
AS214351 Adds 'PureCrack' Relay Node and DGA Domains in C2 Expansion
A follow-up snapshot of a financially motivated multi-family malware campaign reveals a new relay node on 196.251.107.104 bearing a self-issued ten-year wildcard TLS certificate labelled 'PureCrack / Relay.' Two algorithmically generated .com domains have appeared alongside it, signalling the operator is layering domain-based fallback channels onto a raw-IP C2 foundation. A near-invisible installer stub detected by only 1 of 76 engines points to parallel evasion experimentation.
Since CTX Team's earlier coverage of this financially motivated campaign — documented then as a raw-IP beaconing operation running six malware families across a single young autonomous system — ten new files, two algorithmically generated domains, and a second command-and-control IP have surfaced. The most operationally significant addition is not another payload variant but a structural change to the hosting fabric itself: 196.251.107.104, a new node within AS214351 operated by Femo IT…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read