Lesson 13 - Group 1: Malware and Malicious Activity Indicators

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/24

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:33 PM on 7/29/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

25 Terms

1
New cards
Virus
Malware that relies on a host file or media-delivery vector and spreads within code without authorization.
2
New cards
What virus types are listed in Lesson 13?
Non-resident or file infector, memory resident, boot, and script or macro viruses.
3
New cards
Worm
Malware that propagates through memory or network links and may consume bandwidth or crash processes.
4
New cards
Trojan
A malicious program concealed within an apparently benign program.
5
New cards
PUP or PUA
A potentially unwanted program or application, such as bloatware or software installed alongside another application; also called grayware.
6
New cards
Fileless malware
Malware that uses remote execution, memory residence, scripts, the registry, shellcode, or built-in tools rather than relying primarily on files stored on disk.
7
New cards
Living off the land
Abusing legitimate built-in scripting tools or system utilities to perform malicious activity.
8
New cards
What persistence mechanism is associated with fileless malware in Lesson 13?
Registry-based persistence.
9
New cards
Adware
A potentially unwanted program that displays advertising or changes browser settings.
10
New cards
Spyware
Malware that monitors local activity, records information, captures screenshots, or redirects activity.
11
New cards
Keylogger
Software or hardware that records keystrokes.
12
New cards
Backdoor
A method of bypassing normal access controls, created by malware, misconfiguration, or unauthorized software.
13
New cards
RAT
Remote Access Trojan; malware that gives an attacker remote control of a compromised system.
14
New cards
Botnet
A group of compromised hosts controlled through a command-and-control network.
15
New cards
C2 or C&C
Command and control communication used to direct compromised systems.
16
New cards
Rootkit
Malware designed to maintain privileged and concealed access by modifying system files, utilities, logs, or firmware.
17
New cards
What rootkit indicators are listed?
Replacement of key system files, purged logs, SYSTEM or root-level activity, and firmware compromise.
18
New cards
Ransomware
Malware that locks a user out of a system or demands payment to restore access.
19
New cards
Crypto-malware
High-impact ransomware that encrypts data files or storage devices.
20
New cards
Cryptojacking
Unauthorized use of system resources to mine cryptocurrency.
21
New cards
Logic bomb
Malicious code designed to activate when a specified condition is met.
22
New cards
TTP
Tactics, Techniques, and Procedures used by a threat actor.
23
New cards
IoC
Indicator of Compromise; evidence suggesting that malicious activity or compromise occurred.
24
New cards
What framework documents attacker TTPs and IoCs?
MITRE ATT&CK.
25
New cards
What general malware indicators are listed in Lesson 13?
Browser changes, ransomware notifications, suspicious sandbox behavior, high resource consumption, blocked or inaccessible files, account compromise, and missing or out-of-cycle log