Comment by dwedge
20 hours ago
> If you want a malware report to be taken seriously, in general, you should expect to roll up your sleeves and be able to provide an analysis of concrete malicious behaviour.
I reported them all the Cloudflare and Cloudflare took them down. One moved away from Cloudflare, and Twitter kept them up.
I reported another to NiceNIC and they asked for: 1. Verifiable malicious download file or sample hash 2. Screenshot or screen recording with the full URL visible 3. Evidence of malicious scripts, obfuscated code, or download chain 4. HTTP response, redirect chain, headers, or packet capture data 5. Third-party security verdict tied to the specific URL or file
I just ignored them. I don't work for them and if they want to host illegal content then it's not my business decision.
This one in particular had the download in base64, piping into Javascript and running a binary as a fake Apple Updater script.
But I am sick of this attitude that it's my responsibility for a malware report to be taken seriously. If they introduce malware bounties then ok, but otherwise I'm doing them a favour by reporting it and if they want to continue to host it after reasonable being made aware of its existence, they should be legally responsible.
> But I am sick of this attitude that it's my responsibility for a malware report to be taken seriously.
It takes no effort to make the claim, and considerable effort to act upon it. Why should they believe you, a priori?