Whisper Research

Threat research / World Cup 2026

Six domains in eight seconds

The match had not started. The infrastructure had.

A global event gives defenders a calendar while giving opportunists a runway. On March 20, six FIFA lookalikes appeared in eight seconds. The tournament would not begin for another 83 days. Registration timing was not a verdict; it was a lead. Across the wider dataset, that same monitor-first approach preserved a separate non-blocked name that later opened into a nine-domain phishing cluster.

The opening clue was coordination, not malice. The repeated stem, shared registrar, TLD spread, and near-simultaneous creation are consistent with automated batch registration. Those traits justified monitoring and infrastructure pivots; by themselves, they did not identify an operator or prove malicious intent.

The signal arrived before the threat verdict.

01

The opportunity opened months before kickoff. Six domains sharing the fifa-com stem were registered through one registrar in eight seconds, inside a wider eight-domain ring.

02

The monitored population kept expanding. One repeatable *worldcup*.com.cn naming pattern grew from 260 domains on June 11 to 523 by July 17, while the July 18 feed checkpoint contained nearly five times the matching query count observed on June 11.

03

The decisive evidence came from the pivot. A FIFA-themed domain first recorded with ALLOW later led, through an exact nameserver-pair intersection, to eight additional domains carrying the same high-confidence phishing state.

04

The defensive lesson is to preserve weak signals. A lookalike is not automatically malicious, and a missing feed verdict is not a safety finding. Monitoring creates the lead; connected infrastructure and later threat evidence determine whether it should escalate.

The first clue arrived 83 days before kickoff.

At 12:52:32 UTC on March 20, the first domain in the burst was registered. Five more followed by 12:52:40. All six repeated the same fifa-com stem across different top-level domains and used the same registrar. A seventh ring member had appeared eight minutes earlier; an eighth followed three days later.

6domains created between 12:52:32 and 12:52:40 UTC
7ring members registered on March 20
8top-level domains in the wider ring
83days from the burst to the June 11 opening
Creation sequence for the fifa-com lookalike ring
DomainCreated UTCRegistrarPlace in sequence
fifa-com[.]comMar 20 12:44:01GoDaddyEarlier that morning
fifa-com[.]vipMar 20 12:52:32GoDaddyBurst begins
fifa-com[.]siteMar 20 12:52:33.274GoDaddy+1.274 seconds
fifa-com[.]websiteMar 20 12:52:37.143GoDaddy+5.143 seconds
fifa-com[.]storeMar 20 12:52:39.405GoDaddy+7.405 seconds
fifa-com[.]shopMar 20 12:52:40GoDaddy+8 seconds
fifa-com[.]xyzMar 20 12:52:40GoDaddy+8 seconds
fifa-com[.]topMar 23 14:40:38GnameRing extends three days later

By July 18, the feed-visible query count was nearly five times the June 11 checkpoint.

The broader monitored population also appeared in query activity visible to Whisper Data Feeds. The feed presented 23,930 matching queries at the June 11 checkpoint and 119,188 on July 18, a 4.98× difference. These are six discrete observations, not a continuous daily series or the total DNS-query volume for the domains.

Queries presented in Whisper Data Feeds at six checkpoints

Y-axis: feed-visible queries for measured names at each checkpoint; the same filter was applied throughout

Unit · observed queries
Read the exact chart data
DateMatching domainsQueries observed in Whisper Data Feeds
2026-06-111,72023,930
2026-07-012,12131,694
2026-07-041,96035,320
2026-07-172,079109,003
2026-07-182,194119,188
2026-07-192,031114,880
What changedThe measured names generated activity visible to Whisper Data Feeds, and the July 18 checkpoint was the highest of the six observations. The chart does not establish the shape or cause of activity between checkpoints. The counts are not people, sessions, page visits, losses, or victims.

A second population more than doubled during the tournament.

As we tracked the broader lookalike landscape, one naming grammar stood out: *worldcup*.com.cn. Comparable frozen daily runs counted 260 matching domains on June 11 and 523 by July 17. The population then held at 523 through the July 19 final run.

Cumulative *worldcup*.com.cn population

Thirty-nine daily pipeline runs, June 11 to July 19

260 → 523 / +101.2%
Read the exact daily chart data
Comparable frozen daily runs for the *worldcup*.com.cn rule
DateCumulative domainsDateCumulative domains
2026-06-112602026-07-01442
2026-06-123272026-07-02446
2026-06-133532026-07-03462
2026-06-143552026-07-04472
2026-06-153572026-07-05472
2026-06-163622026-07-06473
2026-06-173642026-07-07473
2026-06-183642026-07-08473
2026-06-193642026-07-09486
2026-06-203672026-07-10486
2026-06-213742026-07-11489
2026-06-223792026-07-12512
2026-06-233822026-07-13514
2026-06-243982026-07-14514
2026-06-254002026-07-15514
2026-06-264002026-07-16520
2026-06-274082026-07-17523
2026-06-284112026-07-18523
2026-06-294182026-07-19523
2026-06-30430
+263net additions across the comparable daily series
101.2%growth from the June 11 baseline
80.6%of net expansion present by July 4
523population at the July 19 final-day run
What the pattern gave usThe naming grammar created a population to monitor, not a blocklist. We used novelty, activity presented in Whisper Data Feeds, infrastructure reuse, content, and sourced threat intelligence to decide which names merited deeper investigation.
5.5%

of the FIFA-themed NOD corpus carried BLOCK, REVIEW, or WATCH in the frozen July 19 pipeline run.

Most names had no included feed verdict. That did not make them safe.

The frozen July 19 run contained 2,169 FIFA-themed names in the newly observed domain corpus. Only 119 carried BLOCK, REVIEW, or WATCH on the included feeds. The remaining 2,050 were unlisted in that snapshot.

119 feed-flagged2,050 not flagged on included feeds

That gap is why the investigation could not end with a reputation lookup. An unlisted domain may be benign, inactive, too new for a feed, or simply unseen by the included sources. The state describes coverage at one frozen point in time; it is neither a clean bill of health nor evidence of maliciousness.

The investigation changed when we stopped treating each domain as an isolated object.

We compared registration, nameserver, origin, routing, and threat-state relationships. Each layer answered a different question: which names appeared together, which infrastructure they reused, and whether later evidence changed the assessment.

01 / Origin context

A bounded sample converged on one probable backend.

A July 19 origin analysis connected 14 sampled farm domains to one probable backend. The result applies to that sample; it does not automatically extend to all 523 names.

02 / Nameserver context

The eight-domain ring separated into four groups.

The July 21 graph snapshot organized the fifa-com.* ring by nameserver relationships, creating pivots that a one-domain status check could not provide.

03 / Threat context

The evidence changed after the final snapshot.

On July 21, all eight ring domains returned HIGH in a bounded graph re-check. We keep that later observation separate rather than projecting it backward onto March or July 19.

No provider allegationRegistrars, DNS providers, CDNs, hosting companies, and networks are legitimate shared services. Their appearance in an infrastructure path does not imply participation, authorization, or knowledge of abuse.

One ALLOW lead opened into a nine-domain phishing cluster.

On June 8, the newly observed domain pipeline recorded fifaguanwangzhongwen[.]lol (roughly, “FIFA official website, Chinese”) with an ALLOW verdict. The brand-and-lure language kept it in scope. When we reopened the lead in WhisperGraph on July 21, the evidence picture changed.

Read the nine-domain evidence table
Exact-pair domains carrying HIGH · phishing · malware · blacklist with four threat-source signals in the July 21 WhisperGraph snapshot; DNS and routing re-checked July 22
DomainIPv4 addressAnnounced prefixASN
fifaguanwangzhongwen[.]lol160.124.56.139160.124.32.0/19AS132839
fifashijiebeiguanwang[.]lol160.124.56.138160.124.32.0/19AS132839
fifazuqiushijiepojieban[.]lol160.124.64.122160.124.64.0/19AS132839
fifazuixinshijiepaimingwanzheng[.]lol166.75.188.253166.75.160.0/19AS132839
fifashijiepaimingyilanbiaoquanbuduiwu[.]lol166.75.186.124166.75.160.0/19AS132839
fifashijiepaimingyilanbiaozuixin[.]lol166.75.186.123166.75.160.0/19AS132839
fifashijiepaimingdiyi[.]lol166.75.187.67166.75.160.0/19AS132839
fifazuixinshijiepaimingzuihouyiming[.]lol166.75.189.194166.75.160.0/19AS132839
fifaguanwangrukouzhongwen[.]lol160.124.31.170160.124.0.0/19AS132839
MONITOR

The weak signal survived long enough to become useful.

The pipeline first observed the seed on June 8 and recorded ALLOW. Monitoring preserved the name as a lead before a blocking verdict existed.

PIVOT

The exact pair narrowed the neighborhood.

Following both nameserver relationships surfaced eight additional FIFA-themed domains. Every one carried the same four-source HIGH · phishing · malware · blacklist graph state.

CORROBORATE

Live routing supplied a separate line of evidence.

All nine IPv4 addresses fell within four prefixes announced by AS132839 / POWER LINE DATACENTER. That concentration adds context; it does not make the ASN itself a verdict.

Taken togetherNo single feature decided the case. Confidence increased because independent evidence aligned: brand-and-lure language, a later multi-source phishing state, exact nameserver-pair reuse, a nine-domain naming cluster, and routing concentration outside the Cloudflare CDN. The nameserver pair and ASN remain investigative pivots, not operator attribution, proof about neighboring customers, or an allegation against either provider.

Keep the lead before it becomes the incident.

This investigation did not begin with a confirmed phish. It began with timing and naming. The graph mattered because it allowed a weak signal to be revisited after new threat and infrastructure evidence appeared.

Flat lookup

“Is this domain listed?”

Connected investigation

“What else was created, hosted, routed, or listed with it, and when?”

MONITOR

Start while infrastructure is still being assembled.

Watch newly created brand and event lookalikes months ahead of launches, sales, tournaments, and public deadlines.

CLUSTER

Pivot on relationships that narrow the field.

Combine registration cadence and naming grammar with nameservers, certificates, hosting, routing, feed-visible activity, and content. Avoid high-fan-out pivots that mostly describe shared infrastructure.

EXPLAIN

Separate observation from assessment.

Show what came from a feed, what came from connected infrastructure, what was verified live, and what remains an analyst inference.

Follow the signal before the lure reaches a user.

Bring Whisper a brand, domain, IP, nameserver, prefix, or ASN. Across approximately 7.4 billion nodes and 39 billion edges, WhisperGraph follows connected DNS, routing, registration, hosting, and threat context while retaining the evidence behind the answer.

How to read the findings.

Interpretation limits

A themed or lookalike domain is not automatically malicious; it is an indicator to watch and a starting point for pivots into related infrastructure. Query counts in this article represent activity observed in Whisper Data Feeds, not all DNS queries for the measured domains, and they do not identify people or outcomes. Registration cadence supports coordination but does not attribute an operator. Shared infrastructure may include unrelated customers. Probable origin is a graph inference, not ground truth. Feed absence means “not listed on the included feeds at that time,” not “safe.”

Disclosure

This independent research is not affiliated with or endorsed by FIFA. Indicators are defanged. Provider names describe infrastructure relationships and do not imply participation in abuse.