Were the spa504g.cfg pulls coming from the same infosec scanner IPs as everything else or from another source? Curious whether the targeted-looking requests actually separate out from the background noise.
Doesn't the fingerprint also cluster the other non-malicious Go HTTP clients on the internet? Seems though TLS gave the grouping, and the GCP hosting and filename guessing is what I think made it malicious. They are two…
[flagged]
[dead]
Were the spa504g.cfg pulls coming from the same infosec scanner IPs as everything else or from another source? Curious whether the targeted-looking requests actually separate out from the background noise.
Doesn't the fingerprint also cluster the other non-malicious Go HTTP clients on the internet? Seems though TLS gave the grouping, and the GCP hosting and filename guessing is what I think made it malicious. They are two…
[flagged]
[dead]