C&CMembers
C&C

Shared Certificates, Not Payloads, Tie Five Emotet-Linked Domains

A cluster of five domains and one Hostinger-hosted IP shows more evidence of coordinated infrastructure than of malicious payload activity. Two certificate-issuer cohorts and a shared nameserver pairing link the nodes with far greater precision than the lone file sample in the record can offer.

Jul 31, 2026, 05:44 (UTC+9)Last seenJul 31, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC11RegionsUS

Five domains and a single Hostinger-hosted IP address form a hosting cluster that looks less like purpose-built command infrastructure and more like a disposable inventory kept in circulation for years. Across the set, two distinct certificate-issuer cohorts and a shared nameserver pairing tie the nodes together with far more precision than anything the lone piece of file telemetry in this record can offer. The strongest signal here isn't a payload — it's the paperwork.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence