ZeroHour

Indicators of compromise

1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domain33115c.comtbot[.]xyz Janoub-hightech[.]com Internationaljobsite[.]com 33115c[.]com Adversaries used ChatGPT-related URLs to spread spam messScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainbardassai.comparking campaign we have identified involved nine domains: Bardassai[.]com Gemini-addons[.]com Gemini-agents[.]com Gemini-agi[.]comScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainchatgpt0002.cngpt000[.]cn Chatgpt008[.]cn Chatgpt178[.]cn Chatgpt009[.]cn Chatgpt0002[.]cn Chatgpt188[.]cn Chatgptapp888[.]cn Chatgpt138[.]cn ChatgpScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainchatgpt000.cn[.]cn Chatgpt005[.]cn Chatgptapp000[.]cn Chatgptapp999[.]cn Chatgpt000[.]cn Chatgpt008[.]cn Chatgpt178[.]cn Chatgpt009[.]cn Chatgpt00Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainchatgpt005.cnsimilar naming pattern: Chatgptproapp[.]com Chatgptios[.]cn Chatgpt005[.]cn Chatgptapp000[.]cn Chatgptapp999[.]cn Chatgpt000[.]cn ChaScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainchatgpt006.cn002[.]cn Chatgpt188[.]cn Chatgptapp888[.]cn Chatgpt138[.]cn Chatgpt006[.]cn All domains are hosted by name servers from dnspod[.]netScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainchatgpt008.cn[.]cn Chatgptapp000[.]cn Chatgptapp999[.]cn Chatgpt000[.]cn Chatgpt008[.]cn Chatgpt178[.]cn Chatgpt009[.]cn Chatgpt0002[.]cn Chatgpt1Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainchatgpt009.cnapp999[.]cn Chatgpt000[.]cn Chatgpt008[.]cn Chatgpt178[.]cn Chatgpt009[.]cn Chatgpt0002[.]cn Chatgpt188[.]cn Chatgptapp888[.]cn ChatgScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainchatgpt138.cn09[.]cn Chatgpt0002[.]cn Chatgpt188[.]cn Chatgptapp888[.]cn Chatgpt138[.]cn Chatgpt006[.]cn All domains are hosted by name servers frScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainchatgpt178.cn000[.]cn Chatgptapp999[.]cn Chatgpt000[.]cn Chatgpt008[.]cn Chatgpt178[.]cn Chatgpt009[.]cn Chatgpt0002[.]cn Chatgpt188[.]cn ChatgptaScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainchatgpt188.cnpt008[.]cn Chatgpt178[.]cn Chatgpt009[.]cn Chatgpt0002[.]cn Chatgpt188[.]cn Chatgptapp888[.]cn Chatgpt138[.]cn Chatgpt006[.]cn All doScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainchatgptapp000.cnattern: Chatgptproapp[.]com Chatgptios[.]cn Chatgpt005[.]cn Chatgptapp000[.]cn Chatgptapp999[.]cn Chatgpt000[.]cn Chatgpt008[.]cn ChatgpScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainchatgptapp888.cnpt178[.]cn Chatgpt009[.]cn Chatgpt0002[.]cn Chatgpt188[.]cn Chatgptapp888[.]cn Chatgpt138[.]cn Chatgpt006[.]cn All domains are hosted byScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainchatgptapp999.cnpp[.]com Chatgptios[.]cn Chatgpt005[.]cn Chatgptapp000[.]cn Chatgptapp999[.]cn Chatgpt000[.]cn Chatgpt008[.]cn Chatgpt178[.]cn Chatgpt00Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainchatgptios.cnt and follows a similar naming pattern: Chatgptproapp[.]com Chatgptios[.]cn Chatgpt005[.]cn Chatgptapp000[.]cn Chatgptapp999[.]cn ChaScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainchatgptproapp.coms the keyword chatgpt and follows a similar naming pattern: Chatgptproapp[.]com Chatgptios[.]cn Chatgpt005[.]cn Chatgptapp000[.]cn ChatgpScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domaindnspod.netChatgpt006[.]cn All domains are hosted by name servers from dnspod[.]net and share the same common IP address in Hong Kong. This cScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domaingemini-addons.comn we have identified involved nine domains: Bardassai[.]com Gemini-addons[.]com Gemini-agents[.]com Gemini-agi[.]com Gemini-super-intelliScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domaingemini-agents.cominvolved nine domains: Bardassai[.]com Gemini-addons[.]com Gemini-agents[.]com Gemini-agi[.]com Gemini-super-intelligence[.]com Gemini-sScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domaingemini-agi.comns: Bardassai[.]com Gemini-addons[.]com Gemini-agents[.]com Gemini-agi[.]com Gemini-super-intelligence[.]com Gemini-superintelligence[Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domaingemini-super-intelligence.comom Gemini-addons[.]com Gemini-agents[.]com Gemini-agi[.]com Gemini-super-intelligence[.]com Gemini-superintelligence[.]com Geminisuperintelligence[.]Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domaingemini-superintelligence.coments[.]com Gemini-agi[.]com Gemini-super-intelligence[.]com Gemini-superintelligence[.]com Geminisuperintelligence[.]com Gpt-vision[.]com My-gpt-cpaScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domaingeminisuperintelligence.comini-super-intelligence[.]com Gemini-superintelligence[.]com Geminisuperintelligence[.]com Gpt-vision[.]com My-gpt-cpa[.]com All these domains leadScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domaingptsotre.comn Nov. 6, 2023, during which numerous related domains, like gptsotre[.]com , were registered. The breaking news about Sora, an upcomScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domaingpt-vision.comemini-superintelligence[.]com Geminisuperintelligence[.]com Gpt-vision[.]com My-gpt-cpa[.]com All these domains lead traffic to monetiScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domaininternationaljobsite.comKetlenpack[.]online Oha-chatbot[.]xyz Janoub-hightech[.]com Internationaljobsite[.]com 33115c[.]com Adversaries used ChatGPT-related URLs to sprScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainjanoub-hightech.coms from this campaign: Ketlenpack[.]online Oha-chatbot[.]xyz Janoub-hightech[.]com Internationaljobsite[.]com 33115c[.]com Adversaries usedScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainketlenpack.onlinee identified the following five domains from this campaign: Ketlenpack[.]online Oha-chatbot[.]xyz Janoub-hightech[.]com InternationaljobsScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainmsftchatgpt.comw domains where many of them contain both trademarks (e.g., msftchatgpt[.]com ). Another significant spike occurred on March 14, 2023,Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainmy-gpt-cpa.comigence[.]com Geminisuperintelligence[.]com Gpt-vision[.]com My-gpt-cpa[.]com All these domains lead traffic to monetization services aScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainoha-chatbot.xyzlowing five domains from this campaign: Ketlenpack[.]online Oha-chatbot[.]xyz Janoub-hightech[.]com Internationaljobsite[.]com 33115c[.Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainsedodna.comd traffic to monetization services at sedoparking[.]com and sedodna[.]com through different types of redirections, including serverScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainsedoparking.comAll these domains lead traffic to monetization services at sedoparking[.]com and sedodna[.]com through different types of redirectionsScam Attacks Taking Advantage of the Popularity of the Generative AI Wave
Palo Alto Unit 42
· Aug 17, 2026
domainbiillpi.comavior patterns. Our detector identified one such C2 domain, biillpi[.]com. Figure 4 shows the DNS request trends for this domain. WAutoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic
Palo Alto Unit 42
· Aug 17, 2026
domaincarollewis.networke malicious DNS traffic detector. One example is the domain carollewis[.]network . Figure 8 shows that DNS traffic for this scam activityAutoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic
Palo Alto Unit 42
· Aug 17, 2026
domaincomcadt.netcaptures traffic toward squatting domains . One example is comcadt[.]net , which is a typosquatting domain mimicking a popular telAutoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic
Palo Alto Unit 42
· Aug 17, 2026
domainnetworkcyclechain.comcious landing pages. An example URL is cqk1rt8hubcc73f3775g.networkcyclechain[.]com/01 , which was a fake antivirus page when we checked it iAutoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic
Palo Alto Unit 42
· Aug 17, 2026
domainpococo.cclimited amount of heartbeat traffic to the malicious domain pococo[.]cc but not in a uniform manner, over the course of one day.Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic
Palo Alto Unit 42
· Aug 17, 2026
domainrobotatten.compresents the DNS requests to a malicious Trojan’s C2 domain robotatten[.]com , hosted by nameservers from the DDNS provider ztomy[.]coAutoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic
Palo Alto Unit 42
· Aug 17, 2026
domainrun.shFigure 3 illustrates the DNS requests trend for the domain run[.]sh from a specific device that presents abnormal time seriesAutoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic
Palo Alto Unit 42
· Aug 17, 2026
domainztomy.comtatten[.]com , hosted by nameservers from the DDNS provider ztomy[.]com . The DDNS service resolves this domain to many IP addresAutoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic
Palo Alto Unit 42
· Aug 17, 2026
domainassignment.ziported as malicious now contain prank content. For instance, assignment[.]zip downloads a ZIP archive that contains a picture of a leekTLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domainattachedpdf.zipn Rick Astley. These 13 domains resemble file names such as attachedpdf[.]zip and testvideo[.]mov . All of them point to the same set oTLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domainbit.lycluster under the TLDs .zip and .mov redirected users to a bit[.]ly link that led to a YouTube music video of a 1987 song titTLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domainbomb.ziped ZIP archive containing an EICAR test file. The second is bomb[.]zip , a site that critiques ICANN's decision to approve the .TLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domainchicken.phpunder the same domain for URLs ending in harriet[.]php and chicken[.]php . Similar to the previous campaign, all 92 domains shareTLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domainchoto.clickhese 112 domains subsequently redirected to URL paths under choto[.]click/vx/<string> that redirected to gambling websites. FigureTLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domainchoto.xyzall 112 domains redirected to different URL paths under the choto[.]xyz domain. Figure 3. Redirection campaign with 112 domains fTLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domaincloudwaysapps.comiet[.]bot redirected to the URL at phpstack-1171166-4096956.cloudwaysapps[.]com/harriet.php Figure 6 illustrates how the picture/avatar dTLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domaineicar-test-file.ziprrently distribute content flagged as malware. The first is eicar-test-file[.]zip that appears to send a randomly named ZIP archive containTLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domaingooglechrome.zipct to pages critiquing the TLD, like latestupdate[.]zip and googlechrome[.]zip . Figure 9 illustrates an example of the critique sites.TLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domainharriet.botroot name string suffixed by .php . For example, the domain harriet[.]bot redirected to the URL at phpstack-1171166-4096956.cloudwaTLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domainharriet.phprent landing pages under the same domain for URLs ending in harriet[.]php and chicken[.]php . Similar to the previous campaign, allTLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domainlatestupdate.zipalicious domains redirect to pages critiquing the TLD, like latestupdate[.]zip and googlechrome[.]zip . Figure 9 illustrates an exampleTLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domainphotos.zips a picture of a leek and one music track (mp3 file), while photos[.]zip simply contains the text: “haha you got phished!” At leasTLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domaintestvideo.mov3 domains resemble file names such as attachedpdf[.]zip and testvideo[.]mov . All of them point to the same set of nameservers denoteTLD Tracker: Exploring Newly Released Top
Palo Alto Unit 42
· Aug 17, 2026
domainac.idnameserver domains and one mail server DNS record: Ns5.uts.ac[.]id Ns6.uts.ac[.]id Mail.uts.ac[.]id We found that these newAutomatically Detecting DNS Hijacking in Passive DNS
Palo Alto Unit 42
· Aug 17, 2026
domainccdc.orgromise DNS hijacking records c-sharp[.]in A 139.59.255[.]10 ccdc.org[.]do A 139.59.255[.]10 dkujpest[.]hu A 135.148.57[.]147 dkuAutomatically Detecting DNS Hijacking in Passive DNS
Palo Alto Unit 42
· Aug 17, 2026
domainccdc.org.do.59.255[.]10 after DNS hijacking. Additionally, we detected ccdc[.]org[.]do , which also resolved to 139.59.255[.]10 on June 28, inAutomatically Detecting DNS Hijacking in Passive DNS
Palo Alto Unit 42
· Aug 17, 2026
domainc-sharp.in9.59.255[.]10 from Singapore for a research center’s domain c-sharp[.]in . This new IP address was suspicious because c-sharp[.]inAutomatically Detecting DNS Hijacking in Passive DNS
Palo Alto Unit 42
· Aug 17, 2026
domaindkujpest.hucal opposition to the Hungarian government, owns the domain dkujpest[.]hu . This domain has been using IP addresses from the 37.9.1Automatically Detecting DNS Hijacking in Passive DNS
Palo Alto Unit 42
· Aug 17, 2026
domaingoogle.co.ukin the history of the registered/root domain portion (e.g., google.co.uk in the case of www.google.co.uk) of the domain name. We conAutomatically Detecting DNS Hijacking in Passive DNS
Palo Alto Unit 42
· Aug 17, 2026
domaingyumolcstarhely.huThe nameservers for the domain for several years were: Ns1.gyumolcstarhely[.]hu Ns2.gyumolcstarhely[.]hu Ns3.gyumolcstarhely[.]hu Ns1.webAutomatically Detecting DNS Hijacking in Passive DNS
Palo Alto Unit 42
· Aug 17, 2026
domainns1.csit-host.comhanged, its nameservers (i.e., NS records) were hijacked to ns1[.]csit-host[.]com and ns2[.]csit-host[.]com . Both of the nameservers resAutomatically Detecting DNS Hijacking in Passive DNS
Palo Alto Unit 42
· Aug 17, 2026
domainns2.csit-host.com.e., NS records) were hijacked to ns1[.]csit-host[.]com and ns2[.]csit-host[.]com . Both of the nameservers resolved to the same hijackedAutomatically Detecting DNS Hijacking in Passive DNS
Palo Alto Unit 42
· Aug 17, 2026
domainorg.doe DNS hijacking records c-sharp[.]in A 139.59.255[.]10 ccdc.org[.]do A 139.59.255[.]10 dkujpest[.]hu A 135.148.57[.]147 dkujpeAutomatically Detecting DNS Hijacking in Passive DNS
Palo Alto Unit 42
· Aug 17, 2026
domainuts.ac.idtential domains to hijack. In a similar case, we found that uts[.]ac[.]id (a university's domain) started resolving to a SingaporAutomatically Detecting DNS Hijacking in Passive DNS
Palo Alto Unit 42
· Aug 17, 2026
domainwebonic.hu[.]hu Ns2.gyumolcstarhely[.]hu Ns3.gyumolcstarhely[.]hu Ns1.webonic[.]hu, ns2.webonic[.]hu Ns3.webonic[.]hu These nameserver domaiAutomatically Detecting DNS Hijacking in Passive DNS
Palo Alto Unit 42
· Aug 17, 2026
domainwebsupport.hutack, the domain operators switched the nameservers to: Ns1.websupport[.]hu Ns1.websupport[.]hu Ns1.websupport[.]hu We hypothesize thAutomatically Detecting DNS Hijacking in Passive DNS
Palo Alto Unit 42
· Aug 17, 2026
domainzone-h.orgked into recent hacking incidents for this IP address using Zone-H[.]org . Figure 7 shows two instances of web page defacement invAutomatically Detecting DNS Hijacking in Passive DNS
Palo Alto Unit 42
· Aug 17, 2026
domain2021olympicupdateslive.comddress 3.64.163[.]50 was shared by domains from 2021 (e.g., 2021olympicupdateslive[.]com ) and those from 2024 (e.g., parisolympicgames2024[.]comNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domain2024olympicslive.com.g., tokyoolympicsport[.]com ) and the 2024 Olympics (e.g., 2024olympicslive[.]com ). From the observed infrastructure patterns, we infer thNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domain2024olympics-shop.comnt. Figure 8 shows two screenshots from the landing page of 2024olympics-shop[.]com that tricked visitors into registering for a bogus investNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domain2024parisolympicathletes.comPersistent Olympic Targeting Threat 2024olympicslive[.]com 2024parisolympicathletes[.]com olympicparis2024[.]com paris-olympics2024[.]com paris24olNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainallolympic.comclimbolympic[.]com . Figure 10. Gambling website hosted on allolympic[.]com . Figure 11. Gambling website hosted on olympiarealestateNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainclimbolympic.comwithin this campaign. Figure 9. Gambling website hosted on climbolympic[.]com . Figure 10. Gambling website hosted on allolympic[.]comNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainolympiarealestate-online.comon allolympic[.]com . Figure 11. Gambling website hosted on olympiarealestate-online[.]com . Indicators of Compromise Suspicious Domains From PersisNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainolympicparis2024.comhreat 2024olympicslive[.]com 2024parisolympicathletes[.]com olympicparis2024[.]com paris-olympics2024[.]com paris24olympics[.]com parisolympNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainolympics.apke site also offers a download link for an Android app named Olympics[.]apk that poses as a legitimate cash app, but it is actually sNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainparis24olympics.comletes[.]com olympicparis2024[.]com paris-olympics2024[.]com paris24olympics[.]com parisolympic24[.]com parisolympicgames2024[.]com parisolyNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainparisolympic24.comis2024[.]com paris-olympics2024[.]com paris24olympics[.]com parisolympic24[.]com parisolympicgames2024[.]com parisolympicgames2024officialNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainparisolympicgames2024.com, 2021olympicupdateslive[.]com ) and those from 2024 (e.g., parisolympicgames2024[.]com ). In addition, multiple domains from both Olympic eventsNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainparisolympicgames2024official.compics[.]com parisolympic24[.]com parisolympicgames2024[.]com parisolympicgames2024official[.]com parisolympicgamesevents[.]com parisolympicgamesofficial[.Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainparisolympicgamesevents.comsolympicgames2024[.]com parisolympicgames2024official[.]com parisolympicgamesevents[.]com parisolympicgamesofficial[.]com parisolympicgamestickets[Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainparisolympicgamesofficial.comlympicgames2024official[.]com parisolympicgamesevents[.]com parisolympicgamesofficial[.]com parisolympicgamestickets[.]com parisolympicsphotographe[.Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainparisolympicgamestickets.comrisolympicgamesevents[.]com parisolympicgamesofficial[.]com parisolympicgamestickets[.]com parisolympicsphotographe[.]com parisolympictickets[.]comNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainparis-olympics2024.com.]com 2024parisolympicathletes[.]com olympicparis2024[.]com paris-olympics2024[.]com paris24olympics[.]com parisolympic24[.]com parisolympicgaNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainparisolympicsphotographe.comisolympicgamesofficial[.]com parisolympicgamestickets[.]com parisolympicsphotographe[.]com parisolympictickets[.]com Scam Domains Leveraging OlympicNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domainparisolympictickets.comrisolympicgamestickets[.]com parisolympicsphotographe[.]com parisolympictickets[.]com Scam Domains Leveraging Olympics 2024olympics-shop[.]comNetwork Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domaintokyoolympicsport.com. This included domains targeting previous Olympics (e.g., tokyoolympicsport[.]com ) and the 2024 Olympics (e.g., 2024olympicslive[.]com ).Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Palo Alto Unit 42
· Aug 17, 2026
domain3adating.comdating-related keywords to create phishing domains such as 3adating[.]com and meetyoursoulmate[.]life . Figure 11. Example of an adBeneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems
Palo Alto Unit 42
· Aug 17, 2026
domain7eh3gj.lolregistration. For example, xd2kdw[.]lol , ba3e7q[.]lol and 7eh3gj[.]lol were created on August 22, 2024, and began carrying malicBeneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems
Palo Alto Unit 42
· Aug 17, 2026
domainba3e7q.lolshortly after the registration. For example, xd2kdw[.]lol , ba3e7q[.]lol and 7eh3gj[.]lol were created on August 22, 2024, and begBeneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems
Palo Alto Unit 42
· Aug 17, 2026
domaindappadar.biomains including dapparadar[.]app , dappadar[.]community and dappadar[.]bio . Figure 4. Redirection networks of phishing TDS. These sBeneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems
Palo Alto Unit 42
· Aug 17, 2026
domaindappadar.communityontains many squatting domains including dapparadar[.]app , dappadar[.]community and dappadar[.]bio . Figure 4. Redirection networks of phBeneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems
Palo Alto Unit 42
· Aug 17, 2026
domaindapparadar.appTDS structure. It contains many squatting domains including dapparadar[.]app , dappadar[.]community and dappadar[.]bio . Figure 4. RedBeneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems
Palo Alto Unit 42
· Aug 17, 2026
domainmeetyoursoulmate.lifewords to create phishing domains such as 3adating[.]com and meetyoursoulmate[.]life . Figure 11. Example of an adult-themed phishing site asBeneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems
Palo Alto Unit 42
· Aug 17, 2026
domainmobesti.como legitimate websites. We identified a recent example using mobesti[.]com for a phishing campaign. Figure 10 shows how this campaigBeneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems
Palo Alto Unit 42
· Aug 17, 2026
domainvkmarketing2.come same entry website are redirected to different URLs under vkmarketing2[.]com , then to various shady landing pages. Figure 6. RedirectBeneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems
Palo Alto Unit 42
· Aug 17, 2026
domainxd2kdw.lolto the service shortly after the registration. For example, xd2kdw[.]lol , ba3e7q[.]lol and 7eh3gj[.]lol were created on August 22Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems
Palo Alto Unit 42
· Aug 17, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.