top | item 17515115

(no title)

wwwv | 7 years ago

They are linked as HTTP referrer, so they can get the tokens out of the stats page later on.

It's using a popular and well known domain to evade detection.

discuss

order

Vinnl|7 years ago

That's true, but doesn't it also place their fate in the hands of the owners of StatCounter and HiStats?

(Of course I am just speculating - there's definitely still ways this could be abused. I'll update my comment.)

sdf43543t345|7 years ago

Doesn't matter. Google Analytics was used to steal ethereum seeds too (as the 'referer' also I believe). Its common to use analytics as exfiltration services -- the traffic is not as suspicious and usually https.

wwwv|7 years ago

That's why they're using two different stats engines.