C&CMembers
C&C

36 'sslsecure' Domains Mask a Templated Adware Pipeline

Thirty-six hostnames built from a single sslsecure<N>.com template, registered in three bursts across eight registrar fronts between 2015 and 2020, sit behind a signed Win32 installer tied to the domaiq PUP/adware lineage. The domain layer's scripted naming and persistent nameserver backend outshine the malware sample it fronts for.

Jun 27, 2026, 09:20 (UTC+9)Last seenJul 2, 2026Severity100ByCTX TeamIOC39MITRE29RegionsUS

Thirty-six hostnames sit behind an indicator set that VirusTotal enrichment and registrar records tie to a single naming convention: sslsecure<N>.com, reproduced apex-for-apex with an identical api.v2., track.v2., and staticrr. subdomain triplet bolted onto each one. The pattern runs from sslsecure2.com through sslsecure10.com, and it isn't cosmetic — it's a templated hosting fabric built to look, at a glance, like generic SSL or security infrastructure rather than adware plumbing.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence