nerdexam
Cisco

300-215 · Question #22

Refer to the exhibit. According to the Wireshark output, what are two indicators of compromise for detecting an Emotet malware download? (Choose two.)

The correct answer is A. Domain name: iraniansk.com D. filename= "Fy.exe". From the Wireshark capture: A (iraniansk.com): This domain is not a known legitimate resource and is hosting a suspicious file named "Fy.exe," strongly indicative of a malware distribution domain. D (Fy.exe): The Content-Disposition: attachment; filename="Fy.exe" header…

Submitted by valeria.br· Mar 6, 2026Forensics Techniques

Question

Refer to the exhibit. According to the Wireshark output, what are two indicators of compromise for detecting an Emotet malware download? (Choose two.)

Exhibit

300-215 question #22 exhibit

Options

  • ADomain name: iraniansk.com
  • BServer: nginx
  • CHash value: 5f31ab113af08=1597090577
  • Dfilename= "Fy.exe"
  • EContent-Type: application/octet-stream

How the community answered

(44 responses)
  • A
    82% (36)
  • B
    9% (4)
  • C
    7% (3)
  • E
    2% (1)

Explanation

From the Wireshark capture: A (iraniansk.com): This domain is not a known legitimate resource and is hosting a suspicious file named "Fy.exe," strongly indicative of a malware distribution domain. D (Fy.exe): The Content-Disposition: attachment; filename="Fy.exe" header explicitly signals a binary executable download, a key indicator in Emotet campaigns.

Topics

#Wireshark#network traffic analysis#Emotet#Indicators of Compromise (IoC)

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice