350-201 · Question #77
An employee abused PowerShell commands and script interpreters, which lead to an indicator of compromise (IOC) trigger. The IOC event shows that a known malicious file has been executed, and there…
The correct answer is A. ExecutedMalware.ioc. Crossrider is a an Adware variant that targets Mac with the intent of displaying ads. It also changes the default home page of Safari and Chrome browsers. W32.AccesschkUtility.ioc Accesscheck is a Windows utility that lets users check for access rights on resources including…
Question
An employee abused PowerShell commands and script interpreters, which lead to an indicator of compromise (IOC) trigger. The IOC event shows that a known malicious file has been executed, and there is an increased likelihood of a breach. Which indicator generated this IOC event?
Options
- AExecutedMalware.ioc
- BCrossrider.ioc
- CConnectToSuspiciousDomain.ioc
- DW32 AccesschkUtility.ioc
How the community answered
(22 responses)- A91% (20)
- C5% (1)
- D5% (1)
Explanation
Crossrider is a an Adware variant that targets Mac with the intent of displaying ads. It also changes the default home page of Safari and Chrome browsers. W32.AccesschkUtility.ioc Accesscheck is a Windows utility that lets users check for access rights on resources including files, directories, registry keys, global objects and Windows services. This utility could be used by malware or threat actors with malicious intent such as collection of information necessary for privilege escalation on the compromised host. This indicator monitors for accesschk tool used with suspicious options that suppress errors and dialog boxes. ExecutedMalware.ioc A known malicious file was executed. This increases the likelihood of a successful breach and this event should be promptly investigated.
Topics
Community Discussion
No community discussion yet for this question.