PULSE NAME
ualberta[.]ca - Active Phishing/Hacking against U of A. Databreach includes 18 active malicious detections (DNS Twist - 03.06.26)
WHITE Disable_Duck 2026-03-06 Modified: 2026-04-06
18
IOCs
MEDIUM VOLUME
Domain name permutation engine detects homograph phishing attacks, typo squatting, & brand impersonation. It generates a comprehensive list of domain permutations based on a provided domain name and verifies whether any of these permutations are in use. This tool is useful for uncovering potentially malicious domains that target your organization. Domain Fuzzing Algorithms: Generates permutations using various algorithms. Unicode Domain Names (IDN): Supports internationalized domain names. Dictionary Files: Allows additional permutations from dictionary files. Multithreaded Task Distribution: Efficiently handles multiple tasks. Phishing Detection: Detects live phishing webpages using HTML similarity with fuzzy hashes (ssdeep/tlsh) and screenshot visual similarity with perceptual hashes (pHash). Rogue MX Host Detection: Identifies intercepting misdirected emails. GeoIP Location: Provides geographical location of IPv4 addresses.
Indicators of Compromise (18)
All domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain oalberta.ca 2026-03-06
domain talberta.ca 2026-03-06
domain uaberta.ca 2026-03-06
domain uaiberta.ca 2026-03-06
domain ualbera.ca 2026-03-06
domain ualbert.ca 2026-03-06
domain ualberta.co 2026-03-06
domain ualberta.info 2026-03-06
domain ualberta.net 2026-03-06
domain ualberta.ru 2026-03-06
domain ualbertas.ca 2026-03-06
domain ualbertau.ca 2026-03-06
domain ulaberta.ca 2026-03-06
domain uwalberta.ca 2026-03-06
domain valberta.ca 2026-03-06
hostname ua.lberta.ca 2026-03-06
domain uallberta.ca 2026-03-18
domain ualberta.com 2026-03-18