File Download - How Does it Work? #2025
Answered
by
moloch--
burt-mianus
asked this question in
Q&A
-
|
Hello, I am using Sliver to emulate C2 behaviour in my lab, and when doing firewall inspection I see file downloads appearing as transfers of .api files (i think). It almost looks like the is broken down into smaller chunks and packaged as these benign php files and transferred to the server. (apologies for the crude terminology....) Would appreciate some help understanding the behaviour. Thanks |
Beta Was this translation helpful? Give feedback.
Answered by
moloch--
Oct 25, 2025
Replies: 1 comment
-
|
This document describes the process: |
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
moloch--
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
This document describes the process:
https://sliver.sh/docs?name=HTTPS+C2#under-the-hood