
Disposable Certs and VPS Templates Tie Together a VPN-Trojan/Stealer Web
Three Philippine VPS instances share one self-signed certificate with no domain layer at all, while two redbankenergy.com subdomains front an unrelated 'claudeinwechat.com' certificate. The pattern extends to a revoked WEILAI-signed VPN installer cohort and a validly Bright Data-signed 'Bright SDK' set that sandboxes as the PBot stealer.
Three IP addresses in a single Zenlayer /21 block in the Philippines — 156.59.113.131, 156.59.113.132, and 156.59.113.134 — are all presenting the exact same self-signed TLS certificate, serial 1acf3e37b37910d932ea64e6bb27615d6484c07d, valid from March 2024 clear through March 2034. None of the three shows any VirusTotal detections (0/91 across the board), and none carries a hostname behind the certificate — the issuer and subject fields both read simply "NONE." That absence of a domain layer…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read