C&CMembers
C&C

83 'Suppobox' Domains Trace Back to a Handful of Shared Hosts

Analysis of an 83-domain C2 category tagged 'suppobox' finds the real story isn't a payload but the hosting fabric underneath — batch-registered word-pair domains funneling into a small set of shared IPs, recycled nameservers, and borrowed or oversized certificates. A single decade-old file indicator sits awkwardly alongside a domain population that was active years later.

Aug 29, 2026, 00:50 (UTC+9)Last seenAug 29, 2026Severity87ByCTX TeamIOC93MITRE25RegionsUS

Eighty-three lookalike ".net" domains sit inside a single threat-feed category tagged "suppobox," but the interesting story here is not a payload — it is how the hosting layer beneath those domains was built. Stripped of their two-word dictionary names (gentlemanprobable, waterbicycle, experiencewithout), the domains resolve down to a handful of shared IPs, recycled nameserver pairs, and certificates that were either batch-issued or borrowed outright from unrelated infrastructure.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence