DarkPeonyâs Trail: Certificate Patterns Point to Sustained Campaign Infrastructure
ID: 403993e9-59c1-50ea-a5fe-9cc298e4da0e
STIX ID: report--403993e9-59c1-50ea-a5fe-9cc298e4da0e
Feed Name: Hunt.io Blog
This analysis expands on previously reported DarkPeony infrastructure associated with PlugX: investigators identified multiple IPs, domains, and SSL certificate patterns (notably 'AES' in OU and CloudFlare origin certs) used to hide C2 and malware distribution. The report links a malicious 'Meeting Invitation.msc' sample to domains (e.g., vabercoach.com, loginge.com), lists IPs, ASNs and certificate hashes as network observables, and offers a JARM/subject CN query to help defenders hunt for related CloudFlare-origin certificates and emerging infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
