FILEMembers
FILE

A Five-Minute Certificate, a Decade-Old Encryptor, One Shared Record

A phishing-flagged UK domain received a TLS certificate that expired five minutes after issuance, one node in a 24-domain, six-IP catalog built on burner certificates and wildcard reuse. The only file tied to the record is a decade-old Cerber/CryptoWall encryptor with no cryptographic link to any of the surrounding infrastructure.

Aug 22, 2026, 14:52 (UTC+9)Last seenAug 22, 2026Severity77ByCTX TeamActorRtmIOC37MITRE22RegionsUS

A domain flagged for phishing and fraud, atlanticinsulationservices.co.uk, was issued a TLS certificate on August 10, 2026 that expired five minutes after it was cut — valid from 11:17:47 to 11:22:47 UTC. That is not the certificate of a working website; it reads like automated infrastructure standing itself up, existing, and disappearing before an analyst could even resolve it in a browser.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence