Cisco Talos regularly monitors networks and domain names that may have once formed a part of attacker infrastructure, or perhaps are victims currently targeted by attackers. Talos recently stumbled upon an unregistered domain name, “tiburoninc.net”. The new owner, TriTech, merged with several other companies in 2018 to form a new entity, CentralSquare Technologies, let Tiburon’s domain names expire in April 2019. The domain name was receiving a huge number of DNS queries, such as “saabloynet” and “wpad.dat””]
Source: https://blog.talosintelligence.com/2021/07/security-implications-of.html

