QuestionQ403

Logs and Network Forensics

During dynamic malware analysis, an investigator runs a suspicious file in a controlled lab environment and captures network traffic that shows outbound connections to an unfamiliar remote address. Before reaching conclusions about the malware’s behavior, the investigator must establish whether the observed address is associated with known malicious infrastructure.

How should the investigator evaluate the nature of this remote address?

  • A Monitor live network traffic for suspicious activity
  • B Execute the suspected malware on the workstation
  • C Scan the IP address using online malware-analysis services
  • D Run Wireshark on Windows forensic workstation
Explanation

An online malware-analysis or threat-intelligence service can assess an IP address against reputation data, blocklists, vendor detections, and related indicators to identify associations with known malicious infrastructure. VirusTotal’s IP address reports provide threat reputation and context from multiple security products and datasets.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!