|
|
|
|
|
by DesktopECHO
1256 days ago
|
|
Yeah only the primary server seems to be on blocklists. The malware uses 3 DNS addresses, all on Linode. Not that it matters, as the malware uses 8.8.8.8 if it doesn't like the DNS reply -- Then it tries a DNS server on port 5353! |
|