← Back to context

Comment by lantry

5 hours ago

> Side note: Why use a raw IP address? If anything, this screams “malware.” At least register a decoy domain like lint-checker.com or jenkins-ci-runner.net. If the threat actors who wrote this are reading: take notes people!

Maybe they don't want to give any identifying info to the domain registrar? Or just minimizing their online presence?

Or possibly these hosts fell victims of their malware, too, and see now used as proxies.