nerdexam
GIAC

GCIH · Question #446

An investigation led to the identification of several systems showing suspicious activity. At regular time intervals, the systems send data over port 80 to different external hosts each time. Which…

The correct answer is C. A fast flux bot. Bots are software programs that perform some action on behalf of a human, typically with little or no human intervention. Attackers can use commonly open ports such as HTTP or HTTPS ports implement command and control sessions for their botnets. Using fast flux, where bots can…

Malware Analysis & Advanced Persistent Threats

Question

An investigation led to the identification of several systems showing suspicious activity. At regular time intervals, the systems send data over port 80 to different external hosts each time. Which type of attack is indicated by this activity?

Options

  • AAn ICMP reverse shell
  • BA user mode rootkit
  • CA fast flux bot
  • DA metamorphic worm

How the community answered

(51 responses)
  • A
    10% (5)
  • B
    2% (1)
  • C
    82% (42)
  • D
    6% (3)

Explanation

Bots are software programs that perform some action on behalf of a human, typically with little or no human intervention. Attackers can use commonly open ports such as HTTP or HTTPS ports implement command and control sessions for their botnets. Using fast flux, where bots can communicate with a large number of external hosts, is one way attackers maintain access. Based on the details provided, there is no immediate indication of rootkits, metamorphic code or reverse shell activity.

Topics

#fast flux#botnet C2#port 80 beaconing#dynamic DNS evasion

Community Discussion

No community discussion yet for this question.

Full GCIH Practice