DNS analysis of 96 SourTrade domains uncovered hundreds of connected domains and IP addresses, many flagged as malicious, while identifying indicators that appeared months before researchers formally linked them to the malvertising campaign.