
Same-Day Certificates Expose Scripted C2 Build-Out Behind Two Trojans
A cluster of five domains, four IPs and two Windows droppers shares a same-day Let's Encrypt certificate pattern, a NICENIC registrar cohort, and a cert-serial match tying a fresh domain to its live hosting IP. The payloads are generic signed-but-untrusted installers — the real signature is how fast the infrastructure was assembled.
Three infrastructure nodes — the IPs 31.58.134.74 and 80.97.160.31, plus the freshly minted domain powershell-storage.vg — received Let's Encrypt certificates from the same "YE2" intermediate within a two-day window in June, each carrying an identical 89-day validity span. That kind of synchronized issuance is not how organically managed hosting behaves; it is what scripted infrastructure provisioning looks like when an operator wants a C2 front live and disposable within hours of registering…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read