ExamGecko
Question list
Search
Search

Related questions











Question 445 - 312-50v12 discussion

Report
Export

Mason, a professional hacker, targets an organization and spreads Emotet malware through malicious script. After infecting the victim's device. Mason further used Emotet to spread the infection across local networks and beyond to compromise as many machines as possible. In this process, he used a tool, which is a self-extracting RAR file, to retrieve information related to network resources such as writable share drives. What is the tool employed by Mason in the above scenario?

A.
NetPass.exe
Answers
A.
NetPass.exe
B.
Outlook scraper
Answers
B.
Outlook scraper
C.
WebBrowserPassView
Answers
C.
WebBrowserPassView
D.
Credential enumerator
Answers
D.
Credential enumerator
Suggested answer: D

Explanation:

https://us-cert.cisa.gov/ncas/alerts/TA18-201ACurrently, Emotet uses five known spreader modules: NetPass.exe, WebBrowserPassView, Mail PassView, Outlook scraper, and a credential enumerator. Credential enumerator is a self- extracting RAR file containing two components: a bypass component and a service component. The bypass component is used for the enumeration of network resources and either finds writable share drives using Server Message Block (SMB) or tries to brute force user accounts, including the administrator account. Once an available system is found, Emotet writes the service component on the system, which writes Emotet onto the disk. Emotet's access to SMB can result in the infection of entire domains (servers and clients).

asked 18/09/2024
Ramon Pasay
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first