I know there is a cooldown period for npm packages, but I’m beginning to want a cooldown for domains too. According to socket, the C2 server is sfrclak[.]com, which was registered in the last 24 hours.
NextDNS has a setting to block newly registered (<30d) domains.
NextDNS has a setting to block newly registered (<30d) domains.