Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisHard
A security team is analyzing a suspicious executable found on an internal host. Initial dynamic analysis in a sandbox reveals that the executable attempts to connect to a hardcoded external IP address on TCP port 4444 and then sends an encrypted blob of data. The host's firewall logs confirm a successful outbound connection to this IP and port. What type of malware communication is most likely indicated by this behavior?
- APeer-to-peer (P2P) communication
- BMalware propagation attempt
- CLegitimate software update
- DCommand and control (C2) channel
Show answer & explanationAnswer & explanation
Correct answer: D. Command and control (C2) channel
A hardcoded external IP, a non-standard port (4444), and encrypted small data transfers are strong indicators of a command and control (C2) channel, where malware communicates with its operator to receive commands or exfiltrate data, often using custom encryption.
Why the other options are wrong
- A. P2P communication typically involves connections to multiple, often dynamic, peers, not a single hardcoded external IP, and usually involves larger data transfers.
- B. Malware propagation typically involves scanning for vulnerable hosts and attempting to exploit them, not establishing a persistent C2 connection to a single external IP.
- C. Legitimate software updates usually connect to known vendor domains/IPs on standard ports (like 80/443), involve larger downloads, and are not typically 'encrypted blobs' over non-standard ports.
Command and Control (C2)
The communication network used by attackers to remotely control compromised systems (bots) within a botnet or individual malware infections, often employing stealthy techniques like custom encryption, non-standard ports, or domain generation algorithms.
- Enables remote control of malware
- Often uses non-standard ports or protocols
- Can be encrypted to evade detection
Memory trick: Malware Talks: C2, Exfil, Propagate, Beacon.