|
|
|
|
|
by ndiddy
13 days ago
|
|
That could be how they initially associated the hacker with his GDID, but the criminal filing explicitly mentions that they were able to use Microsoft records to determine that his computer visited specific webpages: > According to Microsoft records, on or about May 12, 2025, at 19:21
UTC—when, according to ngrok records, the ngrok account was created—the device
with the GDID accessed, among other ngrok pages,
“https://dashboard.ngrok.com/signup,” the ngrok page to set up an ngrok account. > Microsoft records also indicate: (1) the user of the device assigned the
GDID accessed multiple sites from Tzulo servers in May 2025, including the .168
server (the IP address used to create the ngrok account) on May 12, 2025; and (2) the user of the device assigned the GDID, on May 12, 2025 at 22:47 UTC, a little more
than three hours after the ngrok account was created, the user visited “[Company
F].com” from the .168 proxy server. |
|