
Espionage C2 Domain Hides Behind Its Hosting Provider's Certificate
The domain mercadojs.com serves malicious command-and-control traffic from a Hostinger shared-hosting IP whose TLS certificate belongs to Hostinger's own brand, not the attacker. The domain runs its own short-lived Let's Encrypt cert, creating a split identity that lets flagged infrastructure inherit a clean IP reputation.
An espionage-linked command-and-control domain, mercadojs.com, is presenting a public face that belongs to its landlord rather than its operator. The domain resolves to a single IP address, 82.25.83.117, sitting on AS 47583 — Hostinger International Limited — but the certificate served from that address is issued to "hostinger.com" with a wildcard subject-alternative-name covering *.hosting24.com, both of them Hostinger's own branded properties, not mercadojs.com.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read