacks are mitigated with capacity, filtering and upstream protection, not allowlisting or antivirus.
T-10

A security analyst reviewing DNS query logs notices an endpoint repeatedly attempting to resolve domains such as "qkxvzmypwt.com" and "brzfljxcqa.net". Which malicious behavior is MOST likely generating this specific type of network traffic?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA denial-of-service attack would show high query volume against servers, not one endpoint resolving a stream of random-looking names.
  2. BTyposquatted domains resemble real brands with small misspellings, whereas these names are random character strings.
  3. CDeprecated TLD queries would involve consistent, meaningful names, not ever-changing random labels under common TLDs.
  4. DCorrect: random-looking, high-entropy names that mostly fail to resolve are the classic sign of a domain generation algorithm searching for its command-and-control server.
T-11

During a cybersecurity simulation, you sent an email to an employee with an attachment named 'Invoice_Update.pdf'. The employee downloaded and opened the file, which gave you unauthorized access to their computer. What type of malware did you use in this scenario?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA worm spreads automatically across networks without user action, whereas this infection required opening an attachment.
  2. BSpyware covertly gathers information but is defined by its spying function, not by disguising itself as a legitimate file.
  3. CAdware displays unwanted advertisements and is not designed to provide remote access to a computer.
  4. DCorrect: a Trojan disguises itself as something legitimate, such as an invoice, so the user runs it and grants the attacker access.
T-12

Which action would NOT prevent the WannaCry ransomware from spreading on a network?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABlocking SMB at the firewall interrupts the port 445 channel the WannaCry worm used to spread between hosts.
  2. BDisabling the legacy SMBv1 protocol removes the vulnerable service that the EternalBlue exploit relied on.
  3. CCorrect: WannaCry propagated as a worm over SMB without needing email, so a spam filter does nothing to stop its spread inside a network.
  4. DMicrosoft's MS17-010 patch fixed the SMBv1 flaw WannaCry exploited, so patching stops its propagation.
T-13

During an active malware incident, a manager insists on immediately reimaging all affected hosts to restore operations. What is the PRIMARY risk of this approach?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ALegal notification matters, yet the most direct and immediate risk of instant reimaging is destroying forensic data before anyone has captured it.
  2. BReintroducing the original weakness is a real concern, but it follows from skipping root cause analysis, which is exactly what losing volatile evidence prevents.
  3. CReimaging affected endpoints does not normally touch backup infrastructure, so backup destruction is not the primary risk of this decision.
  4. DCorrect: reimaging wipes memory, running processes and live connections, destroying the evidence needed to find the entry point, persistence and other compromised hosts.
T-14

Which of the following is NOT a common technique used in detecting malware?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: configuring a firewall is a preventive network control that filters traffic, not a method for detecting malware on systems.
  2. BHeuristic analysis inspects code characteristics and behavior to catch unknown or modified malware.
  3. CAnomaly detection flags deviations from normal system or network behavior, which can reveal malware activity.
  4. DSignature-based detection compares files to known malware patterns and remains a staple of antivirus engines.
T-15

Which of the following is NOT effective in preventing spyware infections?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AHardening browser settings, such as blocking pop-ups and untrusted downloads, reduces spyware infection paths.
  2. BCorrect: browser speed has no bearing on security and does nothing to prevent spyware from being installed.
  3. CUpdated antivirus can recognize and block known spyware before it takes hold.
  4. DRegular audits reveal unauthorized software and weak configurations, helping prevent and catch spyware.
T-16

During an active ransomware incident, an organization determines that patient health records have been accessed. Beyond immediate technical containment, which action is MOST critical according to incident response frameworks?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APaying a ransom guarantees neither deletion nor silence, may breach sanctions rules, and never replaces legally required breach handling.
  2. BPublic statements may come later, but launching a press campaign before compliance review skips the regulated notification process that frameworks require.
  3. CPublishing indicators on social media is uncoordinated disclosure that can tip off attackers and does nothing to meet regulatory obligations.
  4. DCorrect: once protected health information is accessed, involving compliance and legal teams and following breach-reporting rules such as HIPAA becomes a required part of the response.
T-17

An analyst reviewing firewall logs notices outbound DNS requests to an unknown domain at exact 15-minute intervals. The request payloads are small. What behavior does this temporal pattern most likely represent?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA DDoS generates large volumes of traffic, not small queries to one domain at precise intervals.
  2. BCorrect: small requests to an unknown domain at exact intervals match command and control beaconing, where malware checks in for instructions.
  3. COS update checks go to known vendor domains and are not usually locked to exact 15-minute intervals.
  4. DAn external vulnerability scan is inbound traffic, whereas these are outbound DNS requests from inside the network.

Keep-list and skip-list for the final week

  • Keep: the three questions (host file, user action, which part of CIA). They classify every family on this page.
  • Keep: static means not executed, dynamic means executed in isolation.
  • Keep: one first control per family from the matrix.
  • Keep: live samples stay in an isolated lab and inside written scope.
  • Skip until last: named historical outbreaks and their years. Cram, use, dump.
  • Skip until last: analysis-tool brand names. Learn which method a tool belongs to first.

Malware threats: four follow-ups

Is ransomware a separate family or a kind of trojan?

One sample can carry both labels, because they answer different questions. Ransomware names the effect: data encrypted or locked for payment, which MITRE catalogs as Data Encrypted for Impact (T1486). Virus, worm and trojan name how code arrives and spreads, so ransomware hidden in a fake installer is a trojan by delivery and ransomware by payload.

Why do rootkits and keyloggers also show up under system hacking?

EC-Council's v13 course outline lists keyloggers, spyware and rootkits under Module 6 as tools for keeping access and hiding activity (eccouncil.org, as of Oct 11, 2026). Module 7 treats the same software as malware families: what it needs, what it costs and what stops it. Learn the definition once and it serves both modules.

Can a weak score here sink the whole exam?

Not on its own. EC-Council says there is no one-to-one relationship between your percentage per section and your pass or fail result, and that cut scores range from 60% to 85% depending on the exam form (EC-Council certification FAQ and CEH certification page, as of Oct 11, 2026).

What should I study right after malware threats?

Module 8, sniffing and the switch features that defend against it. It opens the Network and Perimeter Hacking domain, the heaviest on the blueprint at 24% (blueprint v5.0, as of Oct 11, 2026); the habit carries over: name the weakness, then the control.

Sources