Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How many ISPs spoof failed DNS queries so they can feed you ads? That alone would make this useless as an evasion technique.


It means the malware would not execute for users on those ISPs because they false-positive for being a sandbox; that doesn't make it useless unless every ISP is doing that.


OTOH it means that laptops won't activate until they are on a work network, for an SMB worm that's probably not a bad strategy.


Clearly not that many considering how well it did manage to spread.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: