Kazy Part Deux: Revenge of the Clear Plastic Tarp
Ohhh, Kazy, you so krazy. It seems Kazy has moved to using outbound UDP port 53 for part of its coms. From what we discern, it appears to be check-in-related traffic. The payloads are static but change on a host-by-host basis. This time, Kazy doesn’t seem to make any attempt to emulate DNS. Outbound UDP [...]