C&CMembers
C&C

A Nine-Second Certificate Gap Exposes a Scripted C2 Build

Two Cloudflare-fronted domains on unrelated TLDs share one resolving IP and received Let's Encrypt certificates nine seconds apart, revealing a scripted provisioning event rather than independent registrations. Alongside a structurally distinct AWS-hosted redirector and two unrelated payloads, the pattern points to two separately engineered infrastructure playbooks under one campaign.

Jul 14, 2026, 05:39 (UTC+9)Last seenJul 14, 2026Severity100ByCTX TeamActorSpring DragonLotus BlossomIOC7MITRE19

Two domains on opposite sides of the top-level-domain map — deluxe.gl and geo-foundation.vg — resolve to the identical IP address, 79.124.59.146, and each received a Let's Encrypt certificate within nine seconds of the other on 2026-06-13. That kind of timing does not happen between two independent registrants. It happens when one operator, or one script, provisions both hostnames as part of the same build.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence