EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesHard

A blue team analyst is investigating a Windows server after a successful phishing attack led to initial compromise. They discover that a legitimate system utility, `svchost.exe`, is running from an unusual directory (`C:\Temp\` instead of `C:\Windows\System32\`) and is making suspicious outbound connections. What type of attack technique is this most indicative of?

  1. ADenial of Service (DoS)
  2. BProcess Hollowing/Spoofing
  3. CSQL Injection
  4. DCross-Site Scripting (XSS)
Show answer & explanation

Correct answer: B. Process Hollowing/Spoofing

Running a legitimate-looking process like `svchost.exe` from an unusual directory, especially when combined with suspicious network activity, is a strong indicator of process hollowing or spoofing. This technique involves injecting malicious code into a legitimate process or replacing a legitimate process with a malicious one to evade detection.

Why the other options are wrong

  • A. DoS aims to disrupt service availability, not typically to gain and maintain access by masquerading processes.
  • C. SQL Injection is a web application vulnerability, not a technique for executing malware on a system.
  • D. XSS is a client-side web vulnerability, not related to server-side process execution.

Process Hollowing/Spoofing

Process hollowing (or runpe) is a code injection technique where an attacker creates a legitimate process in a suspended state, hollows out its legitimate code, and then injects and executes malicious code within that process's memory space.

  • Aims to evade detection by security software (antivirus, EDR).
  • Makes malicious activity appear as legitimate system processes.
  • Often involves creating a new process from a legitimate binary in an unusual location, then injecting malicious code.

Memory trick: Malware in disguise, hiding in plain sight!

More System Hacking Phases and Attack Techniques questions