This repository presents an evidence-based investigation into ShortDot SA, a Luxembourg registry operator controlling seven TLDs, revealing that 70.4% of its 6.2 million domains are phantom registrations with zero DNS records, zero verified legitimate businesses, and significant brand-impersonation phishing at scale.

Stars

110

7-day growth

No data

Forks

8

Open issues

0

License

MIT

Last updated

2026-07-27

AI repository intelligence
FR-AI / ANALYSIS

Why it is worth attention

It systematically documents structural conflicts of interest (e.g., registry execs also lead the brand-protection firm NameBlock), provides daily-updated zone enumeration and threat-intel cross-references, and challenges the registry's claim of serving legitimate users with transparent data and an open challenge to find a single real business.

Who it is for

  • Cybersecurity researchers and threat analysts
  • ICANN compliance and policy stakeholders
  • Brand protection and anti-phishing teams
  • Domain industry watchdogs and journalists

Use cases

  • Ingesting daily IOC feeds (STIX 2.1, CSV) for phishing detection and blocking
  • Providing evidence for ICANN compliance complaints against registry abuse
  • Conducting academic or policy research on domain abuse and registry accountability
  • Evaluating domain portfolios for due diligence or brand-risk assessment

Strengths

  • 100% enumeration of all domains across seven zones with daily updates
  • Multi-source threat intelligence cross-reference (Spamhaus, SURBL, URLScan, OTX, and eight phishing feeds)
  • Open data and reproducible methodology with full zone files and structured analytics
  • Clear documentation of registry-registrar conflicts (e.g., NameSilo 55× concentration anomaly) and revenue flows

Considerations

  • Limited to ShortDot-operated TLDs; does not cover other registries
  • Legitimacy classification relies on automated signals and manual review, which may miss borderline cases
  • Phantom domains (dead no-IP) are categorized as non-malicious but the investigation infers metric padding without direct proof of intent

README quick start

7 zones. 6.2 million domains. Zero verified legitimate businesses.We enumerated every single one.

ShortDot SA (Luxembourg) — a registry operator that charges ICANN $1.74M/year in fees while its zones host 51,670 brand-impersonation domains targeting Chase, Binance, MetaMask, Ledger. 70.4% of all registered domains carry no DNS records. They were never meant to be used. They were meant to be counted. This repository counts them back.

9.5% of all global phishing originates in ShortDot zones  ·  .bond ranks #3 globally by phishing domain count  ·  100% of .bond phishing domains were maliciously registered — Interisle Consulting Group, Phishing Landscape 2025  ·  1,542,922 phishing domains measured


🔴 LIVE INVESTIGATION FEED · Auto-updated · Last fetch 2026-07-27

📦 Domains tracked6,242,647 💰 Est. ShortDot revenue$12,557,633 💸 ICANN fees (registry)$1,741,262 ✅ Confirmed malicious0.1% (3) 🏛️ Verified legitimate0 sites found ⚡ Fresh (≤7d)100.0%

🏷️ TLD Breakdown

TLDDomainsActiveNo IP (dead)Confirmed MaliciousVerified LegitEst. Revenue
.icu976,416277,727 (28.4%)698,6893$634,670
.bond1,325,001106,034 (8.0%)1,218,9670$8,612,506
.cyou756,981265,657 (35.1%)491,3240$492,038
.sbs1,912,083596,569 (31.2%)1,315,5140$1,242,854
.cfd952,385407,496 (42.8%)544,8890$619,050
.buzz209,416130,210 (62.2%)79,2060$680,602
.qpon110,36561,237 (55.5%)49,1280$275,912

Table auto-generated on each daily fetch run.

📈 Registration Burst Days

DateDomains× Average
2026-07-275,1411.0×

🎯 Top Targeted Brands & Keywords

bonus (13) · eos (10) · dia (7) · gaming (6) · tron (6) · portal (6) · hop (4) · ledger (4) · unlock (3) · connect (3) · aura (3) · auth (3) · rug (3) · account (3) · access (2)

📥 Download Threat Intelligence

**Full zone files (all doma

Description

ShortDot SA zone abuse evidence (6.2M domains). Automated Threat Intelligence & daily updated IOCs for .icu, .bond, .cyou, .sbs, .cfd, .buzz, .qpon.

Related repositories

Similar projects matched by category, topics, and programming language.

lopopolo
Featured
lopopolo GitHub avatar

harness-engineering

Harness Engineering is a methodology for improving coding agent outputs by carefully crafting the environment around them—providing curated context, tools, and executable constraints that encode an organization’s nonfunctional requirements and cumulative lessons.

AI & Machine LearningAI Agents
2,390
slvDev
Featured
slvDev GitHub avatar

esp32-ai

A 28.9 million parameter language model runs on an $8 ESP32-S3 microcontroller entirely on-device, generating simple stories at about 9.5 tokens per second.

AI & Machine LearningLarge Language Models
1,960
littledivy
Featured
littledivy GitHub avatar

mimic

mimic captures traffic from any iOS or web app and automatically generates a Python client library that lets you call the app's API like a regular library.

AI & Machine Learning
1,482