Unless they log all HTTP headers or network traffic, they don't. I've yet to see a proxy or FW that logs headers by default.https://twitter.com/maliciouslink/status/882721450410508290 …
They were harvesting usernames and passwords and proxy details, but could load other modules too. Fun...
-
-
Right - but we don't have any current evidence it was used for purposes other than pushing out notpetya, correct?
-
Correct! I doubt they did it for fun though, e.g. credential harvesting in Petya was automatic.
Koniec rozmowy
Nowa rozmowa -
Wydaje się, że ładowanie zajmuje dużo czasu.
Twitter jest przeciążony lub wystąpił chwilowy problem. Spróbuj ponownie lub sprawdź status Twittera, aby uzyskać więcej informacji.
my tweets are severely limited by my lack of understanding of what I am doing.