An analyst performs static analysis on a suspicious executable found on an HMI. The analysis of embedded strings reveals hardcoded byte sequences corresponding to DNP3 function code 13 (Cold Restart) and object group 70 (File Transfer). What is the MOST likely purpose of this malware?
-
A
To exfiltrate historical process data for industrial espionage.
-
B
To encrypt files on the HMI and demand a ransom payment.
-
C
To disrupt or manipulate the physical process by rebooting remote devices and altering device files.
-
D
To establish a persistent command and control channel using the DNP3 protocol for long-term access.