[object Object]

← back to Domain Sniper

honeypot 2026-05-12 recheck @+168h: confirmed nic.co .co WHOIS leak; Dynadot→aggressive

65a6a8feadf21ab1bfad46c31d425fbc90dd8cbe · 2026-05-19 15:08:00 -0700 · Steve Abrams

dusab.co (bucket C, nic.co WHOIS for .co) was sniped by Dynadot Inc
between +4h and +168h. CONTROL bucket stayed at 0/10 — the snipe is
causally linked to the nic.co query channel, not random.

Snipe used Cloudflare NS (donna.ns.cloudflare.com) rather than Dynadot's
own NS — parker/aggregator shop fronting inventory through CF DNS.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

Files touched

Diff

commit 65a6a8feadf21ab1bfad46c31d425fbc90dd8cbe
Author: Steve Abrams <steve@designerwallcoverings.com>
Date:   Tue May 19 15:08:00 2026 -0700

    honeypot 2026-05-12 recheck @+168h: confirmed nic.co .co WHOIS leak; Dynadot→aggressive
    
    dusab.co (bucket C, nic.co WHOIS for .co) was sniped by Dynadot Inc
    between +4h and +168h. CONTROL bucket stayed at 0/10 — the snipe is
    causally linked to the nic.co query channel, not random.
    
    Snipe used Cloudflare NS (donna.ns.cloudflare.com) rather than Dynadot's
    own NS — parker/aggregator shop fronting inventory through CF DNS.
    
    Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---
 registrar-fingerprints.json | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/registrar-fingerprints.json b/registrar-fingerprints.json
index 5e5e76e..611b976 100644
--- a/registrar-fingerprints.json
+++ b/registrar-fingerprints.json
@@ -1,6 +1,6 @@
 {
   "_about": "Public-registrar fingerprint database used by honeypot.js check phase to cross-reference WHOIS evidence against known drop-catch / aggregator operators. 'aggressive' flags operators with documented snipe / drop-catch infrastructure. Not exhaustive; expand as new actors surface.",
-  "_updated": "2026-05-12 (19 operators, 12 aggressive)",
+  "_updated": "2026-05-19 (Dynadot promoted to aggressive after dusab.co snipe; nic.co .co WHOIS confirmed as leak channel)",
   "_schema": {
     "ianaId": "registrar IANA ID (from WHOIS 'Registrar IANA ID' field)",
     "name": "canonical registrar name",
@@ -61,10 +61,10 @@
     },
     "472": {
       "name": "Dynadot",
-      "nsPatterns": ["^ns\\d+\\.dynadot\\.com$"],
+      "nsPatterns": ["^ns\\d+\\.dynadot\\.com$", "^[a-z]+\\.ns\\.cloudflare\\.com$"],
       "country": "US",
-      "aggressive": false,
-      "notes": "Mostly retail. Occasional drop-catch activity. Not a primary aggregator."
+      "aggressive": true,
+      "notes": "Promoted to aggressive 2026-05-19 after dusab.co snipe from honeypot batch 2026-05-12. The snipe came in via bucket C (nic.co WHOIS for .co) — only that bucket fired, CONTROL bucket was 0/10, so nic.co's WHOIS is confirmed leaking to a Dynadot-using aggregator. Snipe used Cloudflare NS (donna.ns.cloudflare.com) rather than Dynadot's own NS, which is the tell of a parker/aggregator shop. abuse@dynadot.com."
     },
     "1479": {
       "name": "NameSilo",

← 9b74164 snapshot — gitify backup 2026-05-19  ·  back to Domain Sniper  ·  gitignore: exclude *.bak backup files e89f9d5 →