EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsMedium
During a malware incident response, an analyst observes that infected systems are communicating with external IP addresses on TCP port 6667 and 6697, which are commonly associated with IRC (Internet Relay Chat). Which malware characteristic is most likely being utilized for command and control (C2) in this scenario?
- AHTTP/HTTPS communication
- BIRC-based botnet communication
- CPeer-to-Peer (P2P) botnet architecture
- DDNS exfiltration
Show answer & explanationAnswer & explanation
Correct answer: B. IRC-based botnet communication
TCP ports 6667 and 6697 are standard ports for Internet Relay Chat (IRC). Malware using these ports to communicate with external IP addresses is highly indicative of an IRC-based botnet, where the attacker uses an IRC channel for command and control of infected machines.
Why the other options are wrong
- A. HTTP/HTTPS communication typically uses ports 80 and 443, not 6667 or 6697.
- C. P2P botnets use direct communication between infected nodes, not typically centralized IRC servers on these specific ports.
- D. DNS exfiltration uses DNS queries to smuggle data out, not for C2 on IRC ports.
IRC-based Botnet
A type of botnet where the attacker (botmaster) uses an Internet Relay Chat (IRC) server and channel to issue commands to and receive responses from compromised computers (bots).
- Uses standard IRC protocols and ports (e.g., TCP 6667, 6697).
- Provides a centralized, real-time command and control mechanism.
- Bots join a specific IRC channel to await commands.
Memory trick: IRC C2: Bots 'chat' on a secret channel for commands.