CompTIA CySA+ (CS0-003)Incident Response and ManagementHard

A security operations center (SOC) analyst receives an alert indicating a high volume of outbound connections from an internal server to various external IP addresses on TCP port 6667. The server's baseline shows no legitimate services using this port. Which of the following is the MOST likely type of malware or activity associated with this behavior?

  1. ASQL injection attempts
  2. BRansomware encryption activity
  3. CWeb server defacement
  4. DBotnet command and control (C2) communication
Show answer & explanation

Correct answer: D. Botnet command and control (C2) communication

TCP port 6667 is a well-known port for Internet Relay Chat (IRC). A high volume of outbound connections to various external IPs on this port, from a server not legitimately using it, is a classic indicator of a compromised machine acting as a bot and communicating with an IRC-based botnet command and control server.

Why the other options are wrong

  • A. SQL injection attempts occur on database ports (e.g., 3306, 1433) or web ports (80/443) to exploit web applications, not outbound IRC ports.
  • B. Ransomware typically encrypts files locally and may communicate with a C2, but often not exclusively on port 6667 for high volume outbound connections.
  • C. Web server defacement involves modifying web content, typically via HTTP/HTTPS, not through outbound IRC connections.

Botnet C2 Indicators

Network traffic patterns and behaviors that suggest a system is part of a botnet and communicating with its command and control server.

  • Unusual outbound connections to known C2 ports (e.g., 6667, 8080, custom ports).
  • Connections to suspicious domains/IPs.
  • Periodic, small data transfers.

Memory trick: Unusual ports are 'Malware's' secret channels, especially IRC for bots.

More Incident Response and Management questions