Skip to content
ScopefileGet the app

Technique fileMalware threats

Virus vs worm vs trojan, and the rest of the malware family

A virus attaches to a host file and spreads when someone runs it; a worm copies itself across networks on its own; a trojan arrives disguised as software the user wants. Rootkits, ransomware, spyware and fileless malware are sorted by what they do once inside.

Exam
312-50
Domain
3 · System hacking
Targets
9

Two axes: spread and staying power

The Malware Threats module is mostly vocabulary, and the vocabulary sorts cleanly on two axes. Propagation is how the code gets from one machine to the next. Persistence is how it survives once there, and how well it hides.

The three headline names split on the first axis. The rest of the family is named for its payload or its hiding method. A short evening with the tables below covers the set; the time saved goes to heavier modules.

The three headline types

Virus, worm and trojan on the propagation axis
TraitVirusWormTrojan
Needs a host file (differs)YesNoIt is the file
Needs a user to run it (differs)YesNoYes
Copies itself (differs)Yes, into other filesYes, across networksNo
Main defense (differs)File scanning, execution controlPatching, segmentationAllowlisting, download hygiene

Tinted rows marked ≠: at least one of the 3 differs from the others.

The rest of the family

Rootkit
Buries itself at a low level of the system, often kernel or boot, so the tools that would find it report a clean machine.
Ransomware
Holds data or systems hostage, usually through encryption, against a payment.
Spyware
Collects information about the user covertly.
Remote Access Trojan (RAT)
A trojan whose payload is a remote-control channel into the machine.
Fileless malware
Runs inside legitimate processes and built-in tools, leaving little on disk for file scanners to find.
Logic bomb
Code that sits dormant until a trigger, such as a date or an event, then runs its payload.

Which family member?

Answered 0/9Hits 0

T-01

Which of the following BEST describes a trojan horse in the context of malware?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AEncrypting user data for extortion describes ransomware, which can arrive by trojan but is a different malware category.
  2. BA vulnerability is a weakness in software, not malicious code; malware may exploit vulnerabilities but is not one itself.
  3. CCorrect: a trojan masquerades as legitimate or useful software and relies on the user to run it, then executes hidden malicious functions.
  4. DSelf-replicating code that spreads without user action describes a worm, whereas a trojan does not replicate on its own.
T-02

What happens during the propagation phase of a worm?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ARemaining dormant until a trigger describes a logic bomb or the dormant phase, not the spreading phase.
  2. BDeleting files is a possible payload, which is separate from how the worm spreads.
  3. CEncrypting files is a ransomware-style payload, not the mechanism by which a worm propagates.
  4. DCorrect: during propagation the worm copies itself to other hosts, usually by exploiting network services, without needing user action.
T-03

Which type of malware restricts access to a system, demanding payment to unlock it?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASpyware secretly collects information about the user, such as keystrokes or browsing habits, rather than locking the system.
  2. BAdware displays unwanted advertising to generate revenue rather than demanding a payment to restore access.
  3. CPhishingware is not a recognized malware category; phishing is a social engineering delivery method.
  4. DCorrect: ransomware encrypts files or locks the system and demands payment, which is why offline backups and tested restores are the key defense.
T-04

What type of malware modifies the operating system's core functionality while hiding its presence from the user and security software?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA worm self-replicates across networks, and hiding inside the operating system is not its defining trait.
  2. BCorrect: a rootkit subverts the operating system or kernel to conceal itself and other malware, which is why offline scans or rebuilding the system are often needed.
  3. CA logic bomb is code that triggers a payload when a condition is met, such as a date, rather than a concealment layer.
  4. DRansomware announces itself by demanding payment, which is the opposite of hiding from the user.
T-05

What is the primary difference between spyware and adware in terms of their intent and functionality?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAdware usually needs network access to fetch and display ads, so working offline is not what separates it from spyware.
  2. BDelivering pop-up ads is the hallmark of adware, so this reverses the two categories.
  3. CCorrect: spyware covertly collects data such as keystrokes or browsing activity, while adware's purpose is to display advertising.
  4. DDeleting system files is not spyware's goal; spyware is harmful because it steals information quietly.
T-06

In the context of malware, what is a Remote Access Trojan (RAT)?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ALegitimate remote administration tools are installed with consent, whereas a RAT is malware even when it offers similar features.
  2. BCorrect: a remote access trojan gives an attacker covert remote control of the victim's machine, typically through a command-and-control channel.
  3. CEncrypting files until a ransom is paid is ransomware, not a remote access trojan.
  4. DSelf-replication across network shares describes a worm or virus, whereas a RAT relies on being installed like any trojan.
T-07

Which of the following statements about fileless malware is TRUE?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AFileless techniques are often more effective because they abuse trusted system tools and evade file-based scanning.
  2. BCorrect: fileless malware runs in memory, often through trusted tools like PowerShell or WMI, leaving few or no malicious files on disk.
  3. CFileless malware is notable for leaving fewer disk artifacts, which complicates forensics.
  4. DIt is harder to detect with signature scanning and usually requires behavioral monitoring, memory analysis or EDR telemetry.
T-08

Which of the following is NOT an example of ransomware?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ALocky is ransomware that spread mainly through malicious email attachments and encrypted victims' files for payment, so it is a valid example.
  2. BWannaCry is the 2017 ransomware worm that spread through the SMBv1 EternalBlue flaw, so it clearly counts as ransomware.
  3. CPetya is ransomware that encrypted the disk's master file table to stop the system from booting, so it is a genuine ransomware example.
  4. DCorrect: Emotet began as a banking trojan and grew into a loader that delivered other malware, including ransomware, but it is not ransomware itself.
T-09

Laura works as a financial analyst at XYZ Corp and has received an Excel spreadsheet from her manager's personal email. She opens the file and it asks her to enable macros. Upon enabling them, her computer starts behaving erratically and several files get corrupted. What type of malware has she MOST LIKELY encountered?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAdware displays unwanted ads and would not normally corrupt files after a macro prompt.
  2. BA rootkit hides malicious activity at a deep system level and is not delivered by enabling spreadsheet macros by definition.
  3. CCorrect: a macro virus lives in document macros, such as in Office files, and runs when the user enables macros, which is why blocking internet macros matters.
  4. DA trojan is any disguised malicious program, but code that runs through enabled spreadsheet macros is more specifically a macro virus.

Detection and analysis

How is malware detected?

Signature detection matches known code patterns and misses anything new. Heuristic and behavior-based detection watch what code does, which catches unknown samples at the cost of more false alarms. Most endpoint products combine both.

What is the difference between static and dynamic analysis?

Static analysis examines a sample without running it: strings, structure, imported functions. Dynamic analysis runs it in an isolated sandbox and records what it does. Analysts usually start static and move to dynamic.

What is an advanced persistent threat?

A well-resourced attacker who gets in quietly and stays for a long time, pursuing a specific goal. The term describes the campaign and the actor more than any one piece of malware.

Does this apply to embedded and industrial devices?

Yes, with a twist. Those devices face their own malware and persistence risks, and availability usually comes first, which limits how they can be scanned and patched; see IoT and OT hacking.