← back to Domain Sniper
honeypot 2026-05-12 recheck @+168h: confirmed nic.co .co WHOIS leak; Dynadot→aggressive
65a6a8feadf21ab1bfad46c31d425fbc90dd8cbe · 2026-05-19 15:08:00 -0700 · Steve Abrams
dusab.co (bucket C, nic.co WHOIS for .co) was sniped by Dynadot Inc
between +4h and +168h. CONTROL bucket stayed at 0/10 — the snipe is
causally linked to the nic.co query channel, not random.
Snipe used Cloudflare NS (donna.ns.cloudflare.com) rather than Dynadot's
own NS — parker/aggregator shop fronting inventory through CF DNS.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Files touched
M registrar-fingerprints.json
Diff
commit 65a6a8feadf21ab1bfad46c31d425fbc90dd8cbe
Author: Steve Abrams <steve@designerwallcoverings.com>
Date: Tue May 19 15:08:00 2026 -0700
honeypot 2026-05-12 recheck @+168h: confirmed nic.co .co WHOIS leak; Dynadot→aggressive
dusab.co (bucket C, nic.co WHOIS for .co) was sniped by Dynadot Inc
between +4h and +168h. CONTROL bucket stayed at 0/10 — the snipe is
causally linked to the nic.co query channel, not random.
Snipe used Cloudflare NS (donna.ns.cloudflare.com) rather than Dynadot's
own NS — parker/aggregator shop fronting inventory through CF DNS.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---
registrar-fingerprints.json | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/registrar-fingerprints.json b/registrar-fingerprints.json
index 5e5e76e..611b976 100644
--- a/registrar-fingerprints.json
+++ b/registrar-fingerprints.json
@@ -1,6 +1,6 @@
{
"_about": "Public-registrar fingerprint database used by honeypot.js check phase to cross-reference WHOIS evidence against known drop-catch / aggregator operators. 'aggressive' flags operators with documented snipe / drop-catch infrastructure. Not exhaustive; expand as new actors surface.",
- "_updated": "2026-05-12 (19 operators, 12 aggressive)",
+ "_updated": "2026-05-19 (Dynadot promoted to aggressive after dusab.co snipe; nic.co .co WHOIS confirmed as leak channel)",
"_schema": {
"ianaId": "registrar IANA ID (from WHOIS 'Registrar IANA ID' field)",
"name": "canonical registrar name",
@@ -61,10 +61,10 @@
},
"472": {
"name": "Dynadot",
- "nsPatterns": ["^ns\\d+\\.dynadot\\.com$"],
+ "nsPatterns": ["^ns\\d+\\.dynadot\\.com$", "^[a-z]+\\.ns\\.cloudflare\\.com$"],
"country": "US",
- "aggressive": false,
- "notes": "Mostly retail. Occasional drop-catch activity. Not a primary aggregator."
+ "aggressive": true,
+ "notes": "Promoted to aggressive 2026-05-19 after dusab.co snipe from honeypot batch 2026-05-12. The snipe came in via bucket C (nic.co WHOIS for .co) — only that bucket fired, CONTROL bucket was 0/10, so nic.co's WHOIS is confirmed leaking to a Dynadot-using aggregator. Snipe used Cloudflare NS (donna.ns.cloudflare.com) rather than Dynadot's own NS, which is the tell of a parker/aggregator shop. abuse@dynadot.com."
},
"1479": {
"name": "NameSilo",
← 9b74164 snapshot — gitify backup 2026-05-19
·
back to Domain Sniper
·
gitignore: exclude *.bak backup files e89f9d5 →