
A 2019 Emotet Invoice Lure Resurfaces With Newly Certified Dormant Domains
A German/Polish invoice-themed Word document tied to Emotet's 2019 malspam wave has resurfaced in telemetry alongside four domains registered between 1997 and 2026. Three sat dormant for a decade or more before recently receiving fresh TLS certificates, suggesting old crimeware infrastructure being reactivated rather than a newly built campaign.
A Word document dressed as a German electricity invoice and a Polish payment notice has resurfaced in telemetry alongside four domains whose registration dates read like a timeline of the internet itself — 1997, 2004, 2014, and 2026. Three of those domains sat dormant for a decade or more before anyone bothered to issue them a fresh TLS certificate; the fourth, registered this year, doesn't even carry its own certificate, borrowing a wildcard from a shared hosting platform instead.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read