Interisle report analyzes which top level domains are used for spam, spreading malware, and phishing.
Interisle has released its annual Cybercrime Supply Chain 2024 report, which discusses which top level domain names are used for malware, phishing, and spam.
The company reviewed 16.3 million attacks from Sept 2023 to Aug 2024. 8.6 million unique domains were used in attacks, compared to 4.8 million in the previous year.
Interisle notes some similarities in registration patterns used in attacks.
First, they are frequently registered in bulk. The report states that 2.6 million domains identified from the attacks were registered in bulk, more than double the previous year’s number. In one example, 17,000 malicious domains were registered in under 8 hours at one registrar.
Second, cheaper domains are at higher risk of being used by bad actors.
From a raw numbers perspective, .com has the most malicious domains, followed by .top, .xyz, .shop, and .cc, according to Interisle. But that tells only part of the story since many namespaces are larger than others.
To compensate for this, Interisle also calculates a Cybercrime Domain Score for each top level domain. Looking at the percentage of domains used for cybercrimes (some of which might have been compromised or hacked), the worst top level domains are .rest, .ooo, .tk, .cam, and .top, according to the report.
Earlier this year, Interisle reported a new trend in malicious domains: bad actors registering subdomains of popular free services to conduct attacks. 1.2 million subdomains were used in the attacks Inserisle analyzed.





The big question is where are the domains being registered?
by who
And which country
Can’t they trace by checking the credit cards???
Or you can pay cash to register domains???
“In one example, 17,000 malicious domains were registered in under 8 hours at one registrar.” What registrar and what are they doing to combat this? They are accepting the money for the registrations so they bear some responsibility, especially when mass registrations are indicative of potential cyber crime.
The report’s authors would agree that they should be doing something about this. It’s one of their recommendations.
If you look at the report you will see which registrars it detecting these bulk registrations at, as well as ones with outsized numbers of bulk registration domains being used for malicious activities.
While I appreciate that domain names can be used to host DNS Abuse, does the report mention anything about how the vast majority of this abusive content is shared via social media? The answer is no.
I’ve seen recent reporting that approximately 80% of abuse is spread via social media sites such as Facebook and Instagram, with viral posts that link to complicated URLs that would not be found otherwise. Five or ten years ago these links were spread by email so looking exclusively at domain names made sense, but as social media is the main driver now, we cannot ignore the 800 pound gorilla in the room as this report clearly does.
Tackling “bad stuff on the Internet” requires a holistic approach, not just going after domain name registrars.
I have some serious doubts about their methods of identifying what actually constitutes a malicious registration. Looking at their numbers I can identify that a significant number of domains they flagged as malicious are actually parked and monetized by reputable parking providers.
It seems that parked=malicious in this report, which throws serious doubts on the value of the conclusions it draws.
Also, it never really picks up on the most highly regulated ccTLD being the one with the most amount of abuse. Or the fact that the most highly abused domain .com is not really one of the cheapest. Or the fact that some of the least regulated and cheapest TLDs like .AT or .DE do not feature on their lists at all…
All in all this appears more like a propaganda piece to support the results they wanted to arrive at than serious research.
Indeed, the question of how people land on these sites is reduced to spam in this report, totally ignoring that the most prevalent delivery mechanism these days is actually social media. But pointing that out probably was not in the interests of the sponsors of this “study”.