← Back to Labs

Command & Control Infrastructure Mechanics

Step through malleable C2 profile transformations, DNS TXT tunneling, memory sleep obfuscation, and JA3 TLS fingerprinting

Target HostImplant AgentPAGE_EXEC_READEdge RedirectorNginx Proxy / CDNC2 Team Server10.0.4.15 (Internal)DNS ResolverRecursive (Port 53)Auth C2 DNSns1.c2-command.orgThreat Hunter NDRNetflow & JA3 TLS EngineJA3 Fingerprint:cd4dde6e79f7e05fTiming Jitter (CV):CV = 0.02 (Fixed)Threat Score:12/100 [CLEAN]INFRASTRUCTUREHTTP/S Reverse Proxy & Decoy Filtering RulesTopology:2-Tier ProxyEdge Proxy:Nginx mod_rewriteBackend IP:10.0.4.15 (Hidden)> location /jquery-3.6.0.min.js {
STEP 1 OF 6

Multi-Tier C2 Infrastructure Setup

Modern command and control (C2) operations place HTTP/S redirectors in front of backend team servers. If security defenders identify and block a public redirector IP, the core C2 management server and campaign database remain hidden and unexposed.

Arrow keys to navigate · R to reset

Tap dots to jump to any step

Read the full article →Take the quiz →