For those playing along at home, just an observation that as of today:

breachforums[.]info

has spun up as new on DDoS-Guard, registered through Nicenic yesterday.

#infosec #threatintel

Also, seeing dozens and dozens of garbage .top domains being spun up on pananames[.]com nameservers, registered through URL Solutions (same company as pananames), and then transferred into storm-pro[.]net. Started Monday 2025-06-24.

#threatintel

@neurovagrant is there anything legit or valid on a .top domain these days? It’s wild.
@jwgoerlich Not that I've seen. I block .top at the DNS level for my home network and have never encountered a need to allowlist something.
@neurovagrant @jwgoerlich I have never received a single ticket request to allow a .top domain.

@badsamurai you guys block it for the Enterprise network?

@neurovagrant @jwgoerlich

@pft @neurovagrant @jwgoerlich Yep! Not a single request or exception.

@badsamurai

That's interesting. I wonder why it's not in the top 10 malicious TLDs of Spamhaus:

https://www.spamhaus.org/reputation-statistics/cctlds/domains/

I'm going to give a try to see if my employer also blocks it. I only know that they block the whole .app TLD...

@neurovagrant @jwgoerlich