During the investigation of an incident, the CSIRT (Computer Security Incident Response Team) of Cegeka Modern SOC discovered a threat actor-controlled infrastructure that was publicly exposed through a WSO (web shell by ORb) PHP web shell. The investigation revealed that a threat actor was abusing 'FreeDNS' services of a DNS provider to register multiple subdomains under legitimate parent domains, without the domain owner’s approval. All these subdomains resolved to the same infrastructure, which hosted web shells and other malicious files that were actively used in phishing campaigns.
This blog, authored by Cristina Aldea and Christos Katopis from Cegeka CSIRT, provides both an overview and a detailed report on the threat actor’s infrastructure as well as the malicious files that were located in their server.
The threat actor-operated server contained multiple malicious web shells, including but not limited to different versions and variants of WSO (web shell by ORb) web shell, phishing pages, credential harvesters and mailer web shells. Further analysis of the tools showed that some of them were related to ‘AnonymousFox’ and other were likely acquired from different cybercrime marketplaces.
The server hosted multiple websites. Each website corresponded to a different subdomain. Surrounding evidence showed that ‘cpanel’ was used for the website and web server management.
Publicly available information suggests that, as of the 30th of June 2026 at least 216 unique subdomains resolved or used to resolve to the public IP address of the server. Some of the subdomains that first appeared on the 27th of April 2026, and more notably on the 6th of May 2026, were related to legitimate parent domains that were registered under the same DNS provider (‘afraid.org’).
Surrounding evidence showed that the threat actor abused ‘FreeDNS’ services of ‘afraid.org’ in order to register subdomains that appeared to be related to legitimate domains that were already hosted under the same ‘FreeDNS’ provider. It is worth noting that ‘afraid.org’ allows a user to add a domain as ‘public’ in their shared domain registry. This allows others to attach subdomains without the domain owner’s approval.
These actions suggest an effort by the threat actor to make the domain appear more trustworthy and legitimate, increasing the probability that users would interact with its associated content.
Please find the full Cegeka CSIRT threat analysis report which includes the observed indicators of compromise here:
Cegeka CSIRT encourages organizations to:
Our Cegeka Modern SOC, staffed with experienced security professionals, can detect and respond to cybersecurity incidents in a timely manner, minimizing or even fully preventing impact on your organization.