EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsHard

A cybersecurity researcher is analyzing a new malware sample. The malware attempts to establish communication with a Command and Control (C2) server by sending DNS queries for seemingly legitimate, but non-existent, domain names. The C2 server then responds with encoded instructions within the DNS response. Which technique is this malware employing to evade detection?

  1. AHTTP Tunneling
  2. BICMP Tunneling
  3. CDNS Tunneling
  4. DSSH Tunneling
Show answer & explanation

Correct answer: C. DNS Tunneling

DNS tunneling is a technique that encapsulates data within DNS queries and responses to establish a covert communication channel. This method is effective for evading detection because DNS traffic is rarely inspected as thoroughly as other protocols, and it's often allowed through firewalls.

Why the other options are wrong

  • A. HTTP tunneling uses HTTP requests and responses for covert communication, not DNS queries.
  • B. ICMP tunneling uses ICMP (ping) packets to exfiltrate data or establish C2, not DNS.
  • D. SSH tunneling creates a secure tunnel over SSH, which is a different protocol and mechanism.

DNS Tunneling

A covert communication method that encapsulates data within DNS queries and responses to bypass network security controls and establish a Command and Control (C2) channel.

  • Uses DNS queries/responses for data transfer
  • Bypasses firewalls and IDS/IPS often
  • Can be used for C2, data exfiltration, or proxying

Memory trick: Hidden data travels in plain sight, disguised as normal network chatter.

More Malware Threats questions