|
|
|
|
|
by rshnotsecure
2427 days ago
|
|
It comes mainly from mapping the subdomains over time and analysis of the ASNs. This is key. You will often see a company with perhaps 200 or so subdomains, that only does business in the United States. But then you will see one subdomain that maps to ASN 4803 or whatever, which then leads to “China Telecom xinjiang”. In fact I encourage you to type: org:”China Telecom xinjiang” “NSFOCUS” into Shodan. Also look at the capital expenditures psychz.net claims on their about page. There is no IaaS company in the world that can afford to lay down as much hardware as they are claiming. Another thing btw is these sites never seem to have job openings. That is common pattern that applies to perhaps 60% of the firms listed. |
|
Generally analysts produce questions which operations runs down to figure out if what they think is going on, is actually going on.
Correct me if I'm wrong here but you're basically saying that you have done the first part and found some suspicious links but not the second part do develop actual evidence one way or the other, is that a fair assessment?