logoalt Hacker News

kachapopopowlast Monday at 4:18 PM1 replyview on HN

if you add non trivial address generation there simply isn't a good way to block it except for hope and prayers. nobody really wants to play wack-a-mole on blocking addresses for c2 servers and then there will always be websites which straight up do not care.


Replies

monerozcashlast Monday at 4:28 PM

I mean, at that point, why wouldn't you just rely on a DGA? At least then you wouldn't be flooding block explorer sites with millions or potentially tens of millions of requests per day for your C&C traffic.

Essentially the exact approach you propose has been attempted in far cleverer ways, it did not work very well.

show 1 reply