EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesHard
A blue team analyst is investigating a Windows server after a successful phishing attack led to initial compromise. They discover that a legitimate system utility, `svchost.exe`, is running from an unusual directory (`C:\Temp\` instead of `C:\Windows\System32\`) and is making suspicious outbound connections. What type of attack technique is this most indicative of?
- ADenial of Service (DoS)
- BProcess Hollowing/Spoofing
- CSQL Injection
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: B. Process Hollowing/Spoofing
Running a legitimate-looking process like `svchost.exe` from an unusual directory, especially when combined with suspicious network activity, is a strong indicator of process hollowing or spoofing. This technique involves injecting malicious code into a legitimate process or replacing a legitimate process with a malicious one to evade detection.
Why the other options are wrong
- A. DoS aims to disrupt service availability, not typically to gain and maintain access by masquerading processes.
- C. SQL Injection is a web application vulnerability, not a technique for executing malware on a system.
- D. XSS is a client-side web vulnerability, not related to server-side process execution.
Process Hollowing/Spoofing
Process hollowing (or runpe) is a code injection technique where an attacker creates a legitimate process in a suspended state, hollows out its legitimate code, and then injects and executes malicious code within that process's memory space.
- Aims to evade detection by security software (antivirus, EDR).
- Makes malicious activity appear as legitimate system processes.
- Often involves creating a new process from a legitimate binary in an unusual location, then injecting malicious code.
Memory trick: Malware in disguise, hiding in plain sight!