Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium

A security analyst is investigating a web server that exhibited unusual outbound connections. They are examining HTTP traffic in a packet capture (PCAP) and observe multiple GET requests to an external domain, where the requested URL path contains long, seemingly random strings of alphanumeric characters. The 'User-Agent' string also appears unusual and inconsistent with typical browsers. Which type of attack or malware activity does this pattern most strongly suggest?

  1. ACommand and Control (C2) communication using HTTP GET requests
  2. BSQL injection attempts
  3. CDistributed Denial of Service (DDoS) reconnaissance
  4. DCross-Site Scripting (XSS) exploit
Show answer & explanation

Correct answer: A. Command and Control (C2) communication using HTTP GET requests

Malware often uses HTTP GET requests with obfuscated URL paths and custom User-Agent strings to communicate with C2 servers, blending in with legitimate web traffic while encoding commands or exfiltrating data.

Why the other options are wrong

  • B. SQL injection attempts involve malicious input in parameters, not necessarily long random URL paths in GET requests.
  • C. DDoS reconnaissance would involve scanning or probing, not repeated GET requests with random URL paths from an internal server.
  • D. XSS exploits target client-side browsers and inject scripts, not typically characterized by server-initiated outbound GET requests with random paths.

HTTP C2 Communication

HTTP Command and Control (C2) communication involves malware using standard HTTP/HTTPS protocols (GET, POST requests) to send and receive commands or exfiltrate data from a C2 server. This technique often employs obfuscated URLs, custom User-Agents, and non-standard HTTP headers to evade detection.

  • Uses common HTTP/HTTPS ports (80, 443)
  • Often seen with unusual URL patterns or query strings
  • May use custom or spoofed User-Agent strings
  • Aims to blend in with legitimate web traffic

Memory trick: C2 'Whispers' commands, often hiding in plain sight like a browser.

More Network Intrusion Analysis questions