Live data from Hacker News

Malicious update/malware by a semi-advanced adversary

axelp.io

1–10 of 37 posts

Re: Malicious update/malware by a semi-advanced adversary

#8

Small blog post where I detail a malicious update I got served, try to track what it was doing, who sent it, and my mistakes. Would love to hear your thoughts!

If not be so quick to jump on conclusions that the distributing sites and servers are aware that they are complicit, or "fake". Infected WordPress installations participating in botnets and spreading malware is a scourge.

It would be commendable to try to contact the site operators in cases like this.

Re: Malicious update/malware by a semi-advanced adversary

#10
This is not really my area of expertise so perhaps explains my confusion.

I'm not actually getting the domain was taken down reasoning, I mean I understand it was taken down but

"but after using an online NS lookup tool, I realized that the DNS records were deleted some time last night. This must have been in response to the next stage having been downloaded. It’s unclear whether deleting the DNS records was automatic or manual."

so is the assumption here that they were trying to get just one person, or actually this specific person CuckooExe?

Could it be that the deletion happened because

1. they know infection happened because data sent ?

2. Next stage of infection not happen (whatever that would be) therefore it follows infection detected.

3. delete dns on infection detected?

or am I overthinking this?

Post reply on HN