A security analyst is examining a server that was recently compromised. They discover that a malicious executable was installed. Network forensics reveals that after installation, the executable consistently made outbound connections to a specific external IP address on TCP port 80, using standard HTTP GET requests. However, the 'User-Agent' string in these requests was always 'Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)' and the HTTP headers contained unusual, fixed-length parameters. This communication was used to receive commands. What type of C2 communication is this?
- AHTTP C2
- BCustom TCP C2
- CICMP C2
- DDNS C2
Show answer & explanationAnswer & explanation
Correct answer: A. HTTP C2
HTTP C2 communication involves malware using standard HTTP or HTTPS protocols to communicate with its command and control server. By mimicking legitimate HTTP traffic (like using common User-Agent strings and sending GET/POST requests on port 80/443), attackers try to blend in and evade detection. The presence of a fixed User-Agent and unusual, fixed-length parameters within HTTP headers are common ways malware embeds commands or data within seemingly normal HTTP traffic.
Why the other options are wrong
- B. Custom TCP C2 would use a non-standard application-layer protocol, not standard HTTP GET requests with specific headers and parameters.
- C. ICMP C2 uses ICMP packets, not HTTP GET requests on TCP port 80.
- D. DNS C2 uses DNS queries/responses, not HTTP GET requests on TCP port 80.
HTTP Command and Control (C2)
A method of command and control where malware communicates with its C2 server using standard HTTP or HTTPS requests and responses, often mimicking legitimate web browser traffic.
- Blends with normal web traffic, making detection difficult.
- Often uses common ports (80, 443) and legitimate-looking User-Agent strings.
- Commands and data are typically encoded or embedded within HTTP headers, cookies, or POST data.
Memory trick: Malware C2 uses different languages to talk to its master.