Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium
A network security analyst is reviewing a packet capture (PCAP) file from a compromised host. They observe a large number of outbound HTTP GET requests to various subdomains of an unfamiliar domain, such as 'a.malicious.com', 'b.malicious.com', 'c.malicious.com', and so on. The subdomains appear to be randomly generated. What network intrusion technique does this pattern suggest?
- ASQL injection
- BDomain Generation Algorithm (DGA) C2
- CDistributed Denial of Service (DDoS)
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: B. Domain Generation Algorithm (DGA) C2
A Domain Generation Algorithm (DGA) is used by malware to periodically generate a large number of domain names that can be used as rendezvous points with their command and control (C2) servers. The observed pattern of numerous, randomly generated subdomains of an unfamiliar domain is a classic indicator of DGA in action.
Why the other options are wrong
- A. SQL injection targets web application vulnerabilities and does not involve outbound HTTP requests to randomly generated domains.
- C. DDoS attacks aim to overwhelm a target with traffic, not to communicate with C2 servers via generated domains.
- D. XSS is a client-side attack that injects malicious scripts into web pages, not a technique for malware C2 communication.
Domain Generation Algorithm (DGA)
An algorithm used by malware to generate a large number of potential domain names that can be used for command and control (C2) communication.
- Helps malware evade blacklisting by constantly changing C2 domains.
- Often generates domains that appear random or nonsensical.
- Requires the attacker to pre-register some of the generated domains to establish communication.
Memory trick: Malware uses tricks to hide its control center.