
Six-Year-Old Domain, Faked Autodiscover Cert Outshine Blank File Hashes
Three Thai subdomains carved from a real medical-software vendor's namespace, a Singapore IP wearing a forged A2 Hosting certificate, and a six-year-old Chinese domain freshly reissued form the only legible signal in a record with 16 file indicators and zero file-level metadata. CTX Team reads this as a hosting-and-camouflage fingerprint, not a payload story.
Three subdomains carved out of a Thai medical-software vendor's own domain zone, a Singapore-hosted IP wearing a certificate that borrows another hosting provider's name, and a six-year-old Chinese-registered domain freshly reissued with a GoDaddy certificate — together these form the only legible signal in a record that otherwise offers almost nothing.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read