Indicators of compromise
1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | 33115c.com | tbot[.]xyz Janoub-hightech[.]com Internationaljobsite[.]com 33115c[.]com Adversaries used ChatGPT-related URLs to spread spam mess | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bardassai.com | parking campaign we have identified involved nine domains: Bardassai[.]com Gemini-addons[.]com Gemini-agents[.]com Gemini-agi[.]com | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chatgpt0002.cn | gpt000[.]cn Chatgpt008[.]cn Chatgpt178[.]cn Chatgpt009[.]cn Chatgpt0002[.]cn Chatgpt188[.]cn Chatgptapp888[.]cn Chatgpt138[.]cn Chatgp | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chatgpt000.cn | [.]cn Chatgpt005[.]cn Chatgptapp000[.]cn Chatgptapp999[.]cn Chatgpt000[.]cn Chatgpt008[.]cn Chatgpt178[.]cn Chatgpt009[.]cn Chatgpt00 | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chatgpt005.cn | similar naming pattern: Chatgptproapp[.]com Chatgptios[.]cn Chatgpt005[.]cn Chatgptapp000[.]cn Chatgptapp999[.]cn Chatgpt000[.]cn Cha | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chatgpt006.cn | 002[.]cn Chatgpt188[.]cn Chatgptapp888[.]cn Chatgpt138[.]cn Chatgpt006[.]cn All domains are hosted by name servers from dnspod[.]net | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chatgpt008.cn | [.]cn Chatgptapp000[.]cn Chatgptapp999[.]cn Chatgpt000[.]cn Chatgpt008[.]cn Chatgpt178[.]cn Chatgpt009[.]cn Chatgpt0002[.]cn Chatgpt1 | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chatgpt009.cn | app999[.]cn Chatgpt000[.]cn Chatgpt008[.]cn Chatgpt178[.]cn Chatgpt009[.]cn Chatgpt0002[.]cn Chatgpt188[.]cn Chatgptapp888[.]cn Chatg | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chatgpt138.cn | 09[.]cn Chatgpt0002[.]cn Chatgpt188[.]cn Chatgptapp888[.]cn Chatgpt138[.]cn Chatgpt006[.]cn All domains are hosted by name servers fr | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chatgpt178.cn | 000[.]cn Chatgptapp999[.]cn Chatgpt000[.]cn Chatgpt008[.]cn Chatgpt178[.]cn Chatgpt009[.]cn Chatgpt0002[.]cn Chatgpt188[.]cn Chatgpta | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chatgpt188.cn | pt008[.]cn Chatgpt178[.]cn Chatgpt009[.]cn Chatgpt0002[.]cn Chatgpt188[.]cn Chatgptapp888[.]cn Chatgpt138[.]cn Chatgpt006[.]cn All do | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chatgptapp000.cn | attern: Chatgptproapp[.]com Chatgptios[.]cn Chatgpt005[.]cn Chatgptapp000[.]cn Chatgptapp999[.]cn Chatgpt000[.]cn Chatgpt008[.]cn Chatgp | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chatgptapp888.cn | pt178[.]cn Chatgpt009[.]cn Chatgpt0002[.]cn Chatgpt188[.]cn Chatgptapp888[.]cn Chatgpt138[.]cn Chatgpt006[.]cn All domains are hosted by | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chatgptapp999.cn | pp[.]com Chatgptios[.]cn Chatgpt005[.]cn Chatgptapp000[.]cn Chatgptapp999[.]cn Chatgpt000[.]cn Chatgpt008[.]cn Chatgpt178[.]cn Chatgpt00 | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chatgptios.cn | t and follows a similar naming pattern: Chatgptproapp[.]com Chatgptios[.]cn Chatgpt005[.]cn Chatgptapp000[.]cn Chatgptapp999[.]cn Cha | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chatgptproapp.com | s the keyword chatgpt and follows a similar naming pattern: Chatgptproapp[.]com Chatgptios[.]cn Chatgpt005[.]cn Chatgptapp000[.]cn Chatgp | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | dnspod.net | Chatgpt006[.]cn All domains are hosted by name servers from dnspod[.]net and share the same common IP address in Hong Kong. This c | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gemini-addons.com | n we have identified involved nine domains: Bardassai[.]com Gemini-addons[.]com Gemini-agents[.]com Gemini-agi[.]com Gemini-super-intelli | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gemini-agents.com | involved nine domains: Bardassai[.]com Gemini-addons[.]com Gemini-agents[.]com Gemini-agi[.]com Gemini-super-intelligence[.]com Gemini-s | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gemini-agi.com | ns: Bardassai[.]com Gemini-addons[.]com Gemini-agents[.]com Gemini-agi[.]com Gemini-super-intelligence[.]com Gemini-superintelligence[ | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gemini-super-intelligence.com | om Gemini-addons[.]com Gemini-agents[.]com Gemini-agi[.]com Gemini-super-intelligence[.]com Gemini-superintelligence[.]com Geminisuperintelligence[.] | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gemini-superintelligence.com | ents[.]com Gemini-agi[.]com Gemini-super-intelligence[.]com Gemini-superintelligence[.]com Geminisuperintelligence[.]com Gpt-vision[.]com My-gpt-cpa | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | geminisuperintelligence.com | ini-super-intelligence[.]com Gemini-superintelligence[.]com Geminisuperintelligence[.]com Gpt-vision[.]com My-gpt-cpa[.]com All these domains lead | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gptsotre.com | n Nov. 6, 2023, during which numerous related domains, like gptsotre[.]com , were registered. The breaking news about Sora, an upcom | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gpt-vision.com | emini-superintelligence[.]com Geminisuperintelligence[.]com Gpt-vision[.]com My-gpt-cpa[.]com All these domains lead traffic to moneti | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | internationaljobsite.com | Ketlenpack[.]online Oha-chatbot[.]xyz Janoub-hightech[.]com Internationaljobsite[.]com 33115c[.]com Adversaries used ChatGPT-related URLs to spr | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | janoub-hightech.com | s from this campaign: Ketlenpack[.]online Oha-chatbot[.]xyz Janoub-hightech[.]com Internationaljobsite[.]com 33115c[.]com Adversaries used | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ketlenpack.online | e identified the following five domains from this campaign: Ketlenpack[.]online Oha-chatbot[.]xyz Janoub-hightech[.]com Internationaljobs | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | msftchatgpt.com | w domains where many of them contain both trademarks (e.g., msftchatgpt[.]com ). Another significant spike occurred on March 14, 2023, | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | my-gpt-cpa.com | igence[.]com Geminisuperintelligence[.]com Gpt-vision[.]com My-gpt-cpa[.]com All these domains lead traffic to monetization services a | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | oha-chatbot.xyz | lowing five domains from this campaign: Ketlenpack[.]online Oha-chatbot[.]xyz Janoub-hightech[.]com Internationaljobsite[.]com 33115c[. | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | sedodna.com | d traffic to monetization services at sedoparking[.]com and sedodna[.]com through different types of redirections, including server | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | sedoparking.com | All these domains lead traffic to monetization services at sedoparking[.]com and sedodna[.]com through different types of redirections | Scam Attacks Taking Advantage of the Popularity of the Generative AI Wave Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | biillpi.com | avior patterns. Our detector identified one such C2 domain, biillpi[.]com. Figure 4 shows the DNS request trends for this domain. W | Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | carollewis.network | e malicious DNS traffic detector. One example is the domain carollewis[.]network . Figure 8 shows that DNS traffic for this scam activity | Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | comcadt.net | captures traffic toward squatting domains . One example is comcadt[.]net , which is a typosquatting domain mimicking a popular tel | Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | networkcyclechain.com | cious landing pages. An example URL is cqk1rt8hubcc73f3775g.networkcyclechain[.]com/01 , which was a fake antivirus page when we checked it i | Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pococo.cc | limited amount of heartbeat traffic to the malicious domain pococo[.]cc but not in a uniform manner, over the course of one day. | Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | robotatten.com | presents the DNS requests to a malicious Trojan’s C2 domain robotatten[.]com , hosted by nameservers from the DDNS provider ztomy[.]co | Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | run.sh | Figure 3 illustrates the DNS requests trend for the domain run[.]sh from a specific device that presents abnormal time series | Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ztomy.com | tatten[.]com , hosted by nameservers from the DDNS provider ztomy[.]com . The DDNS service resolves this domain to many IP addres | Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | assignment.zip | orted as malicious now contain prank content. For instance, assignment[.]zip downloads a ZIP archive that contains a picture of a leek | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | attachedpdf.zip | n Rick Astley. These 13 domains resemble file names such as attachedpdf[.]zip and testvideo[.]mov . All of them point to the same set o | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bit.ly | cluster under the TLDs .zip and .mov redirected users to a bit[.]ly link that led to a YouTube music video of a 1987 song tit | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bomb.zip | ed ZIP archive containing an EICAR test file. The second is bomb[.]zip , a site that critiques ICANN's decision to approve the . | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | chicken.php | under the same domain for URLs ending in harriet[.]php and chicken[.]php . Similar to the previous campaign, all 92 domains share | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | choto.click | hese 112 domains subsequently redirected to URL paths under choto[.]click/vx/<string> that redirected to gambling websites. Figure | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | choto.xyz | all 112 domains redirected to different URL paths under the choto[.]xyz domain. Figure 3. Redirection campaign with 112 domains f | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | cloudwaysapps.com | iet[.]bot redirected to the URL at phpstack-1171166-4096956.cloudwaysapps[.]com/harriet.php Figure 6 illustrates how the picture/avatar d | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | eicar-test-file.zip | rrently distribute content flagged as malware. The first is eicar-test-file[.]zip that appears to send a randomly named ZIP archive contain | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | googlechrome.zip | ct to pages critiquing the TLD, like latestupdate[.]zip and googlechrome[.]zip . Figure 9 illustrates an example of the critique sites. | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | harriet.bot | root name string suffixed by .php . For example, the domain harriet[.]bot redirected to the URL at phpstack-1171166-4096956.cloudwa | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | harriet.php | rent landing pages under the same domain for URLs ending in harriet[.]php and chicken[.]php . Similar to the previous campaign, all | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | latestupdate.zip | alicious domains redirect to pages critiquing the TLD, like latestupdate[.]zip and googlechrome[.]zip . Figure 9 illustrates an example | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | photos.zip | s a picture of a leek and one music track (mp3 file), while photos[.]zip simply contains the text: “haha you got phished!” At leas | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | testvideo.mov | 3 domains resemble file names such as attachedpdf[.]zip and testvideo[.]mov . All of them point to the same set of nameservers denote | TLD Tracker: Exploring Newly Released Top Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ac.id | nameserver domains and one mail server DNS record: Ns5.uts.ac[.]id Ns6.uts.ac[.]id Mail.uts.ac[.]id We found that these new | Automatically Detecting DNS Hijacking in Passive DNS Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ccdc.org | romise DNS hijacking records c-sharp[.]in A 139.59.255[.]10 ccdc.org[.]do A 139.59.255[.]10 dkujpest[.]hu A 135.148.57[.]147 dku | Automatically Detecting DNS Hijacking in Passive DNS Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ccdc.org.do | .59.255[.]10 after DNS hijacking. Additionally, we detected ccdc[.]org[.]do , which also resolved to 139.59.255[.]10 on June 28, in | Automatically Detecting DNS Hijacking in Passive DNS Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | c-sharp.in | 9.59.255[.]10 from Singapore for a research center’s domain c-sharp[.]in . This new IP address was suspicious because c-sharp[.]in | Automatically Detecting DNS Hijacking in Passive DNS Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | dkujpest.hu | cal opposition to the Hungarian government, owns the domain dkujpest[.]hu . This domain has been using IP addresses from the 37.9.1 | Automatically Detecting DNS Hijacking in Passive DNS Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | google.co.uk | in the history of the registered/root domain portion (e.g., google.co.uk in the case of www.google.co.uk) of the domain name. We con | Automatically Detecting DNS Hijacking in Passive DNS Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gyumolcstarhely.hu | The nameservers for the domain for several years were: Ns1.gyumolcstarhely[.]hu Ns2.gyumolcstarhely[.]hu Ns3.gyumolcstarhely[.]hu Ns1.web | Automatically Detecting DNS Hijacking in Passive DNS Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ns1.csit-host.com | hanged, its nameservers (i.e., NS records) were hijacked to ns1[.]csit-host[.]com and ns2[.]csit-host[.]com . Both of the nameservers res | Automatically Detecting DNS Hijacking in Passive DNS Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ns2.csit-host.com | .e., NS records) were hijacked to ns1[.]csit-host[.]com and ns2[.]csit-host[.]com . Both of the nameservers resolved to the same hijacked | Automatically Detecting DNS Hijacking in Passive DNS Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | org.do | e DNS hijacking records c-sharp[.]in A 139.59.255[.]10 ccdc.org[.]do A 139.59.255[.]10 dkujpest[.]hu A 135.148.57[.]147 dkujpe | Automatically Detecting DNS Hijacking in Passive DNS Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | uts.ac.id | tential domains to hijack. In a similar case, we found that uts[.]ac[.]id (a university's domain) started resolving to a Singapor | Automatically Detecting DNS Hijacking in Passive DNS Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | webonic.hu | [.]hu Ns2.gyumolcstarhely[.]hu Ns3.gyumolcstarhely[.]hu Ns1.webonic[.]hu, ns2.webonic[.]hu Ns3.webonic[.]hu These nameserver domai | Automatically Detecting DNS Hijacking in Passive DNS Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | websupport.hu | tack, the domain operators switched the nameservers to: Ns1.websupport[.]hu Ns1.websupport[.]hu Ns1.websupport[.]hu We hypothesize th | Automatically Detecting DNS Hijacking in Passive DNS Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | zone-h.org | ked into recent hacking incidents for this IP address using Zone-H[.]org . Figure 7 shows two instances of web page defacement inv | Automatically Detecting DNS Hijacking in Passive DNS Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 2021olympicupdateslive.com | ddress 3.64.163[.]50 was shared by domains from 2021 (e.g., 2021olympicupdateslive[.]com ) and those from 2024 (e.g., parisolympicgames2024[.]com | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 2024olympicslive.com | .g., tokyoolympicsport[.]com ) and the 2024 Olympics (e.g., 2024olympicslive[.]com ). From the observed infrastructure patterns, we infer th | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 2024olympics-shop.com | nt. Figure 8 shows two screenshots from the landing page of 2024olympics-shop[.]com that tricked visitors into registering for a bogus invest | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 2024parisolympicathletes.com | Persistent Olympic Targeting Threat 2024olympicslive[.]com 2024parisolympicathletes[.]com olympicparis2024[.]com paris-olympics2024[.]com paris24ol | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | allolympic.com | climbolympic[.]com . Figure 10. Gambling website hosted on allolympic[.]com . Figure 11. Gambling website hosted on olympiarealestate | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | climbolympic.com | within this campaign. Figure 9. Gambling website hosted on climbolympic[.]com . Figure 10. Gambling website hosted on allolympic[.]com | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | olympiarealestate-online.com | on allolympic[.]com . Figure 11. Gambling website hosted on olympiarealestate-online[.]com . Indicators of Compromise Suspicious Domains From Persis | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | olympicparis2024.com | hreat 2024olympicslive[.]com 2024parisolympicathletes[.]com olympicparis2024[.]com paris-olympics2024[.]com paris24olympics[.]com parisolymp | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | olympics.apk | e site also offers a download link for an Android app named Olympics[.]apk that poses as a legitimate cash app, but it is actually s | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | paris24olympics.com | letes[.]com olympicparis2024[.]com paris-olympics2024[.]com paris24olympics[.]com parisolympic24[.]com parisolympicgames2024[.]com parisoly | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | parisolympic24.com | is2024[.]com paris-olympics2024[.]com paris24olympics[.]com parisolympic24[.]com parisolympicgames2024[.]com parisolympicgames2024official | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | parisolympicgames2024.com | , 2021olympicupdateslive[.]com ) and those from 2024 (e.g., parisolympicgames2024[.]com ). In addition, multiple domains from both Olympic events | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | parisolympicgames2024official.com | pics[.]com parisolympic24[.]com parisolympicgames2024[.]com parisolympicgames2024official[.]com parisolympicgamesevents[.]com parisolympicgamesofficial[. | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | parisolympicgamesevents.com | solympicgames2024[.]com parisolympicgames2024official[.]com parisolympicgamesevents[.]com parisolympicgamesofficial[.]com parisolympicgamestickets[ | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | parisolympicgamesofficial.com | lympicgames2024official[.]com parisolympicgamesevents[.]com parisolympicgamesofficial[.]com parisolympicgamestickets[.]com parisolympicsphotographe[. | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | parisolympicgamestickets.com | risolympicgamesevents[.]com parisolympicgamesofficial[.]com parisolympicgamestickets[.]com parisolympicsphotographe[.]com parisolympictickets[.]com | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | paris-olympics2024.com | .]com 2024parisolympicathletes[.]com olympicparis2024[.]com paris-olympics2024[.]com paris24olympics[.]com parisolympic24[.]com parisolympicga | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | parisolympicsphotographe.com | isolympicgamesofficial[.]com parisolympicgamestickets[.]com parisolympicsphotographe[.]com parisolympictickets[.]com Scam Domains Leveraging Olympic | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | parisolympictickets.com | risolympicgamestickets[.]com parisolympicsphotographe[.]com parisolympictickets[.]com Scam Domains Leveraging Olympics 2024olympics-shop[.]com | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | tokyoolympicsport.com | . This included domains targeting previous Olympics (e.g., tokyoolympicsport[.]com ) and the 2024 Olympics (e.g., 2024olympicslive[.]com ). | Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 3adating.com | dating-related keywords to create phishing domains such as 3adating[.]com and meetyoursoulmate[.]life . Figure 11. Example of an ad | Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 7eh3gj.lol | registration. For example, xd2kdw[.]lol , ba3e7q[.]lol and 7eh3gj[.]lol were created on August 22, 2024, and began carrying malic | Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ba3e7q.lol | shortly after the registration. For example, xd2kdw[.]lol , ba3e7q[.]lol and 7eh3gj[.]lol were created on August 22, 2024, and beg | Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | dappadar.bio | mains including dapparadar[.]app , dappadar[.]community and dappadar[.]bio . Figure 4. Redirection networks of phishing TDS. These s | Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | dappadar.community | ontains many squatting domains including dapparadar[.]app , dappadar[.]community and dappadar[.]bio . Figure 4. Redirection networks of ph | Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | dapparadar.app | TDS structure. It contains many squatting domains including dapparadar[.]app , dappadar[.]community and dappadar[.]bio . Figure 4. Red | Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | meetyoursoulmate.life | words to create phishing domains such as 3adating[.]com and meetyoursoulmate[.]life . Figure 11. Example of an adult-themed phishing site as | Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | mobesti.com | o legitimate websites. We identified a recent example using mobesti[.]com for a phishing campaign. Figure 10 shows how this campaig | Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | vkmarketing2.com | e same entry website are redirected to different URLs under vkmarketing2[.]com , then to various shady landing pages. Figure 6. Redirect | Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | xd2kdw.lol | to the service shortly after the registration. For example, xd2kdw[.]lol , ba3e7q[.]lol and 7eh3gj[.]lol were created on August 22 | Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems Palo Alto Unit 42 | · Aug 17, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.