Hacker News new | ask | show | jobs
by _8j50 1401 days ago
Yes a malicious actor needs more than that because compromised domains are valuable and keeping them alive longer means more money...

A non-malicious actor who needs the URL isn't monitoring or responding to the incident properly. Threat actors do take advantage of this and simulate a fake cleanup. Actually they exclude certain ips and asns on phishing kits so that visiting the url gives you a 404 or a webhosts "cleanup" page.