Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisHard

A security team is analyzing a suspicious executable found on an internal host. Initial dynamic analysis in a sandbox reveals that the executable attempts to connect to a hardcoded external IP address on TCP port 4444 and then sends an encrypted blob of data. The host's firewall logs confirm a successful outbound connection to this IP and port. What type of malware communication is most likely indicated by this behavior?

  1. APeer-to-peer (P2P) communication
  2. BMalware propagation attempt
  3. CLegitimate software update
  4. DCommand and control (C2) channel
Show answer & explanation

Correct answer: D. Command and control (C2) channel

A hardcoded external IP, a non-standard port (4444), and encrypted small data transfers are strong indicators of a command and control (C2) channel, where malware communicates with its operator to receive commands or exfiltrate data, often using custom encryption.

Why the other options are wrong

  • A. P2P communication typically involves connections to multiple, often dynamic, peers, not a single hardcoded external IP, and usually involves larger data transfers.
  • B. Malware propagation typically involves scanning for vulnerable hosts and attempting to exploit them, not establishing a persistent C2 connection to a single external IP.
  • C. Legitimate software updates usually connect to known vendor domains/IPs on standard ports (like 80/443), involve larger downloads, and are not typically 'encrypted blobs' over non-standard ports.

Command and Control (C2)

The communication network used by attackers to remotely control compromised systems (bots) within a botnet or individual malware infections, often employing stealthy techniques like custom encryption, non-standard ports, or domain generation algorithms.

  • Enables remote control of malware
  • Often uses non-standard ports or protocols
  • Can be encrypted to evade detection

Memory trick: Malware Talks: C2, Exfil, Propagate, Beacon.

More Network Intrusion Analysis questions