C&CMembers
C&C

Self-Signed 'malware.com' Cert Ties Two Domains to One Host

Two subdomains of one Dynadot-registered domain share an identical self-signed certificate literally naming '*.malware.com,' the same AWS-style IP, and a 36-URL update.json polling pattern. CTX Team's read of the infrastructure clashes sharply with the feed's APT28/shlayer attribution tag.

Jul 10, 2026, 08:48 (UTC+9)Last seenJul 10, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC40MITRE15

Two subdomains of one 2018-registered domain — update.buffernavpose.com and errors.buffernavpose.com — terminate in an identical self-signed TLS certificate whose subject and issuer both read literally "*.malware.com," issued under the stock OpenSSL demo organization name "Internet Widgits Pty Ltd." Both hostnames resolve to the same address, 34.209.195.255, and both sit on a domain registered through Dynadot Inc on 2018-05-12 and still being updated as recently as 2026-04-16.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence