
83 'Suppobox' Domains Trace Back to a Handful of Shared Hosts
Analysis of an 83-domain C2 category tagged 'suppobox' finds the real story isn't a payload but the hosting fabric underneath — batch-registered word-pair domains funneling into a small set of shared IPs, recycled nameservers, and borrowed or oversized certificates. A single decade-old file indicator sits awkwardly alongside a domain population that was active years later.
Eighty-three lookalike ".net" domains sit inside a single threat-feed category tagged "suppobox," but the interesting story here is not a payload — it is how the hosting layer beneath those domains was built. Stripped of their two-word dictionary names (gentlemanprobable, waterbicycle, experiencewithout), the domains resolve down to a handful of shared IPs, recycled nameserver pairs, and certificates that were either batch-issued or borrowed outright from unrelated infrastructure.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read