QuestionQ44

Forensics Techniques

Question Image

Refer to the exhibit. What do these artifacts show?

  • A An executable file is requesting an application download.
  • B A malicious file is redirecting users to different domains.
  • C The MD5 of a file is identified as a virus and is being blocked.
  • D A forged DNS request is forwarding users to malicious websites.
Explanation

A network artifact identified as a PE32 executable from an HTTP source indicates an executable involved in an application download. The artifact details do not establish that the file is malicious, that a hash was blocked as a virus, that DNS was forged, or that users were redirected to other domains.

Community Discussion

No comments yet. Be the first to start the discussion!