300-215 · Question #22
Refer to the exhibit. According to the Wireshark output, what are two indicators of compromise for detecting an Emotet malware download? (Choose two.)
The correct answer is A. Domain name: iraniansk.com D. filename= "Fy.exe". From the Wireshark capture: A (iraniansk.com): This domain is not a known legitimate resource and is hosting a suspicious file named "Fy.exe," strongly indicative of a malware distribution domain. D (Fy.exe): The Content-Disposition: attachment; filename="Fy.exe" header…
Question
Refer to the exhibit. According to the Wireshark output, what are two indicators of compromise for detecting an Emotet malware download? (Choose two.)
Exhibit
Options
- ADomain name: iraniansk.com
- BServer: nginx
- CHash value: 5f31ab113af08=1597090577
- Dfilename= "Fy.exe"
- EContent-Type: application/octet-stream
How the community answered
(44 responses)- A82% (36)
- B9% (4)
- C7% (3)
- E2% (1)
Explanation
From the Wireshark capture: A (iraniansk.com): This domain is not a known legitimate resource and is hosting a suspicious file named "Fy.exe," strongly indicative of a malware distribution domain. D (Fy.exe): The Content-Disposition: attachment; filename="Fy.exe" header explicitly signals a binary executable download, a key indicator in Emotet campaigns.
Topics
Community Discussion
No community discussion yet for this question.
