Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisHard

A security analyst is examining a server that was recently compromised. They discover that a malicious executable was installed. Network forensics reveals that after installation, the executable consistently made outbound connections to a specific external IP address on TCP port 80, using standard HTTP GET requests. However, the 'User-Agent' string in these requests was always 'Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)' and the HTTP headers contained unusual, fixed-length parameters. This communication was used to receive commands. What type of C2 communication is this?

  1. AHTTP C2
  2. BCustom TCP C2
  3. CICMP C2
  4. DDNS C2
Show answer & explanation

Correct answer: A. HTTP C2

HTTP C2 communication involves malware using standard HTTP or HTTPS protocols to communicate with its command and control server. By mimicking legitimate HTTP traffic (like using common User-Agent strings and sending GET/POST requests on port 80/443), attackers try to blend in and evade detection. The presence of a fixed User-Agent and unusual, fixed-length parameters within HTTP headers are common ways malware embeds commands or data within seemingly normal HTTP traffic.

Why the other options are wrong

  • B. Custom TCP C2 would use a non-standard application-layer protocol, not standard HTTP GET requests with specific headers and parameters.
  • C. ICMP C2 uses ICMP packets, not HTTP GET requests on TCP port 80.
  • D. DNS C2 uses DNS queries/responses, not HTTP GET requests on TCP port 80.

HTTP Command and Control (C2)

A method of command and control where malware communicates with its C2 server using standard HTTP or HTTPS requests and responses, often mimicking legitimate web browser traffic.

  • Blends with normal web traffic, making detection difficult.
  • Often uses common ports (80, 443) and legitimate-looking User-Agent strings.
  • Commands and data are typically encoded or embedded within HTTP headers, cookies, or POST data.

Memory trick: Malware C2 uses different languages to talk to its master.

More Network Intrusion Analysis questions