← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
The World Cup Fraud Infrastructure is Nearly Three Times Larger Than We First Reported
The expanded investigation into World Cup phishing infrastructure has revealed a significantly larger and more complex web of fraudulent domains than previously reported. Initially, 79 domains were identified, but further research has expanded that count to at least 222 domains operating across 203 unique IP addresses, which marks an increase of approximately 2.8 times in domain numbers and over 14 times in hosting footprint. The campaign is characterized by at least four separate operator clusters, indicating a distributed network of cybercriminals rather than a single, centralized threat actor.
Indicators of Compromise (27)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | 1b02595c66a13a4a5a523a76de25803bdb950623 | — | 2026-05-21 | |
| FileHash-SHA1 | 3b8bb7631b39f455d31544b55ba97b49ab1888c1 | — | 2026-05-21 | |
| FileHash-SHA1 | fb0498ab592232747a4d90aa150ee4e0506869ca | — | 2026-05-21 | |
| FileHash-SHA1 | fc1db8def38bb08010bb8f8ac14d5e498ff8ff43 | — | 2026-05-21 | |
| IPv4 | 104.225.235.49 | CC=US ASN=AS25820 it7 networks inc | 2026-05-21 | |
| IPv4 | 148.178.16.48 | CC=US ASN=ASNone | 2026-05-21 | |
| IPv4 | 154.39.81.213 | CC=US ASN=AS8796 kurun cloud inc | 2026-05-21 | |
| IPv4 | 154.86.0.33 | CC=DE ASN=AS136897 enjoyvc cloud group limited. | 2026-05-21 | |
| IPv4 | 38.246.249.74 | CC=US ASN=AS174 cogent communications | 2026-05-21 | |
| domain | bexiapparelsw.shop | — | 2026-05-21 | |
| domain | cairnspringsw.shop | — | 2026-05-21 | |
| domain | dustdigitalsw.shop | — | 2026-05-21 | |
| domain | fifa-com.one | — | 2026-05-21 | |
| domain | fifa-com.shop | — | 2026-05-21 | |
| domain | fifa-com.site | — | 2026-05-21 | |
| domain | fifa-com.store | — | 2026-05-21 | |
| domain | fifa-com.vip | — | 2026-05-21 | |
| domain | fifawebsite.cn | — | 2026-05-21 | |
| domain | floridagiftssw.shop | — | 2026-05-21 | |
| domain | https-fifa.cn | — | 2026-05-21 | |
| domain | protectlysw.shop | — | 2026-05-21 | |
| domain | vww-fifa.com | — | 2026-05-21 | |
| domain | ww-fifa.vip | — | 2026-05-21 | |
| domain | ww-fifaweb.cn | — | 2026-05-21 | |
| domain | www-fifa-com.vip | — | 2026-05-21 | |
| domain | www-fifaworldcup.one | — | 2026-05-21 | |
| domain | www-fifaworldcup.vip | — | 2026-05-21 |