
Same Cert Cadence Links Phishing Site to Domain Farm
A phishing-flagged Spanish domain and two nuronapp.com hosts share an identical Let's Encrypt 'YR2' issuer and 89-day validity window issued within days of each other. A wildcard certificate on nuronapp.com further exposes at least nine hidden pivot-brand subdomains never otherwise seen in the record.
Three domains that have nothing else in common — a Spanish site already flagged for phishing, and two hosts sitting under a fifteen-year-old apex — were all issued Let's Encrypt certificates through the identical "YR2" intermediate, with identical 89-day validity windows opened within a nine-day span. lavers.es, which alphaMountain.ai categorizes as Phishing, picked up a YR2 certificate valid 2026-06-05 through 2026-09-03. treddle.nuronapp.com got one valid 2026-05-29 through 2026-08-27.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read