
A Nine-Second Certificate Gap Exposes a Scripted C2 Build
Two Cloudflare-fronted domains on unrelated TLDs share one resolving IP and received Let's Encrypt certificates nine seconds apart, revealing a scripted provisioning event rather than independent registrations. Alongside a structurally distinct AWS-hosted redirector and two unrelated payloads, the pattern points to two separately engineered infrastructure playbooks under one campaign.
Two domains on opposite sides of the top-level-domain map — deluxe.gl and geo-foundation.vg — resolve to the identical IP address, 79.124.59.146, and each received a Let's Encrypt certificate within nine seconds of the other on 2026-06-13. That kind of timing does not happen between two independent registrants. It happens when one operator, or one script, provisions both hostnames as part of the same build.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read