FILEMembers
FILE

Dormant Domain Wakes Days Before New Invoice-Lure Malware Wave

A domain registered in November 2025 sat idle for seven months before both it and its origin server received new TLS certificates in a 48-hour window in late June 2026. Six days later, an invoice-themed loader and its RAR carrier surfaced, suggesting deliberately staged infrastructure rather than always-on C2.

Jun 29, 2026, 21:46 (UTC+9)Last seenJul 2, 2026Severity100ByCTX TeamIOC23MITRE38RegionsAUCNDEHUIE

Seven months after a Namecheap registrant quietly stood up xingtialai.com, the domain's operators finally bothered to secure it: a Let's Encrypt certificate was issued for the site on 2026-06-23, and the origin server behind it picked up its own certificate two days earlier, on 2026-06-21. Within a week, on 2026-06-29, two brand-new files — an invoice-themed .NET loader and the RAR archive that appears to have delivered it — surfaced carrying anti-sandbox timers and debugger checks.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence