4 ms·
I still don't get it, what exactly was flagged that caused the domain to get noticed by... Who exactly? Did it have anything to do with the owner logging into h
by triangleman 7y ago
I still don't get it, what exactly was flagged that caused the domain to get noticed by... Who exactly? Did it have anything to do with the owner logging into his server? What is the sequence of events in bullet point format? I know the author tried to be clear but I'm confused as to what actually happened.
- akersten 7y agoA particular malware contacted its command and control servers via procedurally generated domain names (to make it difficult to shut down just a single domain that controlled it). Malware researchers reversed a sample of the malware and started blackholing domains that matched the pattern to get ahead of the malware by preventing it from communicating with the domain du jour. It just so happens that the authors domain pattern-matched domains that would be contacted by the malware.
- triangleman 7y agoThank you. So it was just a coincidence that this person logged into his server at the same time as the domain was taken down? It was simply a suspicious looking domain name?