• 0 Posts
  • 10 Comments
Joined 2 years ago
cake
Cake day: October 24th, 2023

help-circle




  • Typosquat domain for sure! In a sandbox I’m seeing that all the download links point to the same HTML page on a .ink domain that cloudflare is now refusing to serve.

    But our buddy joe already got a copy for us so we can at least view that report for fun: https://www.joesandbox.com/analysis/1763244/1/html

    Edit: It pulls down an MSI installer or something it runs with msiexec but disguised with a PDF file extension. It seems to want a copy of cmd.exe to exist in an AutoIT installation (SearchPathW vs “C:\Program Files (x86)\AutoIt3\cmd.exe”) as well as pointing toward the multilanguage (.exe.mui) and other cmd variants. I suspect we’re one step away from a real payload with this report and that’s what we’d see the “Invoke-Obfuscation” powershell the sandbox spotted used for (if that wasn’t a false positive due to the base64 offset string).


  • Sure, here’s an opinion.

    Banning is permanent and shouldn’t be first or immediate response. Repeat offenders that cross some quality or quanity threshhold may deserve that, but you should adopt power rangers rules and seek proportional responses, and only escalate as a response where possible.

    Bans should be transparent, contestable, and consistent in their application. However fair or unfair the rules you settle on, the perception of that consistency and impartiality influences the communitiea reaction. Too gentle and your community’s purpose blurs into something unintended, too harsh and your users will flee for greener pastures.

    Asking instead of dictating is the right approach in my opinion so I think you’re aimed in a good direction.

    Three strikes is where I would start, but maybe some strikes count for more than others? This is a hard problem and the answer will change over time. In cases where you can’t be consistent though, you must be transparent to salvage the trust you’re eroding.