3 ms·
Not necessarily. You could probably infer it from a MySQL client in the malware itself and the queries its making to tables and such.
by dclusin 6y ago
Not necessarily. You could probably infer it from a MySQL client in the malware itself and the queries its making to tables and such.
- FDSGSG 6y agoThat sounds reaaally unlikely. If the malware shipped a mysql client the NSA would definitely be able to pop the mysql server it connects to.
- stevehawk 6y agothe point wasnt whether or not they could or did. the point was that it could be inferred based on what sql client the malware client was using without ever touching the sever.
- FDSGSG 6y agoIt is extraordinarily unlikely that the malware would ship with a mysql client or talk mysql with the C2 If it does, that's an easy claim to prove.
- enkid 6y agoThey know specific commands and configurations for the "drobovur-server" which is the "Command and Control (C2) Server." This makes me think they have the actual server software and probably some sort of operational deployment.