Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

White Papers

Profiling the “Jabber ZeuS” Rogue Botnet Enterprise - An Analysis

Profiling the “Jabber ZeuS” Rogue Botnet Enterprise - An Analysis

We decided to take a peek at the prolific “Jabber ZeuS” gang using exclusively public and proprietary sources in order to offer additional insights into the online infrastructure of the cybercriminals in question using Matelgo in combination with WhoisXML API’s integration. As a result came up with some pretty interesting findings in the context of exposing additional domains registered by the original “Jabber ZeuS” gang, which could greatly assist researchers and vendors on their way to track down the cybercriminals behind these campaigns.
Profiling a Rogue Fast-Flux Botnet Infrastructure That’s Currently Hosting Multiple Online Cybercrime Enterprises - An Analysis

Profiling a Rogue Fast-Flux Botnet Infrastructure That’s Currently Hosting Multiple Online Cybercrime Enterprises - An Analysis

We’ve recently decided to map and research various domain registrations made by well-known and established online cybercriminals. We took several hundred emails known to belong to well-known cybercriminals and decided to cross-check them for related domain registrations by using Maltego and WhoisXML API’s vast and in-depth real-time and historical WHOIS records database.

In this article, we’ll thoroughly discuss the relevant findings for this study based on several hundred email addresses known to be owned and operated by known cybercriminals and checked them for related domain registrations. Then we will provide actionable intelligence on the online infrastructure of these newly discovered domains known to be managed and registered by known cybercriminals.

Profiling a Portfolio of Cybercriminal Email Addresses By Using WhoisXML API's Historical WHOIS Search and Maltego - An Analysis

Profiling a Portfolio of Cybercriminal Email Addresses By Using WhoisXML API's Historical WHOIS Search and Maltego - An Analysis

We’ve recently decided to map and research various domain registrations made by well-known and established online cybercriminals. We took several hundred emails known to belong to well-known cybercriminals and decided to cross-check them for related domain registrations by using Maltego and WhoisXML API’s vast and in-depth real-time and historical WHOIS records database.

In this article, we’ll thoroughly discuss the relevant findings for this study based on several hundred email addresses known to be owned and operated by known cybercriminals and checked them for related domain registrations. Then we will provide actionable intelligence on the online infrastructure of these newly discovered domains known to be managed and registered by known cybercriminals.

Profiling a Money Mule Recruitment Registrant Emails Portfolio - An Analysis

We’ve recently decided to take an in-depth and personal look inside the modern money mule recruitment ecosystem by using WhoisXML API’s powerful and versatile real-time and historical WHOIS records database, which is one of the security industry’s and the Web’s leading databases for real-time and historical OSINT records. WhoisXML API’s data is a highly recommended tool in the arsenal of OSINT researchers and analysts, which also includes cybercrime researchers and threat intelligence analysts for relevant enrichment and research and analysis.

Exposing a Rogue Domain Portfolio of Fake News Sites - An Analysis

We’ve recently came across to a third-party research indicating a pretty interesting and important Iran-based foreign influence and disinformation campaign. So, we’ve decided to take a deeper look by using Maltego and WhoisXML API so as to offer additional insights into the disinformation campaign in terms of its online infrastructure.

In this analysis, we’ll use public campaign sources for the sample data and will offer an in-depth peek inside its online infrastructure by using Maltego and WhoisXML API’s vast real-time and historical WHOIS database as well as specifying additional IoCs (Indicators of Compromise) for the purpose of assisting researchers and vendors on their way to stay on top of this campaign.

Exposing a Fraudulent Boutique and Rogue Cybercrime-Friendly Forum Community - An Analysis

We decided to take an in-depth look into the infamous hxxp://omerta.cc cybercrime-friendly forum community, which is currently sharing the same infrastructure as the original E-Shop for stolen credit cards information which we’ve already profiled and elaborated on in two separate white papers and case studies. There I decided to continue monitoring and investigating the original E-Shop for stolen credit cards information which we profiled in our original white paper – hxxp://thefreshstuffs.at and came up with some pretty interesting results. Those results also include an additional set of E-shops for stolen credit card information that are actively sharing the same infrastructure of the original E-Shop for stolen credit card information, which we profiled in our original research.

Security Researchers Targeted in a Spear Phishing Campaign - An Analysis

We’ve recently become aware of a malicious targeted spear-phishing client-side exploits dropping campaign that targets legitimate security researchers by approaching them personally or using social media in an attempt to entice them into verifying the validity of a supposedly newly discovered and recently launched Zero Day flaw, which in reality once executed drops malicious software on the hosts of the affected researchers. So, we decided to research even further and offer practical and relevant including actionable intelligence on the campaign’s infrastructure for the purpose of assisting fellow researchers and the industry on its way to track down and monitor the campaign.

How to Use WhoiXML API in Combination with Maltego for Advanced Mapping and Reconnaissance of the Emotet Botnet - An Analysis

In this research and analysis, we’ll use a sample seed of Emotet known and confirmed botnet C&C malicious and fraudulent IPs and offer a detailed peek inside its network infrastructure including an additional set of malicious MD5s which we stumbled upon while profiling it in order to assist security researchers, clients and customers on their way to stay on top of their game in terms of the Emotet botnet.

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.