CompTIA SecurityX (CAS-005)Security OperationsHard
A security analyst is investigating a suspected data exfiltration incident. They have identified a compromised internal server that was observed making frequent, small outbound HTTP POST requests to an external IP address that changes periodically. The HTTP user-agent string used in these requests is highly unusual and inconsistent with any legitimate application on the server. What technique is the attacker most likely employing?
- AData Exfiltration via HTTP C2
- BCredential Stuffing
- CPort Scanning
- DWeb Shell
Show answer & explanationAnswer & explanation
Correct answer: A. Data Exfiltration via HTTP C2
The scenario describes a compromised server making frequent, small, outbound HTTP POST requests to a changing external IP with an unusual user-agent. This is characteristic of a command and control (C2) channel over HTTP, where data is exfiltrated in the POST request body or as part of the C2 communication, often disguised by unusual user-agents and dynamic IPs to evade detection.
Why the other options are wrong
- B. Credential stuffing involves using stolen credentials to gain unauthorized access to accounts, which does not directly manifest as frequent outbound HTTP POST requests.
- C. Port scanning involves scanning for open ports on target systems, not frequent outbound HTTP POST requests from a compromised server.
- D. A web shell provides remote access to a compromised web server, but the observed behavior (frequent outbound POSTs to external, changing IPs) is more indicative of data exfiltration via a C2 channel rather than direct interactive web shell usage.
HTTP C2 for Data Exfiltration
A technique where attackers use HTTP/HTTPS for command and control (C2) communication and to exfiltrate data from a compromised system, often disguised as legitimate web traffic.
- Leverages common web ports (80, 443) to evade detection.
- Often uses HTTP GET for commands, HTTP POST for data exfiltration.
- May employ unusual User-Agent strings, dynamic IPs/domains, or encrypted payloads.
- Difficult to distinguish from legitimate web traffic without deep packet inspection.
Memory trick: Look for the ghost in the machine, whispering secrets through normal channels.