Open cardosec

Case 777685 · Malware & intel · L2 Practitioner

The 60-second heartbeat

Practise as: Incident drill · Interview

Live alertNDR flags DEV-LAPTOP-17 making HTTPS requests to cdn-update-sync[.]com every 60s (+/- 10%) for 4 days, each about 1.2 KB, via an unsigned binary in %APPDATA%\Roaming\Updater.

Interview questionWalk me through confirming whether this is C2 and what you would do next.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Periodic, small, consistent requests to a rare young domain from an unsigned AppData binary is classic beaconing
  2. Check domain age/WHOIS, passive DNS, TLS cert and JA3; see if any other hosts talk to it
  3. Pull the binary: hash lookup, sandbox detonation, check persistence (Run key, scheduled task)
  4. Contain host, block domain at DNS/proxy, and hunt for lateral movement from the laptop over the 4 days
  5. Find initial vector: downloads and browser history around first-seen time, e.g. fake software update

If the interviewer pushes back

  • Beaconing interval suddenly drops to 1 second. What does that suggest the operator is doing?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.