
A Redirect Node With No Name: Certificate Cycling Masks a 2014 Dropper
A domain buried in a routine C2 record serves a certificate for a hostname no one requested, exposing it as a relay in a shared hosting fabric rather than an independent site. Sixteen domains and three scattered IPs turn out to be linked not by malware code but by the rhythm of Let's Encrypt certificate reissuance.
A domain buried inside a routine C2-infrastructure record — baktus.kilu.de — is not serving its own website. Query it over TLS and the certificate that comes back carries the subject name redirect.subdomain.com, a string that points nowhere near the domain a browser actually requested. That mismatch is the clearest single artefact in this record: it marks the node as a relay hop inside a shared hosting fabric, not an independent site with its own identity.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read