C&CMembers
C&C

AS214351 Adds 'PureCrack' Relay Node and DGA Domains in C2 Expansion

A follow-up snapshot of a financially motivated multi-family malware campaign reveals a new relay node on 196.251.107.104 bearing a self-issued ten-year wildcard TLS certificate labelled 'PureCrack / Relay.' Two algorithmically generated .com domains have appeared alongside it, signalling the operator is layering domain-based fallback channels onto a raw-IP C2 foundation. A near-invisible installer stub detected by only 1 of 76 engines points to parallel evasion experimentation.

May 26, 2026, 21:16 (UTC+9)Last seenJun 10, 2026Severity100ByCTX TeamIOC30MITRE18RegionsALBOCADEDZ

Since CTX Team's earlier coverage of this financially motivated campaign — documented then as a raw-IP beaconing operation running six malware families across a single young autonomous system — ten new files, two algorithmically generated domains, and a second command-and-control IP have surfaced. The most operationally significant addition is not another payload variant but a structural change to the hosting fabric itself: 196.251.107.104, a new node within AS214351 operated by Femo IT…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence