Hacker News new | ask | show | jobs
by BoorishBears 1400 days ago
... MS is telling everyone that the root domain is on a black list. A malicious actor doesn't need more than that, they already know the exact URL that malware resides at.

A non-malicious actor doesn't know, so telling them the exact URL at least tells them where the compromised asset might be.

1 comments

Yes a malicious actor needs more than that because compromised domains are valuable and keeping them alive longer means more money...

A non-malicious actor who needs the URL isn't monitoring or responding to the incident properly. Threat actors do take advantage of this and simulate a fake cleanup. Actually they exclude certain ips and asns on phishing kits so that visiting the url gives you a 404 or a webhosts "cleanup" page.