logo

WHOIS: identification or correlation?

ID: 1d2e0df5-06f1-5ab2-9218-23cbbb82d5ef

STIX ID: report--1d2e0df5-06f1-5ab2-9218-23cbbb82d5ef

Feed Name: The Spamhaus Project

Threat Score
30/100

Date Published: 2023-12-07

Date Updated: 2026-04-30

Author: Carel Bitter

...
...

The report summarizes a case study where researchers successfully correlated a large set of malicious domains attributed to the Prolific Puma operator by leveraging publicly available WHOIS registrant records in the .us TLD; it highlights that .us registry policies (no WHOIS proxy and accessible WHOIS service) made large-scale attribution feasible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.