A scanning operation on 38 IPs looked like 11,107 across 147 networks (honeylabs.net) 2 points by Robbedoes 2mo ago ↗ HN
[–] pseudocoder204 2mo ago ↗ Doesn't the fingerprint also cluster the other non-malicious Go HTTP clients on the internet? Seems though TLS gave the grouping, and the GCP hosting and filename guessing is what I think made it malicious. They are two different things, am I right?
1 comment
[ 1.9 ms ] story [ 14.2 ms ] thread