A security operations center (SOC) receives an alert indicating 'High volume of outbound traffic to unusual ports from an internal web server.' Further investigation reveals that the server is attempting to connect to multiple external IP addresses on a wide range of non-standard ports. The web server should only be communicating on ports 80, 443, and 22 (for management). What is the MOST likely cause of this activity?
- AAn authorized penetration test is underway.
- BA legitimate software update attempting to fetch patches.
- CThe web server is part of a botnet and is scanning for vulnerable hosts.
- DA misconfigured firewall rule allowing excessive outbound traffic.
Show answer & explanationAnswer & explanation
Correct answer: C. The web server is part of a botnet and is scanning for vulnerable hosts.
A web server communicating on a wide range of non-standard ports to multiple external IP addresses, beyond its legitimate function, is highly indicative of it being compromised and used as part of a botnet for scanning or launching further attacks. Legitimate updates usually use standard ports, misconfigured firewalls allow traffic but don't initiate scans, and authorized pen tests are typically communicated to the SOC.
Why the other options are wrong
- A. Authorized penetration tests should be communicated to the SOC in advance to avoid false positives and would typically have defined scope and targets, not random scanning from a production web server.
- B. Legitimate software updates usually use well-known ports (e.g., 80, 443) and specific update servers, not a wide range of unusual ports.
- D. While a misconfigured firewall could allow the traffic, it wouldn't explain the server *initiating* scanning activity to random external IPs on unusual ports.
Botnet Activity Indicators
Observable behaviors that suggest a system has been compromised and is acting as part of a botnet. These often include unusual network traffic patterns, C2 communication, and scanning for other vulnerable hosts.
- Unusual outbound connections to diverse IPs/ports.
- Periodic C2 communication patterns.
- Participation in DDoS attacks or spam campaigns.
Memory trick: Compromised Servers Chat and Scan, Not Just Serve.