
One TLS Certificate Ties Five Hosts to Sekisui House Impersonation
Seventeen IPs linked to an Allaple-tagged file drop cluster almost entirely inside AS4713, a Japanese carrier block run by NTT DOCOMO BUSINESS. Five of those hosts share a byte-identical wildcard certificate spoofing homebuilder Sekisui House, while all 17 addresses score 0/90 on malicious-detection scans.
Seventeen IP addresses sit inside a single file-hash record tagged to the Allaple worm family, and fourteen of them collapse into one place: AS4713, registered to NTT DOCOMO BUSINESS,Inc. Five of those fourteen — 202.18.210.172, 202.18.210.153, 202.18.209.143, 202.18.209.144, and 202.18.209.153 — serve a byte-identical TLS certificate, serial b9f3aa6546060eaeb9b07a8fed689d8, issued by GeoTrust TLS RSA CA G1 under DigiCert, with a wildcard subject of *.sekisuihouse.co.jp.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read