QuestionQ320

Detecting Exploitation and Covert Communications Tools

An investigation identified several systems exhibiting suspicious activity. At regular intervals, the systems transmit data over port 80 to a different external host each time. What type of attack does this activity indicate?

  • A An ICMP reverse shell
  • B A user mode rootkit
  • C A fast flux bot
  • D A metamorphic worm
Explanation

Fast flux employs rapidly changing, distributed network endpoints to obscure and maintain malicious command-and-control infrastructure. Repeated HTTP communication over port 80 to rotating external hosts is characteristic of a fast-flux bot.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!