C&CMembers
C&C

DNS links flagged domain to IP with matching TLS fingerprints

The A record for `dfkjgoi3.info` points to `213.108.199.215`, and saved certificate and JARM records match across the two indicators. Those observations strengthen the case for investigating them as a related service, but neither the command-and-control classification nor the infrastructure match establishes malware traffic or an operator.

Oct 8, 2026, 23:52 (UTC+9)Last seenOct 8, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC62MITRE48RegionsUA

The DNS record for dfkjgoi3.info points to 213.108.199.215, and the two indicators carry matching recorded HTTPS certificates and JARM service fingerprints. That combination raises a more useful question than whether either address has a malicious reputation: how firmly does the evidence identify a common service, and what activity can actually be attached to it? CTX Threat Intelligence’s records support a concrete domain-to-IP relationship, reinforced by matching TLS characteristics.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence