FILEMembers
FILE

Aged GoDaddy Domains Get Synced Certs, Front 2018 Macro Downloader

Two 19-20-year-old GoDaddy domains plus a third UK domain/IP pocket were all reissued matching 89-day Let's Encrypt certificates within weeks of each other. The only fully profiled payload tied to the pattern is a macro-laced Word downloader dated to 2018, suggesting recycled hosting propping up a legacy loader.

Sep 12, 2026, 06:50 (UTC+9)Last seenSep 12, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC13

Two domains that have sat quietly under GoDaddy registration since the mid-2000s were both re-fronted with brand-new Let's Encrypt certificates within about five weeks of each other in mid-2026 — dthakar.com and elmodular.com, ages 19 and 20 years respectively, neither showing any sign of active legitimate use in that span. A third node, eatspam.co.uk, and its sole resolving address, 45.158.164.138, picked up matching certificates from the same issuer pool on an overlapping schedule.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence