25 Apr
2018
25 Apr
'18
3:34 p.m.
On Wed, Apr 25, 2018 at 11:28 AM, J. Oquendo <joquendo@e-fensive.net> wrote:
Anyone else seeing DGA (1) like behavior for Comcast based customers? If so, is there any information on it? Seeing a lot of traffic to bogus domains all synonymous with their networks.
don't they have a anti-botnet-automagic-walled-garden thing that's supposed to stop this? (also, example request RRs?)