Criminal Use of Domain Names
Greg Aaron, Illumintel Colin Strutt, Interisle Consulting Group
1
Criminal Use of Domain Names Greg Aaron, Illumintel Colin Strutt, - - PowerPoint PPT Presentation
Criminal Use of Domain Names Greg Aaron, Illumintel Colin Strutt, Interisle Consulting Group 1 Maliciously Registered Domain Names Domain names registered to perpetrate cybercrime. Scope of the problem? 197,876,195 gTLD domain names
1
specifically, it has very human costs: theft of money and personal information.
2
3
services to “weaponize” large numbers of domains for their attacks.
acquire domain names
4
threat intelligence and reputation lists.
spamming
registrations.
5
December 12-25, 2018 =
names
Registrar IANA ID Abuse Domains
GMO Internet, Inc.
d/b/a Onamae.com
49 8,713 (100%)
NameCheap, Inc.
1068 2 (0%)
Nearly all of these were registered using a single registrar
6
Above: # of domains in .TOKYO registry. Source: ntldstats.com The blocklisted domains represented 7% of the domains in the TLD
7
8
9
1 ¥ = €0.0083
Customers can upload a file of names Web site will create random names
Address, registrant Email address.
and .WORK
criminal actors.
10
records (nameservers), malware data, spamples, etc. Each is a different specialty.
InterQ GMO Internet, Inc.; IDC Frontier, Inc.; Sakura Internet, Inc.
additional bogus pseudonyms, etc.
targeting Japanese citizens.
11
bulk registration services to use large numbers of domains for their attacks
Analysis of DNS Abuse in gTLDs (SADAG)
a difference with one intervention.]
12
13