
Dormant Domain Wakes Days Before New Invoice-Lure Malware Wave
A domain registered in November 2025 sat idle for seven months before both it and its origin server received new TLS certificates in a 48-hour window in late June 2026. Six days later, an invoice-themed loader and its RAR carrier surfaced, suggesting deliberately staged infrastructure rather than always-on C2.
Seven months after a Namecheap registrant quietly stood up xingtialai.com, the domain's operators finally bothered to secure it: a Let's Encrypt certificate was issued for the site on 2026-06-23, and the origin server behind it picked up its own certificate two days earlier, on 2026-06-21. Within a week, on 2026-06-29, two brand-new files — an invoice-themed .NET loader and the RAR archive that appears to have delivered it — surfaced carrying anti-sandbox timers and debugger checks.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read