Case 777685 · Malware & intel · L2 Practitioner
The 60-second heartbeat
Practise as: Incident drill · Interview
Live alertNDR flags DEV-LAPTOP-17 making HTTPS requests to cdn-update-sync[.]com every 60s (+/- 10%) for 4 days, each about 1.2 KB, via an unsigned binary in %APPDATA%\Roaming\Updater.
Interview questionWalk me through confirming whether this is C2 and what you would do next.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Periodic, small, consistent requests to a rare young domain from an unsigned AppData binary is classic beaconing
- Check domain age/WHOIS, passive DNS, TLS cert and JA3; see if any other hosts talk to it
- Pull the binary: hash lookup, sandbox detonation, check persistence (Run key, scheduled task)
- Contain host, block domain at DNS/proxy, and hunt for lateral movement from the laptop over the 4 days
- Find initial vector: downloads and browser history around first-seen time, e.g. fake software update
If the interviewer pushes back
- Beaconing interval suddenly drops to 1 second. What does that suggest the operator is doing?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.