EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsEasy

A security operations center (SOC) analyst is reviewing network flow logs and observes an unusual pattern: a large number of outbound connections from an internal server to various external IP addresses on port 25 (SMTP). Further investigation reveals that the server is not authorized to send external email and appears to be sending unsolicited messages. This behavior is indicative of the server being compromised and used to distribute which type of malware?

  1. ASpambot
  2. BRootkit
  3. CKeylogger
  4. DRansomware
Show answer & explanation

Correct answer: A. Spambot

A spambot is a type of bot that is designed to assist in the sending of spam. When a server is compromised and observed sending a large volume of unauthorized external email on port 25, it is acting as a spambot.

Why the other options are wrong

  • B. A rootkit hides its presence and other malicious processes, but its primary function isn't sending spam.
  • C. A keylogger records keystrokes, not sending emails.
  • D. Ransomware encrypts files and demands payment, not primarily sending emails.

Spambot

A program designed to collect email addresses or to send spam emails from a compromised system.

  • Utilizes SMTP (port 25) to send large volumes of unsolicited email.
  • Often part of a botnet.
  • Can be used for phishing, malware distribution, or advertising.

Memory trick: Spam Bots Send Many Emails.

More Malware Threats questions