I don't want to scare y'all, but I just checked the @greynoise.io sensor logs and found over 1000 sessions in the last hour that used this sophisticated technique (ie, attempted to download malware over ephemeral ports)!!
Post image

Comments