
Self-Signed 'malware.com' Cert Ties Two Domains to One Host
Two subdomains of one Dynadot-registered domain share an identical self-signed certificate literally naming '*.malware.com,' the same AWS-style IP, and a 36-URL update.json polling pattern. CTX Team's read of the infrastructure clashes sharply with the feed's APT28/shlayer attribution tag.
Two subdomains of one 2018-registered domain — update.buffernavpose.com and errors.buffernavpose.com — terminate in an identical self-signed TLS certificate whose subject and issuer both read literally "*.malware.com," issued under the stock OpenSSL demo organization name "Internet Widgits Pty Ltd." Both hostnames resolve to the same address, 34.209.195.255, and both sit on a domain registered through Dynadot Inc on 2018-05-12 and still being updated as recently as 2026-04-16.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read