
WebMonitor RAT Hides Behind Rotating Pool of Hex-Named .to Domains
Nine algorithmically-named .to domains share an identical 'stubbzy/recv3.php' checkin path, exposing a single C2 operator's disposable infrastructure behind two commodity RAT binaries. Two outlier domains that kept registration and certificate records stand apart as the pool's rare paper trail.
Nine domains that look, at first glance, like noise — 81252b01.to, 69385701.to, efe87401.to, 1e517001.to, cf488101.to, 49b56c01.to, bb8c4e01.to, 53fb0701.to, 93319601.to — turn out to share a single, deliberate signature: every one of them exposes an identical subdomain, "stubbzy," and an identical checkin path, "recv3.php." That is not what independently registered infrastructure looks like.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read