CompTIA CySA+ (CS0-003)Incident Response and ManagementHard
A security analyst is reviewing network flow logs and observes a significant increase in outbound traffic to a single external IP address (172.217.160.142) from multiple internal workstations. The traffic is consistently using TCP port 6667, which is typically associated with Internet Relay Chat (IRC). Further investigation reveals that the internal workstations are communicating with this external IP using malformed HTTP requests. Which of the following types of C2 (Command and Control) channel is this activity most indicative of?
- AHTTP/HTTPS-based C2
- BIRC-based C2
- CDNS-based C2
- DSMB-based C2
Show answer & explanationAnswer & explanation
Correct answer: B. IRC-based C2
While the traffic uses 'malformed HTTP requests', the critical indicator is the consistent use of TCP port 6667, which is a common port for IRC. Attackers often use IRC for C2, sometimes disguising their communications as other protocols to evade detection, but the port usage strongly points to IRC-based communication. The 'malformed HTTP requests' might be a technique to further obfuscate the IRC traffic or an attempt to mimic web traffic on a non-standard port.
Why the other options are wrong
- A. HTTP/HTTPS C2 typically uses TCP ports 80 or 443, not 6667.
- C. DNS C2 uses UDP port 53, not TCP port 6667.
- D. SMB C2 operates over TCP ports 139 or 445, not 6667.
IRC-based C2
A Command and Control (C2) channel that leverages the Internet Relay Chat (IRC) protocol for communication between attacker and compromised systems (bots).
- Often uses TCP ports 6667, 6697 (SSL), or other non-standard ports.
- Bots join specific IRC channels to receive commands.
- Traffic can be disguised as other protocols to evade detection.
Memory trick: Bots Talk Securely, Discreetly, and Often Irregularly