Executive Summary
The signal arrived before the threat verdict.
The opportunity opened months before kickoff. Six domains sharing the fifa-com stem were registered through one registrar in eight seconds, inside a wider eight-domain ring.
The monitored population kept expanding. One repeatable *worldcup*.com.cn naming pattern grew from 260 domains on June 11 to 523 by July 17, while the July 18 feed checkpoint contained nearly five times the matching query count observed on June 11.
The decisive evidence came from the pivot. A FIFA-themed domain first recorded with ALLOW later led, through an exact nameserver-pair intersection, to eight additional domains carrying the same high-confidence phishing state.
The defensive lesson is to preserve weak signals. A lookalike is not automatically malicious, and a missing feed verdict is not a safety finding. Monitoring creates the lead; connected infrastructure and later threat evidence determine whether it should escalate.
01 / How the investigation began
The first clue arrived 83 days before kickoff.
At 12:52:32 UTC on March 20, the first domain in the burst was registered. Five more followed by 12:52:40. All six repeated the same fifa-com stem across different top-level domains and used the same registrar. A seventh ring member had appeared eight minutes earlier; an eighth followed three days later.
| Domain | Created UTC | Registrar | Place in sequence |
|---|---|---|---|
| fifa-com[.]com | Mar 20 12:44:01 | GoDaddy | Earlier that morning |
| fifa-com[.]vip | Mar 20 12:52:32 | GoDaddy | Burst begins |
| fifa-com[.]site | Mar 20 12:52:33.274 | GoDaddy | +1.274 seconds |
| fifa-com[.]website | Mar 20 12:52:37.143 | GoDaddy | +5.143 seconds |
| fifa-com[.]store | Mar 20 12:52:39.405 | GoDaddy | +7.405 seconds |
| fifa-com[.]shop | Mar 20 12:52:40 | GoDaddy | +8 seconds |
| fifa-com[.]xyz | Mar 20 12:52:40 | GoDaddy | +8 seconds |
| fifa-com[.]top | Mar 23 14:40:38 | Gname | Ring extends three days later |
02 / The activity signal
By July 18, the feed-visible query count was nearly five times the June 11 checkpoint.
The broader monitored population also appeared in query activity visible to Whisper Data Feeds. The feed presented 23,930 matching queries at the June 11 checkpoint and 119,188 on July 18, a 4.98× difference. These are six discrete observations, not a continuous daily series or the total DNS-query volume for the domains.
Queries presented in Whisper Data Feeds at six checkpoints
Y-axis: feed-visible queries for measured names at each checkpoint; the same filter was applied throughout
Read the exact chart data
| Date | Matching domains | Queries observed in Whisper Data Feeds |
|---|---|---|
| 2026-06-11 | 1,720 | 23,930 |
| 2026-07-01 | 2,121 | 31,694 |
| 2026-07-04 | 1,960 | 35,320 |
| 2026-07-17 | 2,079 | 109,003 |
| 2026-07-18 | 2,194 | 119,188 |
| 2026-07-19 | 2,031 | 114,880 |
03 / The naming pattern
A second population more than doubled during the tournament.
As we tracked the broader lookalike landscape, one naming grammar stood out: *worldcup*.com.cn. Comparable frozen daily runs counted 260 matching domains on June 11 and 523 by July 17. The population then held at 523 through the July 19 final run.
Cumulative *worldcup*.com.cn population
Thirty-nine daily pipeline runs, June 11 to July 19
Read the exact daily chart data
| Date | Cumulative domains | Date | Cumulative domains |
|---|---|---|---|
| 2026-06-11 | 260 | 2026-07-01 | 442 |
| 2026-06-12 | 327 | 2026-07-02 | 446 |
| 2026-06-13 | 353 | 2026-07-03 | 462 |
| 2026-06-14 | 355 | 2026-07-04 | 472 |
| 2026-06-15 | 357 | 2026-07-05 | 472 |
| 2026-06-16 | 362 | 2026-07-06 | 473 |
| 2026-06-17 | 364 | 2026-07-07 | 473 |
| 2026-06-18 | 364 | 2026-07-08 | 473 |
| 2026-06-19 | 364 | 2026-07-09 | 486 |
| 2026-06-20 | 367 | 2026-07-10 | 486 |
| 2026-06-21 | 374 | 2026-07-11 | 489 |
| 2026-06-22 | 379 | 2026-07-12 | 512 |
| 2026-06-23 | 382 | 2026-07-13 | 514 |
| 2026-06-24 | 398 | 2026-07-14 | 514 |
| 2026-06-25 | 400 | 2026-07-15 | 514 |
| 2026-06-26 | 400 | 2026-07-16 | 520 |
| 2026-06-27 | 408 | 2026-07-17 | 523 |
| 2026-06-28 | 411 | 2026-07-18 | 523 |
| 2026-06-29 | 418 | 2026-07-19 | 523 |
| 2026-06-30 | 430 |
04 / Where a verdict stops
of the FIFA-themed NOD corpus carried BLOCK, REVIEW, or WATCH in the frozen July 19 pipeline run.
Most names had no included feed verdict. That did not make them safe.
The frozen July 19 run contained 2,169 FIFA-themed names in the newly observed domain corpus. Only 119 carried BLOCK, REVIEW, or WATCH on the included feeds. The remaining 2,050 were unlisted in that snapshot.
That gap is why the investigation could not end with a reputation lookup. An unlisted domain may be benign, inactive, too new for a feed, or simply unseen by the included sources. The state describes coverage at one frozen point in time; it is neither a clean bill of health nor evidence of maliciousness.
05 / Moving beyond reputation
The investigation changed when we stopped treating each domain as an isolated object.
We compared registration, nameserver, origin, routing, and threat-state relationships. Each layer answered a different question: which names appeared together, which infrastructure they reused, and whether later evidence changed the assessment.
A bounded sample converged on one probable backend.
A July 19 origin analysis connected 14 sampled farm domains to one probable backend. The result applies to that sample; it does not automatically extend to all 523 names.
The eight-domain ring separated into four groups.
The July 21 graph snapshot organized the fifa-com.* ring by nameserver relationships, creating pivots that a one-domain status check could not provide.
The evidence changed after the final snapshot.
On July 21, all eight ring domains returned HIGH in a bounded graph re-check. We keep that later observation separate rather than projecting it backward onto March or July 19.
06 / Following one lead
One ALLOW lead opened into a nine-domain phishing cluster.
On June 8, the newly observed domain pipeline recorded fifaguanwangzhongwen[.]lol (roughly, “FIFA official website, Chinese”) with an ALLOW verdict. The brand-and-lure language kept it in scope. When we reopened the lead in WhisperGraph on July 21, the evidence picture changed.
fifaguanwangzhongwen[.]lol
The name justified monitoring, but the contemporary ALLOW verdict did not justify calling it malicious.
alexa.ns.cloudflare.com
yisroel.ns.cloudflare.com
We required both authoritative nameservers to match. Cloudflare CDN edge IPs and AS13335 were not part of the pivot.
A high-confidence phishing cluster
Read the nine-domain evidence table
| Domain | IPv4 address | Announced prefix | ASN |
|---|---|---|---|
| fifaguanwangzhongwen[.]lol | 160.124.56.139 | 160.124.32.0/19 | AS132839 |
| fifashijiebeiguanwang[.]lol | 160.124.56.138 | 160.124.32.0/19 | AS132839 |
| fifazuqiushijiepojieban[.]lol | 160.124.64.122 | 160.124.64.0/19 | AS132839 |
| fifazuixinshijiepaimingwanzheng[.]lol | 166.75.188.253 | 166.75.160.0/19 | AS132839 |
| fifashijiepaimingyilanbiaoquanbuduiwu[.]lol | 166.75.186.124 | 166.75.160.0/19 | AS132839 |
| fifashijiepaimingyilanbiaozuixin[.]lol | 166.75.186.123 | 166.75.160.0/19 | AS132839 |
| fifashijiepaimingdiyi[.]lol | 166.75.187.67 | 166.75.160.0/19 | AS132839 |
| fifazuixinshijiepaimingzuihouyiming[.]lol | 166.75.189.194 | 166.75.160.0/19 | AS132839 |
| fifaguanwangrukouzhongwen[.]lol | 160.124.31.170 | 160.124.0.0/19 | AS132839 |
The weak signal survived long enough to become useful.
The pipeline first observed the seed on June 8 and recorded ALLOW. Monitoring preserved the name as a lead before a blocking verdict existed.
The exact pair narrowed the neighborhood.
Following both nameserver relationships surfaced eight additional FIFA-themed domains. Every one carried the same four-source HIGH · phishing · malware · blacklist graph state.
Live routing supplied a separate line of evidence.
All nine IPv4 addresses fell within four prefixes announced by AS132839 / POWER LINE DATACENTER. That concentration adds context; it does not make the ASN itself a verdict.
07 / Security implications
Keep the lead before it becomes the incident.
This investigation did not begin with a confirmed phish. It began with timing and naming. The graph mattered because it allowed a weak signal to be revisited after new threat and infrastructure evidence appeared.
“Is this domain listed?”
“What else was created, hosted, routed, or listed with it, and when?”
Start while infrastructure is still being assembled.
Watch newly created brand and event lookalikes months ahead of launches, sales, tournaments, and public deadlines.
Pivot on relationships that narrow the field.
Combine registration cadence and naming grammar with nameservers, certificates, hosting, routing, feed-visible activity, and content. Avoid high-fan-out pivots that mostly describe shared infrastructure.
Separate observation from assessment.
Show what came from a feed, what came from connected infrastructure, what was verified live, and what remains an analyst inference.
Investigate before the click
Follow the signal before the lure reaches a user.
Bring Whisper a brand, domain, IP, nameserver, prefix, or ASN. Across approximately 7.4 billion nodes and 39 billion edges, WhisperGraph follows connected DNS, routing, registration, hosting, and threat context while retaining the evidence behind the answer.
Methods & boundaries
How to read the findings.
Interpretation limits
A themed or lookalike domain is not automatically malicious; it is an indicator to watch and a starting point for pivots into related infrastructure. Query counts in this article represent activity observed in Whisper Data Feeds, not all DNS queries for the measured domains, and they do not identify people or outcomes. Registration cadence supports coordination but does not attribute an operator. Shared infrastructure may include unrelated customers. Probable origin is a graph inference, not ground truth. Feed absence means “not listed on the included feeds at that time,” not “safe.”
Disclosure
This independent research is not affiliated with or endorsed by FIFA. Indicators are defanged. Provider names describe infrastructure relationships and do not imply participation in abuse.