logoalt Hacker News

lantryyesterday at 9:54 PM3 repliesview on HN

> Side note: Why use a raw IP address? If anything, this screams “malware.” At least register a decoy domain like lint-checker.com or jenkins-ci-runner.net. If the threat actors who wrote this are reading: take notes people!

Maybe they don't want to give any identifying info to the domain registrar? Or just minimizing their online presence?


Replies

HPsquaredyesterday at 10:11 PM

That's probably the reason bare IP addresses are associated with sketchy stuff.

cromkayesterday at 11:30 PM

Or possibly these hosts fell victims of their malware, too, and see now used as proxies.

show 1 reply
CITIZENDOTyesterday at 10:03 PM

fair point