3 ms·
not sure if this specific TTP is common, but generally there are a lot of ways that malware authors perform first c2 discovery and then actual c2. attackers can
by thatfunkymunki 5y ago
not sure if this specific TTP is common, but generally there are a lot of ways that malware authors perform first c2 discovery and then actual c2. attackers can use DNS itself for both of these aspects of C2. Even very old reports of since-long-gone attackers like APT1 https://www.mandiant.com/media/9941/download https://www.mandiant.com/media/9941/download indicate use of covert c2 over otherwise benign web applications like google calendar.