ExamRange

In this simulation, you will analyze a network compromise involving deceptive software. You will learn to differentiate between malware types based on their execution behavior and delivery methods within an enterprise environment.

CND (312-38) Network Defense Simulation

Network Scenario

The organization's Marketing department reported that a user downloaded a "PDF to DOCX Converter" from a third-party utility site. The application installed and functioned as expected. However, shortly after, the workstation (IP: 10.0.5.122) began initiating encrypted connections to an external IP (84.22.10.45) on port 443, despite the user not having any browser windows open.

Asset Information
  • Hostname: MKTG-WS-04
  • OS: Windows 10 Enterprise
  • User: j.smith
Observed Event
  • Action: Suspicious Outbound HTTPS
  • Indicator: Periodic beaconing (every 60s)
  • Source: pdf_converter.exe

Traffic & Logs

Firewall Egress Logs (Zone: LAN -> WAN)
2023-10-25 14:10:01 ALLOW TCP 10.0.5.122:51223 -> 84.22.10.45:443 [SYN]
2023-10-25 14:11:01 ALLOW TCP 10.0.5.122:51240 -> 84.22.10.45:443 [SYN]
2023-10-25 14:12:01 ALLOW TCP 10.0.5.122:51255 -> 84.22.10.45:443 [SYN]
IDS Alerts (Suricata)
ALERT [1:20145:3] ET MALWARE Suspicious SSL Certificate (Common Name: Default City)
WARNING [1:2001:1] ET POLICY Binary Download over HTTP (pdf_converter.exe)

Question

Which of the following is a malicious program that looks like a normal program?