Hacker News new | ask | show | jobs
by EligibleDecoy 745 days ago
My bet on the replays was that the attacker misconfigured their payload or something and it was meant to replay command and control requests to obfuscate where the C2 server was