Register and share your invite link to earn from video plays and referrals.

vx-underground
@vxunderground
The largest collection of malware source code, samples, and papers on the internet. Password: infected
Joined August 2019
369 Following    443.5K Followers
A lot of malware campaigns use CloudFlare to mask their C2 infrastructure. They do this for a few reasons, but the primary reason is that it delays the inevitable of their C2 being taken down. The malware developers using CloudFlare isn't necessarily bad, and it isn't necessarily good, it's just a known thing that people abuse. Yes, CloudFlare did their job. CloudFlare takes down malware infrastructure a lot, despite people saying CloudFlare doesn't take any action, because CloudFlare is inundated with both legitimate and illegitimate takedown requests and reports daily. The daily reports they receive are (probably) in the millions daily. If they didn't want to hide behind CloudFlare, the malware developers could also have used a compromised website (very common), or Discord, or Google docs, or Spotify, or ... basically pick a website and service and it can be abused with enough elbow grease. The easiest, fastest, and easily configurable method is generic host with CloudFlare. When the domain is taken down, or CloudFlare takes it down, they simple spin up new infrastructure with a new CloudFlare account and operations resume as normal.
Show more
@vxunderground @Cloudflare So basically, what you’re saying is that Cloudflare did their job? Or that the malware authors are shit? What should the malware authors have done instead? 🤔💭