Code 1 – Configuration for the proxy plugin (proxy_cfg).
Most of the traffic is over HTTPS to popular websites, including several Russian ones. Figure 2 lists the top hostnames contacted by the bot.
Figure 2 – Most requested HOST:PORT pairs.
While looking through the traffic, we spotted an interesting pattern.…