
Certificate-Recycling Pipeline Links 12 Domains Behind Weak Detection
Three Let's Encrypt and Google Trust Services CA intermediates tie together a scattered pool of gambling lures, aged domains, and a sinkholed relic. Two unrelated domains registered a year apart even converge on the same IP, revealing a hosting discipline that outpaces the campaign's near-invisible detection scores.
Twelve domains, four IP addresses, and a single executable make up this cluster — and on the surface, they look unrelated: a decade-old Vietnamese-language domain, a pair of gambling lure pages using Indonesian togel slang, a 2016-registered relic now sitting on sinkhole nameservers, and a 221MB EV-signed installer called "Rave.exe." What ties them together isn't a shared malware family or a dedicated bulletproof host.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read