CompTIA CySA+ (CS0-003)Security OperationsHard
Windows Security Event Log Event ID 4688 shows the following process creation entry on a user workstation: `New Process Name: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe` `Creator Process Name: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE` `Process Command Line: powershell.exe -nop -w hidden -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQA...` Which of the following BEST explains this event?
- AA scheduled task created by Group Policy for patch management
- BA malicious macro spawning an obfuscated, fileless PowerShell payload
- CA print spooler service exploit unrelated to Office
- DA legitimate Word mail-merge macro generating a report
Show answer & explanationAnswer & explanation
Correct answer: B. A malicious macro spawning an obfuscated, fileless PowerShell payload
Microsoft Word (WINWORD.EXE) spawning powershell.exe as a child process, using -nop (no profile), -w hidden (hidden window), and -enc (Base64-encoded command), is a strong indicator of a malicious macro executing an obfuscated, fileless PowerShell payload — a common technique to evade static file-based detection.
Why the other options are wrong
- A. Group Policy scheduled tasks would not originate from WINWORD.EXE as the parent process.
- C. Print spooler exploits involve spoolsv.exe, not Word spawning PowerShell.
- D. Legitimate mail-merge operations do not spawn hidden, encoded PowerShell processes.
Fileless Malware via Office Macro
An attack technique where a malicious Office document macro spawns PowerShell with encoded/hidden flags to execute payloads in memory, avoiding disk-based detection.
- Office app (WINWORD.EXE/EXCEL.EXE) as parent process of powershell.exe is suspicious
- -enc, -nop, -w hidden flags indicate obfuscation and stealth
- Event ID 4688 logs process creation with command-line auditing enabled
Memory trick: A document that secretly whispers hidden PowerShell commands.