|
|
|
|
|
by _8j50
1401 days ago
|
|
Yes a malicious actor needs more than that because compromised domains are valuable and keeping them alive longer means more money... A non-malicious actor who needs the URL isn't monitoring or responding to the incident properly. Threat actors do take advantage of this and simulate a fake cleanup. Actually they exclude certain ips and asns on phishing kits so that visiting the url gives you a 404 or a webhosts "cleanup" page. |
|