Hacker News new | ask | show | jobs
by peter_d_sherman 2050 days ago
Observation: "avsvmcloud.com" -- seems to be the one constant around which a whole bunch of other things, which are variables revolve... (oh sure, "appsync-api" also appears to be a constant -- but it exists at a far less important place in the URL).

"avsvmcloud.com" is far, far more important -- because ALL of the communications go there...

Now, it may be that "avsvmcloud.com" is a legitimate ISP, hosting provider or what-have-you...

But, if I were an investigator on this case, I know I'd want to track each and every place that these requests flow through whoever owns the "avsvmcloud.com" network...

I'd start with the idea that because a subdomain is being used, that the first thing that happens is that subdomains must be resolved by a DNS subdomain servers... so where exactly on whoever owns the "avsvmcloud.com" network, does that happen?

I'd even go so far as to audit, completely dissasemble, the DNS software that is running on those servers... Give it to as many security researchers as possible... What does it do? Where does it point to? What's on the other end of those IP addresses that it resolves to? Are there any anomalies in that IP address resolution? Specifically, when/where and how do they manifest? Are there any patterns there? Who owns the machines on the other side of those IP addresses?

Etc., etc.

In fact...

What would happen if someone were to run a machine learning algorithm on say a, let's be polite and call it a "challenged" DNS resolver?

Would it find some DNS resolution anomalies?

In fact, if I were an investigator, I'd go as far as to audit the whole chain of DNS resolvers / the DNS resolution process THOROUGHLY...