
Bright Data-Signed EarnApp Loader Unchanged as 66 New Domains Surround It
The same four DigiCert-signed EarnApp/net_updater binaries tied to a PBot stealer persist untouched from the prior snapshot, but this update adds 66 new domains and 19 new IPs against just 9 new file hashes. Two registrar cohorts and two certificate-issuer cohorts now bind dozens of previously unrelated-looking domains into the same picture.
The malicious file cluster that CTX Team first catalogued around a Bright Data Ltd-signed EarnApp installer has not moved: the same four binaries, the same DigiCert Trusted G4 Code Signing chain, the same detection spread running from 9 of 75 engines to 24 of 76. What has moved, sharply, is everything sitting around it. This snapshot adds 66 new domains and 19 new IPs against just 9 new file hashes — an order of magnitude more growth in registration and certificate infrastructure than in…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read