Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

White Papers

Exposing a Currently Active Domain Portfolio of Currently Active High-Profile Cybercriminals Internationally

We’ve decided to use Maltego in combination with WhoisXML API’s integration for the purpose of providing actionable and real-time intelligence on a currently active domain portfolio known to have been operated by known high-profile cybercriminals. We used our own high-profile cybercriminal data set for the purpose of empowering fellow researchers and vendors including organizations with the necessary actionable intelligence to help them stay on the top of their game including to assist vendors and organizations on their way to do a proper cyber-attack attribution in terms of tracking down and responding to these campaigns including to assist U.S Law Enforcement and the U.S Intelligence Community on its way to track down and prosecute the cybercriminals behind these campaigns.

Iranian Misinformation Network, Website Seizures, and What’s Left Online

The U.S. Department of Justice took down several Iran-owned websites believed to be involved in a misinformation campaign on June 2021.

In an effort to uncover possibly connected artifacts to make the Internet safer and more transparent, we at WhoisXML API dove deep into the threat, specifically three of the seized sites—presstv[.]com, lualuatv[.]com, and almasirah[.]net, aided by our comprehensive DNS intelligence sources.

The Pareto Botnet – Advanced Cross-Platform Android Malware Using Amazon AWS Spotted in the Wild – An Analysis

We decided to a look at the recently discovered Pareto Botnet using Maltego in combination with WhoisXML API’s integration to provide additional actionable intelligence on the campaign, which could be useful to researchers and vendors on their way to tracking down and responding to the cyberattack campaigns.

In this article we’ll elaborate on the Pareto Botnet and offer practical and actionable intelligence on the actual C&C infrastructure which also includes the use of Amazon’s AWS for C&C (Command and Control) purposes.

Profiling the Liberty Front Press Network Online - An OSINT Analysis

Profiling the Liberty Front Press Network Online - An OSINT Analysis

We decided to take a closer look at the Internet-connected infrastructure of the Liberty Front Press Network in connection with a recent takedown and domain seizure as part of an ongoing law enforcement operation fighting online propaganda online and to offer practical and relevant including actionable intelligence on the Internet-connected infrastructure behind the Liberty Front Press Network including the individuals behind it.

In this analysis, we’ll take a closer look inside the Internet-connected infrastructure behind the Liberty Front Press Network and offer practical and relevant information including actionable intelligence on its Internet-connected infrastructure as well as the individuals behind it.

Profiling the Internet Connected Infrastructure of the Individuals on the U.S Sanctions List – An OSINT Analysis

Profiling the Internet Connected Infrastructure of the Individuals on the U.S Sanctions List – An OSINT Analysis

We decided to take a closer look at the Internet-connected infrastructure used by individuals on the most recently released U.S Sanctions List and offer additional insights into the infrastructure including to look for and provide actionable intelligence on their whereabouts.

In this analysis, we’ll take a closer look at the Internet-connected infrastructure of individuals on the U.S Sanctions List and offer an in-depth discussion on the actual Internet-connected infrastructure.

Profiling Russia's U.S Election Interference 2016 - An OSINT Analysis

Profiling Russia's U.S Election Interference 2016 - An OSINT Analysis

We decided to take a closer look at the U.S Election 2016 interference provoked by several spear phishing and malicious campaigns, courtesy of Russia, for the purpose of offering and providing actionable threat intelligence including possible attribution clues for some of the known participants in this campaign. We hope that way to potentially assist fellow researchers and Law Enforcement professionals on their way to track down and prosecute the cybercriminals behind these campaigns.

In this analysis, we’ll take a closer look at the Internet connected infrastructure behind the U.S Election 2016 campaign in terms of malicious activity and offer practical, relevant and actionable threat intelligence on their whereabouts.

The Crypto DNS Report: The Many Faces of Crypto-Related Internet Properties

The Crypto DNS Report: The Many Faces of Crypto-Related Internet Properties

Note: A special thanks to Ed Gibbs, WhoisXML API’s Advanced Threat Researcher & Technical Account Manager, for his help compiling the domain and subdomain files used in this post.

Cryptocurrencies have gone a long way since their inception. Perhaps the most significant evidence that they have become embedded into our digital society is that as of February 2021, more than 4,000 cryptocurrencies were in existence. A decade ago, most people didn’t even know what Bitcoin was.

Cryptocurrency investing has changed the lives of certain people, too—from the Winklevoss twins who became billionaires through Bitcoin mining to the more recent rags-to-riches story of a Dogecoin millionaire who initially invested his life savings.

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.