300-215 · Question #13
Refer to the exhibit. What do these artifacts indicate?
The correct answer is B. A malicious file is redirecting users to different domains. From the exhibit, the first artifact (PE32 executable from syracusecoffee.com) and the second artifact (HTML from qstride.com) suggest a staged malware delivery method. The executable and the HTML file are linked to different domains, often indicating redirection or multi-stage…
Question
Refer to the exhibit. What do these artifacts indicate?
Exhibit
Options
- AAn executable file is requesting an application download.
- BA malicious file is redirecting users to different domains.
- CThe MD5 of a file is identified as a virus and is being blocked.
- DA forged DNS request is forwarding users to malicious websites.
How the community answered
(29 responses)- A7% (2)
- B55% (16)
- C28% (8)
- D10% (3)
Explanation
From the exhibit, the first artifact (PE32 executable from syracusecoffee.com) and the second artifact (HTML from qstride.com) suggest a staged malware delivery method. The executable and the HTML file are linked to different domains, often indicating redirection or multi-stage infection strategies, which is common in phishing or malvertising campaigns. The Cisco guide explains this tactic as: "One file may appear benign but can initiate downloads or connections to external resources to fetch additional payloads or redirect users".
Topics
Community Discussion
No community discussion yet for this question.
