Incident Response to C2 Domain results in Disabling Google Chrome Prefetch

I got a call the other day that lead to a fast incident response relating to a C2 domain communication.  I thought I would share the steps I took to investigate the event.  Ultimately I learned that Google Chrome and its pre-fetch technology can be a bit of a trouble maker.