
DNS links flagged domain to IP with matching TLS fingerprints
The A record for `dfkjgoi3.info` points to `213.108.199.215`, and saved certificate and JARM records match across the two indicators. Those observations strengthen the case for investigating them as a related service, but neither the command-and-control classification nor the infrastructure match establishes malware traffic or an operator.
The DNS record for dfkjgoi3.info points to 213.108.199.215, and the two indicators carry matching recorded HTTPS certificates and JARM service fingerprints. That combination raises a more useful question than whether either address has a malicious reputation: how firmly does the evidence identify a common service, and what activity can actually be attached to it? CTX Threat Intelligence’s records support a concrete domain-to-IP relationship, reinforced by matching TLS characteristics.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read