APTMembers
APT

Matching subdomains point to different CNAME targets

Two domains carry the same pair of subdomain labels, suggesting a parallel naming scheme. Their recorded aliases do not demonstrate a shared backend, so the DNS link does not establish interchangeable routes or malware delivery.

Oct 10, 2026, 07:26 (UTC+9)Last seenOct 10, 2026Severity100ByCTX TeamActorGold EvergreenBusiness ClubIOC15RegionsUS

Two domains carry the same pair of subdomain labels: yzzcommon and 69f335c8397887d4. That repeated structure raises a concrete question: were the domains interchangeable routes to the same destination? DNS records supplied to CTX Threat Intelligence support a parallel naming scheme, but not a single demonstrated backend. The distinction matters because a useful infrastructure link can otherwise become an unsupported claim about redundancy or malware delivery.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence