EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsMedium

A security analyst is investigating a network intrusion where several internal systems have been compromised. The attacker appears to have gained initial access through a phishing email and subsequently installed a persistent backdoor. The analyst observes that outbound traffic from the compromised hosts includes frequent, small UDP packets to a C2 server, disguised as legitimate DNS queries. This technique is commonly used to evade detection and exfiltrate data. Which type of malware communication channel is being leveraged in this scenario?

  1. AHTTP/HTTPS-based C2
  2. BDNS tunneling
  3. CICMP covert channel
  4. DSMTP exfiltration
Show answer & explanation

Correct answer: B. DNS tunneling

DNS tunneling leverages the DNS protocol to create a covert communication channel, often for data exfiltration or C2 communication. The scenario describes small UDP packets disguised as DNS queries, which is a hallmark of this technique.

Why the other options are wrong

  • A. HTTP/HTTPS tunnels use web traffic, not small UDP packets disguised as DNS.
  • C. ICMP covert channels use ICMP packets, not DNS queries.
  • D. SMTP exfiltration uses email protocols, which is not described by small UDP packets disguised as DNS queries.

DNS Tunneling

A technique that encodes data of other programs or protocols inside DNS queries and responses, creating a covert communication channel.

  • Uses DNS protocol for C2 or data exfiltration.
  • Can bypass firewalls and security controls that inspect other protocols.
  • Often involves small, frequent queries and responses.

Memory trick: Don't Notice Stealthy Data.

More Malware Threats questions