
One Wildcard Certificate Links Five China Unicom IPs Across Four Subnets
Five IP addresses spread across four separate CIDR blocks inside China Unicom's backbone all serve the identical *.certfallback.com wildcard certificate, a pattern CTX Team reads as a deliberately engineered fallback pool rather than shared hosting. All five addresses show zero VirusTotal detections, making the cluster invisible to reputation-based defenses.
Five IP addresses sitting on four separate subnets inside China Unicom's core network all answer HTTPS requests with the exact same TLS certificate — serial 6696262f452fcf46b79266a8, issued by GlobalSign GCC R46 OV TLS CA 2025, carrying the subject organisation "Alibaba (China) Technology Co., Ltd." and a wildcard subject name of *.certfallback.com. That is not a coincidence of shared hosting; it is one certificate identity deliberately deployed across a diversified physical footprint.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read