Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium
A security analyst is investigating a web server that exhibited unusual outbound connections. They are examining HTTP traffic in a packet capture (PCAP) and observe multiple GET requests to an external domain, where the requested URL path contains long, seemingly random strings of alphanumeric characters. The 'User-Agent' string also appears unusual and inconsistent with typical browsers. Which type of attack or malware activity does this pattern most strongly suggest?
- ACommand and Control (C2) communication using HTTP GET requests
- BSQL injection attempts
- CDistributed Denial of Service (DDoS) reconnaissance
- DCross-Site Scripting (XSS) exploit
Show answer & explanationAnswer & explanation
Correct answer: A. Command and Control (C2) communication using HTTP GET requests
Malware often uses HTTP GET requests with obfuscated URL paths and custom User-Agent strings to communicate with C2 servers, blending in with legitimate web traffic while encoding commands or exfiltrating data.
Why the other options are wrong
- B. SQL injection attempts involve malicious input in parameters, not necessarily long random URL paths in GET requests.
- C. DDoS reconnaissance would involve scanning or probing, not repeated GET requests with random URL paths from an internal server.
- D. XSS exploits target client-side browsers and inject scripts, not typically characterized by server-initiated outbound GET requests with random paths.
HTTP C2 Communication
HTTP Command and Control (C2) communication involves malware using standard HTTP/HTTPS protocols (GET, POST requests) to send and receive commands or exfiltrate data from a C2 server. This technique often employs obfuscated URLs, custom User-Agents, and non-standard HTTP headers to evade detection.
- Uses common HTTP/HTTPS ports (80, 443)
- Often seen with unusual URL patterns or query strings
- May use custom or spoofed User-Agent strings
- Aims to blend in with legitimate web traffic
Memory trick: C2 'Whispers' commands, often hiding in plain sight like a browser.