Posts by jeroengui@infosec.exchange
 (DIR) Post #B4hPE1rdg5Ua5j4ex6 by jeroengui@infosec.exchange
       0 likes, 0 repeats
       
       @keepassxc Of course, there’s no full takedown until the domain is placed on client/server hold. That's correct!That said, in practice, I rarely see any recovery once Cloudflare puts up a warning page. It’s usually easier for the threat actor to register a new domain.The good news is that this domain has already propagated across most major AV vendors, and I’ve shared both the domain indicators and the associated malware samples with several partners and information-sharing networks (Quad9, GCA, GSE, etc.). That should help ensure any residual risk is blocked at multiple layers.I'll set up some monitoring for both this domain and any future attempts to impersonate KeePassXC.