CompTIA CySA+ (CS0-003)Security OperationsMedium
A malware analyst detonates a suspicious executable in an isolated sandbox and observes the following behavior report: Process: invoice.exe -> spawns svchost.exe -> injects code into svchost.exe memory space -> svchost.exe opens outbound connection to 185.203.x.x:443 Which technique is the malware most likely using to evade detection?
- AProcess injection into a legitimate system process
- BDLL sideloading from a trusted directory
- CDomain generation algorithm (DGA) for C2 resolution
- DTimestomping of file metadata
Show answer & explanationAnswer & explanation
Correct answer: A. Process injection into a legitimate system process
The malware spawns and injects its code directly into the memory of the legitimate svchost.exe process, then uses that trusted process to make the outbound connection—this is process injection, used to hide malicious activity behind a legitimate process.
Why the other options are wrong
- B. DLL sideloading involves tricking an app into loading a malicious DLL, not injecting code into another running process's memory.
- C. DGA involves algorithmically generating domain names, but the report shows a static IP connection, not domain resolution.
- D. Timestomping alters file creation/modification timestamps, which is not described in the report.
Process Injection
A malware evasion technique where malicious code is injected into the memory space of a legitimate running process to hide activity and evade detection.
- Common target: svchost.exe, explorer.exe
- Hides malicious network/behavior under a trusted process name
- Detected via sandbox dynamic analysis or EDR memory scanning
Memory trick: Injection = a parasite hiding inside a trusted host body.