← back to Domain Sniper

registrar-fingerprints.json

148 lines

{
  "_about": "Public-registrar fingerprint database used by honeypot.js check phase to cross-reference WHOIS evidence against known drop-catch / aggregator operators. 'aggressive' flags operators with documented snipe / drop-catch infrastructure. Not exhaustive; expand as new actors surface.",
  "_updated": "2026-05-19 (Dynadot promoted to aggressive after dusab.co snipe; nic.co .co WHOIS confirmed as leak channel)",
  "_schema": {
    "ianaId": "registrar IANA ID (from WHOIS 'Registrar IANA ID' field)",
    "name": "canonical registrar name",
    "nsPatterns": "regex patterns matched against authoritative NS root domains",
    "country": "registrar country (ISO 3166)",
    "aggressive": "true if known to operate drop-catch / aggregator infrastructure",
    "notes": "freeform"
  },
  "operators": {
    "433": {
      "name": "OVH SAS",
      "nsPatterns": ["^ns\\d+\\.ovh\\.net$", "^dns\\d+\\.ovh\\.net$"],
      "country": "FR",
      "aggressive": true,
      "notes": "Confirmed snipe on butlr.app 2026-05-12 with ns112.ovh.net/dns112.ovh.net. Common destination for European drop-catchers. Cheap registrations make sniping economic."
    },
    "1606": {
      "name": "NameBright / DropCatch",
      "nsPatterns": ["^ns\\d+\\.namebrightdns\\.com$", "^ns\\d+\\.aftermarket\\.com$"],
      "country": "US",
      "aggressive": true,
      "notes": "DropCatch.com is one of the three major drop-catch services. Owns hundreds of credentialed connections to TLD registries to race-grab pending-delete domains."
    },
    "1330": {
      "name": "Pool.com / TurnCommerce",
      "nsPatterns": ["^ns\\d+\\.poolregistry\\.com$", "^ns\\d+\\.parkingcrew\\.net$"],
      "country": "US",
      "aggressive": true,
      "notes": "Pool.com is the second of the big-three drop-catchers. Long-tail dictionary-based filtering, immediate auction listing."
    },
    "64": {
      "name": "Web.com / NameJet / SnapNames",
      "nsPatterns": ["^ns\\d+\\.snapnames\\.com$", "^ns\\d+\\.namejet\\.com$", "^ns\\d+\\.web\\.com$"],
      "country": "US",
      "aggressive": true,
      "notes": "Third major drop-catcher. NameJet auctions, SnapNames retail. Aggressive on premium .com / .net."
    },
    "609": {
      "name": "Sav.com",
      "nsPatterns": ["^ns\\d+\\.sav\\.com$"],
      "country": "US",
      "aggressive": true,
      "notes": "Newer entrant, aggressive on short-form .com and short-LL.io / .ai snipes. Public auctions follow."
    },
    "1170": {
      "name": "Above.com / Trellian",
      "nsPatterns": ["^ns\\d+\\.above\\.com$", "^ns\\d+\\.trellian\\.com$"],
      "country": "AU",
      "aggressive": true,
      "notes": "Long-tail drop-catch + parking + PPC monetization. Common destination for sniped names that get parked rather than auctioned."
    },
    "146": {
      "name": "GoDaddy / GoDaddy Auctions",
      "nsPatterns": ["^ns\\d+\\.domaincontrol\\.com$"],
      "country": "US",
      "aggressive": true,
      "notes": "GoDaddy operates its own auction marketplace and TDNAM (after-market). Snipes through GoDaddy Auctions land at domaincontrol.com NS."
    },
    "472": {
      "name": "Dynadot",
      "nsPatterns": ["^ns\\d+\\.dynadot\\.com$", "^[a-z]+\\.ns\\.cloudflare\\.com$"],
      "country": "US",
      "aggressive": true,
      "notes": "Promoted to aggressive 2026-05-19 after dusab.co snipe from honeypot batch 2026-05-12. The snipe came in via bucket C (nic.co WHOIS for .co) — only that bucket fired, CONTROL bucket was 0/10, so nic.co's WHOIS is confirmed leaking to a Dynadot-using aggregator. Snipe used Cloudflare NS (donna.ns.cloudflare.com) rather than Dynadot's own NS, which is the tell of a parker/aggregator shop. abuse@dynadot.com."
    },
    "1479": {
      "name": "NameSilo",
      "nsPatterns": ["^ns\\d+\\.namesilo\\.com$", "^ns\\d+\\.dnsowl\\.com$"],
      "country": "US",
      "aggressive": false,
      "notes": "Retail registrar. Cheap renewals. Not a known aggregator."
    },
    "1861": {
      "name": "Porkbun",
      "nsPatterns": ["^curitiba\\.ns\\.porkbun\\.com$", "^salvador\\.ns\\.porkbun\\.com$", "^maceio\\.ns\\.porkbun\\.com$", "^fortaleza\\.ns\\.porkbun\\.com$", "^ns\\d*\\.porkbun\\.com$"],
      "country": "US",
      "aggressive": false,
      "notes": "Retail-friendly registrar. Not an aggregator."
    },
    "1068": {
      "name": "Namecheap",
      "nsPatterns": ["^dns\\d+\\.registrar-servers\\.com$"],
      "country": "US",
      "aggressive": false,
      "notes": "Retail registrar. Not a primary aggregator but resold to many."
    },
    "1910": {
      "name": "Cloudflare Registrar",
      "nsPatterns": ["^[a-z]+\\.ns\\.cloudflare\\.com$"],
      "country": "US",
      "aggressive": false,
      "notes": "Wholesale-pricing retail registrar. No aftermarket activity."
    },
    "69": {
      "name": "Tucows / OpenSRS / Hover",
      "nsPatterns": ["^ns\\d+\\.tucows\\.com$", "^ns\\d+\\.hover\\.com$", "^ns\\d+\\.domainpeople\\.com$"],
      "country": "CA",
      "aggressive": false,
      "notes": "Wholesale platform reselling through many small registrars. Identity-of-actual-actor is downstream."
    },
    "81": {
      "name": "Gandi",
      "nsPatterns": ["^ns\\d+\\.gandi\\.net$"],
      "country": "FR",
      "aggressive": false,
      "notes": "Retail-focused European registrar. Not an aggregator."
    },
    "269": {
      "name": "Key-Systems / RRPproxy",
      "nsPatterns": ["^ns\\d+\\.rrpproxy\\.net$", "^ns\\d+\\.key-systems\\.net$"],
      "country": "DE",
      "aggressive": true,
      "notes": "Wholesale + drop-catch via RRPproxy. Frequently fronts for European aftermarket buyers; volume drop-catch credentials at .com/.net registries."
    },
    "1390": {
      "name": "Hexonet / 1API",
      "nsPatterns": ["^ns\\d+\\.hexonet\\.net$", "^ns\\d+\\.ispapi\\.net$"],
      "country": "DE",
      "aggressive": true,
      "notes": "Drop-catch + reseller platform. Volume credentials; common back-end for resellers running automated drop sniping."
    },
    "49": {
      "name": "GMO Internet",
      "nsPatterns": ["^[a-z]+\\.dnsv\\.jp$", "^ns\\d+\\.gmointernet\\.com$", "^ns\\d+\\.onamae\\.com$"],
      "country": "JP",
      "aggressive": true,
      "notes": "Onamae.com — dominant .JP registrar with aggressive aftermarket. Snipes short stems likely to resell to Japanese market."
    },
    "1659": {
      "name": "Crazy Domains / Dreamscape Networks",
      "nsPatterns": ["^ns\\d+\\.crazydomains\\.com$", "^ns\\d+\\.syrahost\\.com$"],
      "country": "AU",
      "aggressive": true,
      "notes": "AU-region drop-catch + aftermarket. Aggressive on .com.au and short generic .com."
    },
    "2487": {
      "name": "Internet.bs / Internet Domain Service BS",
      "nsPatterns": ["^[a-z]+\\.internet\\.bs$", "^dns\\d+\\.internetbs\\.net$"],
      "country": "BS",
      "aggressive": true,
      "notes": "Bahamas-domiciled, anonymity-friendly. Used as a snipe destination when actor wants to obscure attribution; WHOIS often privacy-protected."
    }
  }
}