Malicious update/malware by a semi-advanced adversary
1–10 of 37 posts
Re: Malicious update/malware by a semi-advanced adversary
#2Re: Malicious update/malware by a semi-advanced adversary
#3Re: Malicious update/malware by a semi-advanced adversary
#4Re: Malicious update/malware by a semi-advanced adversary
#5Quoted post unavailable.
Re: Malicious update/malware by a semi-advanced adversary
#6Quoted post unavailable.
Re: Malicious update/malware by a semi-advanced adversary
#7Re: Malicious update/malware by a semi-advanced adversary
#8Small blog post where I detail a malicious update I got served, try to track what it was doing, who sent it, and my mistakes. Would love to hear your thoughts!
It would be commendable to try to contact the site operators in cases like this.
Re: Malicious update/malware by a semi-advanced adversary
#9Re: Malicious update/malware by a semi-advanced adversary
#10I'm not actually getting the domain was taken down reasoning, I mean I understand it was taken down but
"but after using an online NS lookup tool, I realized that the DNS records were deleted some time last night. This must have been in response to the next stage having been downloaded. It’s unclear whether deleting the DNS records was automatic or manual."
so is the assumption here that they were trying to get just one person, or actually this specific person CuckooExe?
Could it be that the deletion happened because
1. they know infection happened because data sent ?
2. Next stage of infection not happen (whatever that would be) therefore it follows infection detected.
3. delete dns on infection detected?
or am I overthinking this?