In this simulation, you will analyze a network compromise involving deceptive software. You will learn to differentiate between malware types based on their execution behavior and delivery methods within an enterprise environment.
CND (312-38) Network Defense Simulation
Network Scenario
The organization's Marketing department reported that a user downloaded a "PDF to DOCX Converter" from a third-party utility site. The application installed and functioned as expected. However, shortly after, the workstation (IP: 10.0.5.122) began initiating encrypted connections to an external IP (84.22.10.45) on port 443, despite the user not having any browser windows open.
- Hostname: MKTG-WS-04
- OS: Windows 10 Enterprise
- User: j.smith
- Action: Suspicious Outbound HTTPS
- Indicator: Periodic beaconing (every 60s)
- Source: pdf_converter.exe
Traffic & Logs
Question
Which of the following is a malicious program that looks like a normal program?
Expert Analysis
Network Observations
In the provided scenario, the network defender observes a classic **Trojan horse** pattern. The malware was masquerading as a legitimate tool (`pdf_converter.exe`). The "Trojan" aspect is the deceptive nature of the file—it provides the promised functionality (converting files) while simultaneously establishing a Command and Control (C2) channel to an external adversary.
Behavior Identification
Unlike a **Worm**, we do not see scanning activity on ports 445 (SMB) or 135 (RPC) directed at other internal hosts. Unlike a **Virus**, this program was a standalone executable that required social engineering (user download) rather than attaching itself to an existing system file. The beaconing traffic (outbound connections every 60 seconds) is indicative of a backdoor component commonly bundled within a Trojan.
Why Choice D is Correct
"D. Trojan horse" is correct because the defining characteristic of a Trojan is its appearance as a useful, legitimate application while hiding malicious payloads.
Why others are wrong
- Impersonation: This is an attack technique (social engineering or protocol spoofing), not a category of malicious software.
- Worm: A worm's primary characteristic is self-replication across networks without human intervention. The logs show no lateral movement.
- Virus: A virus requires a host file to infect and relies on the execution of that host file to propagate. It does not typically pose as a separate "useful" program.
MINI LESSON: Malware Traffic Analysis
Analyze "Egress" traffic. Look for abnormal outbound connections on common ports (443, 80, 53) from unexpected processes. Use EDR (Endpoint Detection and Response) to link network connections back to specific PIDs.
Implement Application Whitelisting and strict Egress Filtering. A Defense-in-Depth strategy would also include Web Content Filtering to block downloads from "unrated" or "utility" categories.