
FILEMembers
FILEBatch-Registered Domains Mimic Baixaki to Push COMODO-Signed Adware
Three domains registered in the same second by the same registrar built a fake Brazilian download portal that fronted a DealPly-tagged installer. The apex domain and its two subdomains share a WHOIS timestamp and a single hosting IP, tying the campaign together years after it went dark.
Jul 7, 2026, 18:55 (UTC+9)Last seenJul 7, 2026Severity100ByCTX TeamIOC18MITRE34RegionsBR
Three domains registered in the same transaction, at the same registrar, at the same second, are doing the work of an entire distribution network for a low-detection installer campaign. The apex domain, baixakialtcdn.com, and its two operational subdomains — os.baixakialtcdn.com and os2.baixakialtcdn.com — were all created through PDR Ltd.
Members only
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to readSource: CTX Threat Intelligence