securityskeptic :donor: :verified:<p>MSFT obtains court order to sinkhole Cobalt Strike C&C traffic. </p><p>The order lists 16 John Does as </p><p>Appendix A of the order identifies the Hosting Companies/Data <br>Centers Where Defendants <br>Placed the Command and <br>Control Servers and the 1000 or so C&C IP addresses. </p><p>It also includes the Whois for the ~110 C&C domains. </p><p>The contact data for these are redacted or unavailable from the ccTLD operator. </p><p>So...</p><p> _none_ of the domain registrations yielded the name and contact of a party that could be named as a defendant in the action?</p><p>Microsoft's attorneys have filed dozens of orders like this one. Surely they asked for a Whois reveal or asked for billing data.</p><p>So...</p><p> _none_ of the domain registration BILLING DATA yielded the name and contact of a party that could be named as a defendant in the action?</p><p><a href="https://www.databreachtoday.com/microsoft-gets-court-order-to-sinkhole-cobalt-strike-traffic-a-21650" rel="nofollow noopener" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">databreachtoday.com/microsoft-</span><span class="invisible">gets-court-order-to-sinkhole-cobalt-strike-traffic-a-21650</span></a></p><p><a href="https://infosec.exchange/tags/ransomware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ransomware</span></a> <a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>malware</span></a> <a href="https://infosec.exchange/tags/cobaltstrike" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cobaltstrike</span></a> <a href="https://infosec.exchange/tags/c2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>c2</span></a> <a href="https://infosec.exchange/tags/whois" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>whois</span></a> <a href="https://infosec.exchange/tags/itsalwaysdns" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>itsalwaysdns</span></a> <a href="https://infosec.exchange/tags/exceptwhenitsIPs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>exceptwhenitsIPs</span></a></p><p>Set aside privacy protection (it can be managed for all natural person's complete and accurate contact data) but share with me:</p>