C&CMembers
C&C

Aged Vietnamese Domain Reissued as C2 Behind Evasive .NET Loader

A three-year-old domain, canhtrang.com, was quietly re-certificated with an 89-day TLS cert and now binds to a self-signed VPS host running a forged-timestamp, high-entropy .NET loader. No actor or malware family is named, but the certificate linkage exposes a repurposed licensing backend serving as command-and-control.

Jun 28, 2026, 06:04 (UTC+9)Last seenJul 2, 2026Severity82ByCTX TeamIOC15MITRE23

A three-year-old Vietnamese domain, canhtrang.com, has resurfaced with a freshly issued 89-day TLS certificate and a self-signed administrative host that binds directly to a single evasive Windows loader — a pattern that looks less like a new campaign standing up infrastructure from scratch than an old, ordinary-looking licensing backend being quietly repurposed for command-and-control. The domain's free., lic., and ping.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence