EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsMedium
A security analyst is investigating a network intrusion where several internal systems have been compromised. The attacker appears to have gained initial access through a phishing email and subsequently installed a persistent backdoor. The analyst observes that outbound traffic from the compromised hosts includes frequent, small UDP packets to a C2 server, disguised as legitimate DNS queries. This technique is commonly used to evade detection and exfiltrate data. Which type of malware communication channel is being leveraged in this scenario?
- AHTTP/HTTPS-based C2
- BDNS tunneling
- CICMP covert channel
- DSMTP exfiltration
Show answer & explanationAnswer & explanation
Correct answer: B. DNS tunneling
DNS tunneling leverages the DNS protocol to create a covert communication channel, often for data exfiltration or C2 communication. The scenario describes small UDP packets disguised as DNS queries, which is a hallmark of this technique.
Why the other options are wrong
- A. HTTP/HTTPS tunnels use web traffic, not small UDP packets disguised as DNS.
- C. ICMP covert channels use ICMP packets, not DNS queries.
- D. SMTP exfiltration uses email protocols, which is not described by small UDP packets disguised as DNS queries.
DNS Tunneling
A technique that encodes data of other programs or protocols inside DNS queries and responses, creating a covert communication channel.
- Uses DNS protocol for C2 or data exfiltration.
- Can bypass firewalls and security controls that inspect other protocols.
- Often involves small, frequent queries and responses.
Memory trick: Don't Notice Stealthy Data.