Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 112-57 Exam - Topic 7 Question 11 Discussion

Which of the following types of phishing attacks allows an attacker to exploit instant messaging platforms by employing IM as a tool to spread spam?
C) Spimming
A) Whaling
B) Pharming
D) Spear phishing

Eccouncil 112-57 Exam - Topic 7 Question 11 Discussion

Actual exam question for Eccouncil's 112-57 exam
Question #: 11
Topic #: 7
[All 112-57 Questions]

Which of the following types of phishing attacks allows an attacker to exploit instant messaging platforms by employing IM as a tool to spread spam?

Show Suggested Answer Hide Answer
Suggested Answer: C

Spimming is defined in digital forensics and cybercrime references as spam over instant messaging (IM). It is a social-engineering variant where attackers use instant messaging platforms (and sometimes chat apps) to deliver unsolicited bulk messages containing malicious links, fraudulent offers, credential-harvesting lures, or malware downloads. Because IM messages are often delivered in real time and can appear to come from known contacts (via compromised accounts), spimming can achieve higher click-through rates than traditional email spam. For investigators, spimming incidents commonly leave artifacts such as chat logs, message timestamps, sender identifiers, embedded URLs, and sometimes downloaded payload traces on the endpoint. These artifacts help establish attacker infrastructure (domains, IPs), victim interaction (click events, file creation), and timeline correlation with network logs.

The other options do not match the ''IM as a tool to spread spam'' description. Whaling targets high-profile individuals via highly tailored phishing, typically email-based. Pharming redirects users to fraudulent websites (often via DNS or host-file manipulation) without relying on bulk IM spam. Spear phishing is targeted phishing toward specific individuals or groups, not necessarily IM spam. Therefore, the phishing/spam attack that exploits instant messaging platforms is Spimming (C).


Contribute your Thoughts:

0/2000 characters
Mary
5 hours ago
I’m leaning towards spimming as well, but I could be mixing it up with pharming. They both sound similar to me.
upvoted 0 times
...
Mammie
5 days ago
I’m a bit confused; I thought spear phishing was about targeting specific people too, but maybe that’s not the case here?
upvoted 0 times
...
Artie
11 days ago
I remember practicing a question about phishing types, and I feel like whaling was more about targeting high-profile individuals, not IM.
upvoted 0 times
...
Theola
16 days ago
I think spimming is the right answer since it specifically relates to instant messaging, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel