
A 2012 Domain Registration Still Feeds a Fake Firefox Installer Today
Three domains bulk-registered in October 2012 remain active software-download fronts, tied through shared IP infrastructure to a GlobalSign certificate spanning Spain and Italy under a Brazilian CDN's ASN. CTX Team maps this as thirteen years of low-detection persistence built around a mis-signed Firefox-impersonating installer.
Three domains bulk-registered on a single day in October 2012 are still actively serving software downloads today, and CTX Team's infrastructure mapping ties the pair of IP addresses behind their apparent callback layer to a shared TLS certificate spanning two European countries under one Brazilian CDN provider's autonomous system.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read