Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium
A security analyst is investigating a compromised endpoint. During the forensic analysis, they discover that the malware found on the system changes its signature and characteristics each time it infects a new system or even within the same system over time. What type of malware is this?
- ATrojan
- BRansomware
- CRootkit
- DPolymorphic Malware
Show answer & explanationAnswer & explanation
Correct answer: D. Polymorphic Malware
Polymorphic malware is a type of malware that constantly changes its identifiable features (e.g., file hash, code structure) while retaining its core functionality. This makes it difficult for signature-based antivirus and intrusion detection systems to detect and block, as the 'signature' is never static.
Why the other options are wrong
- A. A Trojan disguises itself as legitimate software but does not inherently change its signature to evade detection.
- B. Ransomware encrypts data and demands payment, and while it can be polymorphic, its primary characteristic isn't signature change but data encryption.
- C. A rootkit is designed to hide its presence and the presence of other malicious software, not to change its signature.
Polymorphic Malware
Malware that changes its underlying code or signature (e.g., file hash, encryption key, instruction order) each time it replicates or executes, while maintaining its original function. This technique is used to evade detection by signature-based antivirus software and intrusion detection systems.
- Constantly changes its signature.
- Evades signature-based detection.
- Relies on a mutation engine.
- Core functionality remains the same.
Memory trick: Polymorphic malware is like a chameleon, always changing its skin.