About 8 months after their first visit, my server gets another visit from the Bitcoin pickpockets. It's another IP address this time (again an VPN exit node), but the user agent string is exactly the same:
The requested filenames are identical, except for 4 new files/folders (3 of them highlighted in red in the picture below). The order of request is different from the first time. If you have observed this too or have a remark, please post a comment. Didier Stevens |
DidierStevens 647 Posts ISC Handler Jul 21st 2018 |
Thread locked Subscribe |
Jul 21st 2018 3 years ago |
Hits from June 11, reported on June 51 [July 21] ?
How often do you review your log-files? Maybe, it was me, trying to find BitCoin to send to my brother, on his birthday. ![]() |
Anonymous |
Quote |
Jul 21st 2018 3 years ago |
Hmmm. The meta-data for my post, a few seconds ago, shows:
____________________ DidierStevens 90 Posts Posts Reply Quote Edit Jul 21st 2018 10 seconds ago ____________________ Not citing my ID, and "Posts Posts" is is redundantly redundant. ![]() |
Anonymous |
Quote |
Jul 21st 2018 3 years ago |
Hmmm. That metadata for my first post now shows "Anonymous" and just one "Posts".
Nothing can go wrong, go wrong, go wrong, go wrong, go wrong, go wrong, go wrong ... |
Anonymous |
Quote |
Jul 21st 2018 3 years ago |
Sign Up for Free or Log In to start participating in the conversation!