APTMembers
APT

A Disposable AWS Front and a CDN Wildcard Are the Real Story, Not the File

A templated beacon domain delegated through Amazon's Route53 and a CDN-fronted IP wearing an Edgenext wildcard certificate carry more evidential weight than the single file bundled alongside them. Neither infrastructure piece shares a registrar, ASN, or certificate with the other or with the aging, signed network scanner in the same collection pull.

Aug 9, 2026, 01:46 (UTC+9)Last seenAug 9, 2026Severity64ByCTX TeamActorLockbit GangIOC9MITRE4

Two pieces of infrastructure — a beacon domain delegated through Amazon's own nameservers and a CDN-fronted IP wearing someone else's wildcard certificate — carry far more evidential weight in this record than the single file attached to it. The domain, wb.sleevesbarbing.com, resolves through eight rotating A-records behind AWS Route53 delegation and serves six URLs that all follow the identical templated path /mtn/130079/<32-character-hash>.<epoch-timestamp>.000.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence