NEW
Font size
WorksheetsWhat is a Trojan? And Its Indications
Total questions: 36
Worksheet time: 18mins
Which statement best defines a computer Trojan as described in the material?
A self-replicating program that spreads without user action
A program in which malicious or harmful code is contained inside an apparently harmless program or data, later gaining control and causing damage
A security tool that prevents unauthorized access by encrypting data
A network monitoring utility used to detect malware
According to the origin story used in the text, the term "Trojan" is inspired by which event from Greek mythology?
The voyage of Odysseus
The battle of Thermopylae
The Trojan War involving a giant wooden horse used to infiltrate Troy
The creation of Mount Olympus
What typically activates a Trojan on a victim’s system?
Automatic OS updates
User performing certain predefined actions, such as unintentionally installing malicious software or clicking a malicious link
Physical access by the attacker to the machine
A server-side script running on the network
Which is NOT listed as a way hackers use Trojans?
Disable firewalls and antivirus
Record screenshots, audio, and video of a victim’s PC
Use the victim’s PC as a botnet to perform DDoS attacks
Automatically patch the victim’s OS with security updates
Which method describes how attackers may propagate Trojans using victims as intermediaries?
By forcing users to change their passwords frequently
By wrapping malicious code to legitimate programs and using a victim’s computer to commit illegal DoS attacks
By disabling internet connectivity entirely
By installing only signed drivers
Once a Trojan infects a system, what level of privileges does it typically operate with?
Higher than kernel level
Lower than guest account
The same level of privileges as the victim, and it may exploit vulnerabilities to elevate privileges
No privileges until approved by the administrator
Which network scenario increases risk if compromised by a Trojan, according to the text?
Systems using multi-factor authentication only
Systems that transmit passwords over shared networks in clear text or trivially encrypted form
Air-gapped systems without network connectivity
Networks with only IPv6 addresses
Which of the following is an indication of a Trojan attack related to display behavior?
The monitor physically turns off
The computer screen flips upside-down, is inverted, or displays everything backward
Only brightness reduces to minimum
The resolution changes to 4K
Which symptom indicates possible interference with system controls by a Trojan?
The keyboard backlight turns blue
The mouse cursor moves by itself or clicks icons uncontrollably
USB ports become faster
Battery life improves
Which set best groups multiple signs of a Trojan attack affecting system components?
Antivirus automatically updates; browser loads faster; OS boots quicker
Antivirus is disabled and data is corrupted or deleted; Task Manager is disabled; unusual high CPU or memory usage
New fonts appear; printer toner is low; wallpaper remains unchanged
System fan becomes louder; external speakers disconnect; screen saver stays default
Which of the following is a malicious purpose for which attackers deploy Trojans?
Installing operating system updates
Generating fake traffic to perform DoS attacks
Encrypting data for secure communication
Training users on security best practices
In the context of Trojan activity, what does the "listening" state indicate?
The system is actively blocking all ports
The system waits on a port number to connect to another system
The port is reserved for hardware devices only
The Trojan has completed data transfer and shut down
Which sensitive information is specifically mentioned as targeted by Trojans using keyloggers?
Biometric fingerprints
Credit card information useful for domain registration and shopping
Encrypted VPN keys
Source code repositories
According to the table of common ports, which Trojan is associated with port 25?
WinCrash
Antigen
Hackers Paradise
BadPatch
What is a possible post-compromise use of infected devices as described?
Serving as botnets to launch DDoS attacks, send spam emails, or mine cryptocurrencies
Automatic patch management for enterprises
Hosting secure backups for users
Running intrusion detection systems
Which ports are listed for Emotet in the table?
21
5321
6666
6969
Which statement best describes network ports as used by Trojans?
Ports are only physical connectors on hardware
Ports within the OS are software entry/exit points for application traffic, some application-specific or process-specific
Ports can only be used by web browsers
Ports are random numbers with no association to traffic types
Which Trojan commonly uses port 7000?
Remote Grab
NetMonitor
Net Spy
Qaz
Port 7777 is associated with which Trojan?
BADCALL
GodMsg
ICKiller
Ptakks
Which Trojan is mapped to port 8787/54321?
BackOffice 2000
NetBus
GirlFriend 1.0
Delta
Which Trojan pair is listed for port 20034/1120?
Back Orifice / Deep BO
NetBus 2.0, Beta-NetBus 2.01
GabanBus, NetBus
Hack’99 KeyLogger
DeepThroat is shown to use which ports?
2140
2140/3150
31339
31666
Which category best describes malware that provides full remote control over a victim system?
Backdoor Trojans
Remote Access Trojans
Botnet Trojans
Command Shell Trojans
Which statement best describes a Remote Access Trojan (RAT)?
A benign remote administration tool used for IT support
Malware that provides attackers full control over a victim’s system, enabling remote access to files and activities
A firewall rule that blocks unauthorized ports
A hardware device used to sniff network traffic
In the example scenario, how does Jason establish control over Rebecca’s computer?
By sending a phishing email with a malicious macro that opens Port 25
By infecting the system with server.exe and planting a reverse connecting Trojan that connects through Port 80
By exploiting a misconfigured VPN to gain shell access on Port 443
By physically inserting a USB drive and copying RAT binaries
Which capability is commonly associated with RATs as described in the material?
Encrypting hard drives to demand ransom only
Performing screen and camera capture, keylogging, file access, and registry management
Providing automatic system patching and antivirus updates
Limiting network downloads to prevent malware spread
What notable shift in attack vectors did recent analyses report for Remcos RAT distribution?
Use of ISO images
Use of virtual hard disk (.vhd) files with multifaceted capabilities
Exclusive use of malicious browser extensions
Transition to hardware-based implants
According to the extracted VHD file flow diagram, which sequence correctly reflects the layered execution chain?
AMSI Reaper → PowerShell script → PNG to PDF → Task Schedule → VB script → Remcos RAT → .NET binary
PNG to PDF → AMSI Reaper → VB script (base64 decode) → PowerShell script → Download elena.png → Image base64 decode → .NET DLL
PowerShell script → AMSI Bypass → VB Script → Direct RAT execution without downloads
Task Schedule → Immediate RAT execution bypassing any scripts
Which PowerShell behavior is specifically highlighted in the screenshot showing the download of a PDF disguised as PNG?
Writing registry keys to disable Defender directly
Using Invoke-WebRequest to download a file and decoding base64 data to output a PDF
Scheduling a task that runs a batch file every hour
Running a WMI query to enumerate installed software
Which item from the list is an example of an additional RAT mentioned in the material?
Wireshark
Parallax RAT
OpenSSH
Burp Suite
What is a common method used by attackers to disguise Trojans?
Using strong encryption to hide the payload
Creating a separate operating system for execution
Utilizing cloud storage for distribution
Embedding malicious code in legitimate software
Which of the following is a sign that a Trojan may be present on a system?
Improved system performance
Unexpected pop-up ads and browser redirects
Increased battery life on laptops
Frequent system updates
What type of data is often targeted by Trojans for exfiltration?
Software installation logs
System configuration files
User credentials and personal information
Temporary internet files
What type of malware is designed to capture keystrokes and send them to an attacker?
Spyware
Worms
Keyloggers
Adware
Which of the following is a common technique used to deliver Trojans to unsuspecting users?
Direct installation via USB
Bundling with legitimate software
Using hardware backdoors
Only through email attachments
What is the primary goal of a Trojan horse in a cybersecurity context?
To protect against malware
To improve user experience
To enhance system performance
To provide unauthorized access to the system
