3 ms·
Hiding your C&C behind clownflare is basically the default mode for a lot of actors. CF are terribly slow to respond to abuse, their ranges are allowlisted eve
by fullspectrumdev 3y ago
Hiding your C&C behind clownflare is basically the default mode for a lot of actors.
CF are terribly slow to respond to abuse, their ranges are allowlisted everywhere, and it’s not terribly hard to hide your backend infrastructure (origin) even from cloudflare itself.
Sure you have to deal with the eventual takedown of your domain, by CF or more likely the domain registrar, but it’s trivial to work around that (backup domains, frequently rotating them, etc).
What’s funny is how Namecheap are now absolutely god tier at doing takedowns on malicious domains - they used to have a very poor reputation and now will process a takedown (provided evidence) within the hour usually.
- zelphirkalt 3y agoWondering if typo, auto-correct, or intentional ... anyway, I like :D
- averageRoyalty 3y agoGiven the critical tone, I'd say probably intentional.
- miloudi 3y agowhat's C&C? sorry for hijacking the thread.
- e63f67dd-065b 3y agoCommand and Control. The server that issues instructions to the malware.