EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsHard
A security analyst is investigating a web server compromise. The attacker gained initial access by exploiting a vulnerability in a web application. The analyst discovers that the attacker then used a script to download and execute additional malicious components directly into the server's memory, without writing any files to disk. This technique allows the malware to evade traditional endpoint detection systems that rely on file-based signatures. Which term best describes this type of malware execution?
- AFile infector virus
- BCompanion virus
- CFileless malware
- DResident virus
Show answer & explanationAnswer & explanation
Correct answer: C. Fileless malware
Fileless malware operates entirely in memory, leveraging legitimate system tools or processes to execute its malicious payload without writing any files to disk. This makes it extremely difficult to detect with traditional signature-based antivirus solutions. The scenario explicitly describes downloading and executing malicious components 'directly into the server's memory, without writing any files to disk'.
Why the other options are wrong
- A. A file infector virus modifies executable files on disk.
- B. A companion virus creates a new executable file that runs before the legitimate program.
- D. A resident virus loads into memory but still typically originates from a file on disk.
Fileless Malware
Malware that operates without leaving a trace on the file system, executing directly in memory by leveraging legitimate system tools.
- Resides only in RAM, making it volatile and difficult to detect.
- Uses 'living off the land' techniques (e.g., PowerShell, WMI).
- Evades traditional signature-based antivirus and forensic analysis.
Memory trick: Fileless Ghosts Live in Memory.