Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

GitHub RadarDual-use project

phishdestroy/shortdot-evidence

ShortDot SA zone abuse evidence (6.2M domains). Automated Threat Intelligence & daily updated IOCs for .icu, .bond, .cyou, .sbs, .cfd, .buzz, .qpon. Primary language: Python. 110 stars.

Python110 stars8 forkspushed Jul 27, 2026MIT

Project links:Open GitHub projectBack to radar

README Preview

Fetched from GitHub

<div align="center"> <img src="docs/assets/banner.gif" width="100%"/> </div>

<h3 align="center">7 zones. 6.2 million domains. Zero verified legitimate businesses.<br/>We enumerated every single one.</h3>

<p align="center"> <b>ShortDot SA (Luxembourg)</b> — a registry operator that charges ICANN $1.74M/year in fees<br/> while its zones host 51,670 brand-impersonation domains targeting Chase, Binance, MetaMask, Ledger.<br/> 70.4% of all registered domains carry no DNS records. They were never meant to be used.<br/> They were meant to be <i>counted.</i><br/> <b>This repository counts them back.</b> </p>

<p align="center"> <b>9.5%</b> of all global phishing originates in ShortDot zones &nbsp;·&nbsp; <code>.bond</code> ranks <b>#3 globally</b> by phishing domain count &nbsp;·&nbsp; <b>100%</b> of <code>.bond</code> phishing domains were maliciously registered <br/><sub>— Interisle Consulting Group, Phishing Landscape 2025 &nbsp;·&nbsp; 1,542,922 phishing domains measured</sub> </p>

<div align="center">

<br/>

![IANA Registry](https://www.iana.org/assignments/tld-review/) ![TLP CLEAR](https://www.first.org/tlp/) ![License MIT](LICENSE) ![Auto-updated](https://github.com/phishdestroy/shortdot-evidence/actions)

<br/>

</div>

---

<!-- LIVE_STATS:START -->

🔴 LIVE INVESTIGATION FEED &middot; Auto-updated &middot; Last fetch 2026-07-27

<table><tr> <td align="center"><b>📦 Domains tracked</b><br/><sub><code>6,242,647</code></sub></td> <td align="center"><b>💰 Est. ShortDot revenue</b><br/><sub><code>$12,557,633</code></sub></td> <td align="center"><b>💸 ICANN fees (registry)</b><br/><sub><code>$1,741,262</code></sub></td> <td align="center"><b>✅ Confirmed malicious</b><br/><sub><code>0.1%</code> (3)</sub></td> <td align="center"><b>🏛️ Verified legitimate</b><br/><sub><code>0</code> sites found</sub></td> <td align="center"><b>⚡ Fresh (≤7d)</b><br/><sub><code>100.0%</code></sub></td> </tr></table>

🏷️ TLD Breakdown

| TLD | Domains | Active | No IP (dead) | Confirmed Malicious | Verified Legit | Est. Revenue | |:--|--:|--:|--:|--:|--:|--:| | .icu | 976,416 | 277,727 (28.4%) | 698,689 | 3 | — | $634,670 | | .bond | 1,325,001 | 106,034 (8.0%) | 1,218,967 | 0 | — | $8,612,506 | | .cyou | 756,981 | 265,657 (35.1%) | 491,324 | 0 | — | $492,038 | | .sbs | 1,912,083 | 596,569 (31.2%) | 1,315,514 | 0 | — | $1,242,854 | | .cfd | 952,385 | 407,496 (42.8%) | 544,889 | 0 | — | $619,050 | | .buzz | 209,416 | 130,210 (62.2%) | 79,206 | 0 | — | $680,602 | | .qpon | 110,365 | 61,237 (55.5%) | 49,128 | 0 | — | $275,912 |

Table auto-generated on each daily fetch run.

📈 Registration Burst Days

| Date | Domains | × Average | |:--|--:|--:| | 2026-07-27 | 5,141 | 1.0× |

🎯 Top Targeted Brands & Keywords

bonus (13) &middot; eos (10) &middot; dia (7) &middot; gaming (6) &middot; tron (6) &middot; portal (6) &middot; hop (4) &middot; ledger (4) &middot; unlock (3) &middot; connect (3) &middot; aura (3) &middot; auth (3) &middot; rug (3) &middot; account (3) &middot; access (2)

📥 Download Threat Intelligence

Full zone files (all domains per TLD):

| TLD | All domains | Deployed (+IP) | Phantom (no IP) | |:--|:--|:--|:--| | .icu | data/by_tld/icu.txt 976,416 | deployed/icu.txt 277,727 | phantom/icu.txt 698,689 | | .bond | data/by_tld/bond.txt 1,325,001 | deployed/bond.txt 106,034 | phantom/bond.txt 1,218,967 | | .cyou | data/by_tld/cyou.txt 756,981 | deployed/cyou.txt 265,657 | phantom/cyou.txt 491,324 | | .sbs | data/by_tld/sbs.txt 1,912,083 | deployed/sbs.txt 596,569 | phantom/sbs.txt 1,315,514 | | .cfd | data/by_tld/cfd.txt 952,385 | deployed/cfd.txt 407,496 | phantom/cfd.txt 544,889 | | .buzz | data/by_tld/buzz.txt 209,416 | deployed/buzz.txt 130,210 | phantom/buzz.txt 79,206 | | | 110,365 | 61,237 | 49,128 | | | — | 0 | 5,141 |

IOC & blocklists:

| File | Format | Description | |:--|:--:|:--| | `ioc/domains_confirmed.txt` | TXT | Feed + intel confirmed phishing | | `ioc/domains_high.txt` | TXT | HIGH severity (brand impersonation + feed hits) | | `ioc/domains_all_malicious.txt` | TXT | All classified — all severity | | `ioc/indicators.csv` | CSV | Full IOC with TLD/category/severity/IP |

Analytics & structured data:

| File | Format | Description | |:--|:--:|:--| | `data/index.json` | JSON | Full analytics snapshot | | `data/ioc/brand_domains.json` | JSON | Domains by targeted brand | | `data/ioc/serial_registrants.json` | JSON | Repeat registrants + their domains | | `data/ioc/shared_ips.json` | JSON | Bulletproof hosting clusters | | `data/ioc/feed_confirmed.json` | JSON | Per-domain phishing feed source mapping | | `data/ioc/intel_results.json` | JSON | Spamhaus/SURBL/URLScan/OTX cross-ref results | | `data/ioc/stix-bundle.json` | STIX 2.1 | MISP/OpenCTI ready bundle |

📊 Live dashboard: Pages link at top · Updated daily 06:00 UTC

<!-- LIVE_STATS:END -->

<div align="center">

![🔴 LIVE SITE](https://phishdestroy.github.io/shortdot-evidence/) ![Evidence Portal](https://phishdestroy.github.io/shortdot-evidence/) ![ICANN Filed](https://www.icann.org/compliance) ![MIT License](LICENSE)

<br/>

Image: README asset Image: README asset Image: README asset Image: README asset Image: README asset Image: README asset

</div>

---

📑 Table of Contents

<table> <tr> <td valign="top">

Investigation

  • 0 · Special Dedication to NameSilo
  • 1 · Background
  • 2 · Subject: ShortDot SA
  • 2.1 · Principals & Structural Conflicts
  • 3 · The Seven Zones
  • 4 · Methodology

</td> <td valign="top">

The Core Question

  • 5 · Show Me One Legitimate Business
  • 6 · Follow the Money
  • 7 · The "Private Infrastructure" Myth
  • 8 · NameBlock — Structural Conflict
  • 9 · Findings

</td> <td valign="top">

Data / Legal

  • 10 · Timeline of Acquisitions
  • 11 · Enforcement Posture
  • 11.1 · The Freenom Legacy vs. ShortDot Reality
  • 11.2 · The "Gambling & Affiliate" Defense
  • 11.3 · Criminal Infrastructure Record
  • 12 · Repository Structure
  • Legal Notice & Responsible Disclosure

</td> </tr> </table>

---

0 · Special Dedication to NameSilo

<details> <summary><b>🏆 NameSilo: ShortDot's largest registrar partner and most enthusiastic phishing infrastructure supplier — click to expand</b></summary> <br/>

🏆 We must confess: we are massive fans of [NameSilo](https://github.com/phishdestroy/namesilo-evidence). We are endlessly inspired by their mastery — not just their steadfast commitment to retro web design, but their unparalleled operational brilliance in reputation management.

It takes true dedication to aggressively publish self-praising PR articles and manufactured reviews while systematically trying to silence independent security researchers. We watch in awe as they zealously defend phishing operators and scam networks, going so far as to blatantly lie about removing VirusTotal detections just to keep their most "valuable" clients online.

Their coordinated campaigns to deplatform truth-tellers, block researchers, and scrub the internet of any critical analysis are nothing short of breathtaking.

When a registrar fights this hard and spends this much energy protecting malicious infrastructure, it is only fair that we return the favor. This repository exists to give their tireless efforts the global public recognition they so desperately deserve.

<details> <summary><b>💸 The scheme behind the growth — click to read</b></summary> <br/>

ShortDot SA owns the registry — it controls the zones and sets wholesale prices. NameSilo operates as a registrar and is, by volume, the single largest buyer of ShortDot zone domains. Every day, in bulk, NameSilo purchases registrations across .icu, .bond, .cyou, .sbs, .cfd, .buzz, and .qpon — the exact zones its business partner controls.

The same ownership network sits on both sides. Money moves between related entities. The registry books revenue. The registrar books inventory. No real end customer is required — the registration event itself is the product.

Namecheap charges $1.39/yr (.cfd) and $1.54/yr (.sbs) for a single registration with no minimum commitment. NameSilo charges $1.88/yr for both TLDs at its entry tier (1–49 domains) — and only reaches those Namecheap prices at 5,000+ domains purchased simultaneously. No ordinary registrant buys 5,000 domains at once. The pricing structure leaves no rational explanation for NameSilo's dominant volume in ShortDot zones unless the buyer is not operating in a retail market at all.

The result: millions of domains bulk-registered daily, 70.4% with zero DNS records, never activated, never used by any real business. They were never meant to be used. They were meant to be counted — in filings, in pitch decks, in press releases about explosive growth.

</details>

**Full NameSilo investigation → [github.com/p

.qpon
data/by_tld/qpon.txt
deployed/qpon.txt
phantom/qpon.txt
All zones
deployed_all.txt
phantom_all.txt