Recognising malware, and the indicators of compromise it leaves
This course teaches SY0-801, the Security+ exam that launches on or around 17 November 2026. If you are booked on SY0-701, which can be taken until 11 June 2027, use our SY0-701 course instead.
Listen to this lesson
Every episode of this course is also a podcast: listen on Spotify.
This episode is a study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.
Objective 2.5 asks you to analyse indicators of malicious activity. This lesson takes malware — what each type is and how it differs from its neighbours — and then the indicators of compromise SY0-801 now names explicitly: the hashes, addresses, processes, files, log gaps, timestamps and account behaviour that tell you something is wrong. It is written the way the objective is scoped: what the evidence looks like and what stops it, not how to build any of it.
Why this matters
This is the largest objective in Domain 2 and it is examined as recognition. You are given symptoms — a user reports something, a log shows something, a tool alerts on something — and asked what it indicates. Getting fast at that is worth more marks here than in almost any other objective, and it is the same skill Domain 4 asks for when you read logs in an investigation.
The trap is that several malware types produce overlapping symptoms, so the distinguishing detail matters. "Files are encrypted" does not separate ransomware from a wiper pretending to be ransomware, and "the machine is slow" describes half this list.
The lesson
Ransomware, trojan, worm, virus, rootkit and the differences that matter
- Virus — attaches itself to a file or program and needs a user action to run and spread. The defining feature is that it needs a host and a human.
- Worm — self-propagating. It spreads across a network without user action, typically through a vulnerable service. Autonomous spread is why worms produce sudden simultaneous infections across many hosts, and why segmentation and patching are their controls.
- Trojan — appears to be something legitimate and desirable. It does not spread itself; it relies on the user installing it. A remote access trojan (RAT) also gives the attacker interactive control.
- Ransomware — denies access to data, usually by encrypting it, and demands payment. Most current operations also steal data first and threaten to publish it, which means backups alone no longer make you whole.
- Rootkit — hides the presence of other malware by subverting the system's own reporting, at user or kernel level. The defining feature is concealment. A kernel-level rootkit cannot be trusted to be found by something running on the same kernel, which is why offline or boot-time scanning exists.
The distinctions the exam tests: virus needs a user, worm does not; trojan needs deception, worm needs a vulnerability; rootkit is about hiding, not about payload.
Spyware, adware, keyloggers, logic bombs and fileless malware
- Spyware monitors activity and reports it — browsing, credentials, documents. Symptoms are subtle by design: new browser extensions, changed search or proxy settings, outbound connections to unfamiliar hosts.
- Adware forces advertising on the user: pop-ups, injected adverts, a changed home page or search engine. It is often bundled with free software. Beyond the nuisance, it tracks browsing, slows the machine, and can serve malicious adverts, so it is a sign that unwanted software got installed.
- Keylogger records keystrokes. It may be software or a small physical device inline with the keyboard — and no software control finds a hardware one. A software keylogger often shows up as an unexpected process hooking input or an unfamiliar scheduled task.
- Logic bomb lies dormant until a trigger — a date, a file appearing, a particular employee's account being disabled. That last trigger is the insider case: the bomb is usually planted by someone with legitimate access well before it fires, so the investigation must look further back than the incident.
- Fileless malware runs in memory without writing an executable to disk, usually by living off the land — using scripting shells, management interfaces and other trusted built-in tools. Signature antivirus is structurally unable to see it: there is no file, or the file is a legitimate signed system binary. What catches it is behaviour — a document spawning a scripting shell that then connects out is anomalous even though every program involved is legitimate. The answers are EDR, script and command-line logging, application control for scripting engines, and removing local admin rights.
Hashes, addresses, domains, malicious processes and file-system artefacts as indicators
An indicator of compromise (IoC) is a piece of evidence that a system has been compromised. The first group are the ones threat feeds share and security tools match on:
- Hash — the cryptographic fingerprint of a malicious file. A match is near-certain proof that file is present; but change one byte and the hash changes, so a hash catches only that exact file.
- IP address — of a command-and-control server, a download site, or a known attacker. Useful but short-lived, because addresses are cheap to change and often shared with innocent services.
- Domain — longer-lived than an address and often more telling. A very recently registered domain, a lookalike of a real one, or a name that looks randomly generated is suspicious in itself.
- Malicious processes — a process with a misspelled system name, running from the wrong folder, started by the wrong parent, or making network connections it has no reason to make.
- File-system artefacts — files that should not be there: executables in temporary or user folders, unexpected scheduled tasks or services, new startup entries, a ransom note, renamed files with a new extension.
Most malware must talk to its operator, and that channel — command and control — is one of the most reliable things to detect. The signature is beaconing: many short, regular connections from one host to the same destination, often outside working hours. What makes it visible is regularity, not content, because the traffic is usually encrypted. Forcing outbound traffic through a proxy, logging DNS, and alerting on newly registered domains turn these indicators into alerts.
A useful ranking: hashes and addresses are easy to match and trivial for an attacker to change; behaviour — what processes do, how they persist, how they communicate — is harder to detect and much harder for an attacker to change.
Tampered logs, odd timestamps, runaway resource use and strings left in plain text
The second group are signs in the system's own records and behaviour:
- Log manipulation — logs cleared, gaps where entries should be, logging disabled, or entries edited. Clearing a log usually generates its own event; on Windows, clearing the security log records that it was cleared. A gap is evidence, not an absence of evidence. The control is sending logs off the host, to a SIEM or write-once storage, as they are created, so an intruder on the host cannot rewrite history.
- Timestamps — activity at hours the user never works, files whose dates are inconsistent with the rest of the system, or file times set to match old system files so a new file blends in. Comparing timestamps from several sources, and keeping clocks synchronised, is what makes inconsistencies visible.
- Excessive resource consumption — a machine pinned at full processor use with nothing running (cryptomining is the classic cause, sometimes noticed first as a cloud bill); disk activity spiking as files are encrypted; outbound bandwidth far above normal as data leaves; memory growing in a process that should be small.
- Plaintext strings — readable text inside a suspicious file or memory image: web addresses, IP addresses, commands, ransom note wording, registry paths. Analysts extract strings as a quick first look at what a sample does. The inverse matters too: credentials found in plain text in scripts, memory or network captures are both a weakness and a sign of what an attacker may have collected.
Lockouts, impossible travel and concurrent sessions: the account-level signs
Some of the clearest indicators are in the identity logs:
- Account lockout — a burst of lockouts across many accounts suggests guessing; a single executive locked out repeatedly may be targeted. A user who reports being locked out without having mistyped anything is worth taking seriously.
- Impossible travel — successful sign-ins from two places further apart than anyone could travel in the time between them. Either the credentials or a session token are in someone else's hands, or a VPN is confusing the picture, which is why it is a lead to investigate rather than proof.
- Concurrent sessions — the same account signed in at once from two devices or locations that do not fit the user's pattern, especially for an account that normally has one.
The controls are MFA, conditional access that challenges or blocks risky sign-ins, and alerting on exactly these patterns.
A quick table for symptom questions:
| Symptom described | Most likely |
|---|---|
| Files renamed with a new extension, ransom note, backups also targeted | Ransomware |
| Many hosts infected within minutes, no user action | Worm |
| One user installed a "free utility", then odd behaviour | Trojan |
| Processes visible to one tool but not to the OS's own | Rootkit |
| Pop-ups, injected adverts, changed home page | Adware |
| Antivirus clean, yet a scripting shell spawned from an office document | Fileless / living off the land |
| Damage triggered on a date, or after an account was disabled | Logic bomb |
| Small regular outbound connections every few minutes | C2 beaconing |
| Security log cleared overnight | Log manipulation |
| Sign-ins from two continents twenty minutes apart | Impossible travel |
What to take into the exam
- Virus needs a user; worm spreads itself; trojan relies on deception; rootkit hides other things.
- Adware is now examined in place of bloatware; fileless malware defeats signatures, and behavioural detection catches it.
- Hashes and IP addresses are precise but easy for an attacker to change; behaviour is the durable indicator.
- A cleared or gapped log is itself an indicator; ship logs off the host.
- Impossible travel and concurrent sessions point to stolen credentials or tokens.
Practise what you just read
1. Many hosts are infected within minutes and no user reports opening anything. What does this most likely indicate?
Select one
Show answer
B. Autonomous spread without user action is the worm's defining feature, typically through a vulnerable network service, and it produces sudden simultaneous infection across many hosts. Segmentation and patching are its controls. A virus needs a user and a trojan needs deception.
2. What is the most reliable network indicator of command-and-control activity from an infected host?
Select one
Show answer
C. Malware must check in with its operator on a schedule, producing many short, regular connections to the same destination. Beaconing is detected by regularity rather than content, which is why it survives encryption; proxy logs, DNS logging and alerts on new domains make it visible.
3. Why does signature-based antivirus structurally fail against fileless, living-off-the-land activity?
Select one
Show answer
D. Fileless malware runs in memory using scripting shells and other signed system tools, so there is no foreign binary for a signature to match. Detection keys on behaviour, such as a document spawning a shell that connects out, which is why the answer is EDR and command-line logging.
Hands-on labs
Part of the free CompTIA Security+ SY0-801 course — 47 lessons and 78 hands-on labs.
This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.