C&CMembers
C&C

Twenty IPs, One Certificate: How a Phorpiex C2 Pool Mimics 2345.com

Eight of twenty IPs flagged as Phorpiex command-and-control infrastructure sit inside a single China Telecom ASN, and five of those share one TLS certificate branded as the Chinese portal 2345.com. Individually near-invisible to detection engines, the pool becomes legible only once certificate serials and ASNs are cross-referenced.

Jun 11, 2026, 19:10 (UTC+9)Last seenJul 2, 2026Severity100ByCTX TeamIOC30MITRE20RegionsCN

Eight of the twenty IP addresses flagged as command-and-control infrastructure for a financially motivated operation tracked under the phorpiex family sit inside a single China Telecom autonomous system, AS4811 — and five of those nodes present an identical TLS certificate, serial d3d9e9261c1c88d957e704d69617a469, whose subject reads *.2345.com.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence