• XSS.stack #1 – первый литературный журнал от юзеров форума

Smoke Loader domain questions

vncip

floppy-диск
Пользователь
Регистрация
22.05.2023
Сообщения
5
Реакции
1
Hello

I have a question about Smoke Loader, in particular the domain names that must be provided. My understanding is that a builder isn't provided when purchasing Smoke. A domain name (and a backup name) are given along with payment, and an exe is provided in return with these domains hardcoded into them. Obviously this means if your domains are blacklisted or sinkholed, a rebuild of the bot must be undertaken ($30, my understanding).

Does anyone have a recommended hostname provider for this? Obviously must be bulletproof and accept crypto, but how secure must it be? With a small botnet, how long can one expect the domain to last, after being analyzed by security researchers? Assuming the botnet stays small and doesn't do anything stupid, can the domain be expected to last indefinitely, or is it just expected that domains must be updated every so often?

Must it be a hardcore bulletproof domain, or would an Njalla domain be acceptable?

Thank you!
 
There is too many options as others said like using a few layers of stages, update your .exe very often, make sure you use fastflux domains and bulletproof servers and also that would be good if you build some automation with vagrant, terraform etc... That will help you to faster recovery once your .exe, domain or server listed in urlhause. If you can automate the process of refreshing everything with a single command or at least a few clicks. then you don't have to mind about this too much.
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх