Domain Abuse: 2021

Domain Abuse: 2021

Overview

The below statistics shows the advance fee fraud related domain abuse per quarter for 2021 as recorded by Artists Against 419. This records abuse by registrar and ccTLD, exposing the registrars and registries that are problematic and where malicious domains find a foothold to target internet consumers.

The details are broken down by Registrar and  TLD/ccTLDs/free sub-domains (previously called Domain Endings in our reports). We do a comparison of malicious domains. We list All Domains per entity vs Active Domains for 2020. It’s our contention that no consumer facing registrar can stop their services being abused. However they most certainly can, and should, mitigate malicious domains. As such the All vs Active comparison is indicative of a Registrar or Registry’s tolerance for fraud.

We include a cumulative malicious domain count column in the Active Domains, showing how many malicious domains were active in total at each Registrar / Registry by the end of 2021.

In a continuation from 2020, in 2021 the South African co.za ccTLD continued it’s pattern growing abuse to remain the second highest abused TLD/ccTLD, growing from 324 domains registered for the year, to 473. We break this anomaly down by registrar to highlight where this abuse came from.

Definitions Matter

The Artists Against 419 definition of a malicious domain is in line with the ICANN GAC and ICANN CCT definitions. We only list a domain name as malicious in incidents where the domain name was deliberately registered to defraud consumers.

ICANN GAC says the following in the ICANN 46 Beijing Communique:

the domain name registration is being used to facilitate or promote malware, operation of botnets, phishing, piracy, trademark or copyright infringement, fraudulent or deceptive practices, counterfeiting or otherwise engaging in activity contrary to applicable law.

https://gac.icann.org/advice/communiques/public/gac-46-beijing-communique.pdf

ICANN GAC also has this to say in a Sept 2019 statement on DNS Abuse:

Noting that ICANN community findings demonstrated that “consensus exists on what constitutes DNS Security Abuse, or DNS Security Abuse of DNS infrastructure,” the CCT Review Team referred to DNS Abuse as “intentionally deceptive, conniving, or unsolicited activities that actively make use of the DNS and/or the procedures used to register domain names.”

https://gac.icann.org/file-asset/public/gac-statement-dns-abuse-final-18sep19.pdf

Despite these clear plain language definitions, some registrars fail to honor these definitions, instead trying to define their own (rather self serving) abuse definitions. While the few mentioned abuse types are certainly valid, these limited definitions vs annual IC3 statistics show this disconnect. In turn this gaming leads to much consumer harm with such registrars facilitating cyber crime and money laundering through inaction, further overwhelming already constrained law enforcement resources.


Abuse by Registrar

Registrar Quarterly: 2021-01-01 to 2021-12-31 (All Domains)

RegistrarQ1:TotalQ2:TotalQ3:TotalQ4:TotalPeriod:Total
NAMECHEAP, INC.4196935224282062
NAMESILO, LLC25524235691944
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM243272170167852
OWNREGISTRAR, INC.3412318763407
HOSTING CONCEPTS B.V. DBA OPENPROVIDER141563619252
REGISTRAR OF DOMAIN NAMES REG.RU39124595227
GODADDY.COM, LLC60802517182
1API GMBH43284130142
NAME.COM, INC.70211618125
INTERNET DOMAIN SERVICE BS CORP3166515117
DOMAINS.CO.ZA33243519111
ENOM, INC.31302325109
HOSTKING.CO.ZA3129191089
DYNADOT, LLC323371385
TLD REGISTRAR SOLUTIONS LTD.39290270
INSTRA CORPORATION PTY LTD.1155865
FREE SUBDOMAIN1014121551
HOSTINGER, UAB21179451
ONLINENIC, INC.31625347
WEB COMMERCE COMMUNICATIONS LIMITED DBA WEBNIC.CC141511242
INSLYHOST.COM010181038
UPPERLINK LIMITED878831
CHENGDU WEST DIMENSION DIGITAL TECHNOLOGY CO., LTD.0003030
TUCOWS DOMAINS INC.9106530
1&1 INTERNET2223027
PORKBUN, LLC5621427
WILD WEST DOMAINS, LLC0161724
GANDI SAS0230023
SHINJIRU MSC SDN BHD477220
BIGROCK SOLUTIONS LTD2131117
WIX.COM LTD.225615
HOSTAFRICA335213
AXXESS DSL344112
NETEARTH ONE INC. D/B/A NETEARTH444012
SAV.COM, LLC035412
REGISTER DOMAIN SA512311
VEHOST.CO.ZA212611
WEB4AFRICA INC.133411
CENTER OF UKRAINIAN INTERNET NAMES DBA UKRNAMES180110
GOOGLE LLC241310
LAUNCHPAD.COM, INC.234110
ATAK TEKNOLOJI08019
EPAG DOMAINSERVICES GMBH43209
FASTDOMAIN INC.31329
101DOMAIN GRS LIMITED70108
ALIBABA CLOUD04408
NAMEWEB BVBA20068
DNSPOD, INC.01067
REGISTER.COM, INC.32207
WEBAFRICA NETWORKS14207
FREE DOMAIN14016
LIGNE WEB SERVICES SARL DBA LWS21036
NICENIC40026
REGIONAL NETWORK INFORMATION CENTER, JSC DBA RU-CENTER10506
AFRIHOST12115
CRAZY DOMAINS FZ-LLC11305
DREAMHOST, LLC00235
ERANET INTERNATIONAL LIMITED00145
MONIKER ONLINE SERVICES LLC00235
REGTIME LTD.00055
TRUEHOST CLOUD LIMITED00055
XNEELO (PTY) LTD02215
GRANSY S.R.O. D/B/A SUBREG.CZ00404
HOSTING CONCEPTS B.V. DBA OPENPROVIDER 40004
KEY-SYSTEMS GMBH30104
SA DOMAIN31004
123-REG LIMITED T/A 123-REG01023
ENDURANCE DOMAINS TECHNOLOGY PVT. LTD02103
GMO00033
IN2NET NETWORK INC.01023
PSI-USA, INC. DBA DOMAIN ROBOT01023
REGISTER.IT SPA10023
SYNERGY WHOLESALE PTY LTD00033
WEBSPACEBAR02103
ARUBA SPA00202
DANESCO TRADING LTD.01102
FRIKKADEL10102
INTERNET INVEST, LTD. DBA IMENA.UA11002
LIQUIDNET LTD.01012
NETWORK SOLUTIONS, LLC01102
NOTFOUND11002
SA WEBHOSTS00022
ZA DOMAINS11002
AMPLEHOSTING10001
ARSYS INTERNET, S.L. DBA NICLINE.COM10001
CHENGDU WEST DIMENSION DIGITAL TECHNOLOGY CO., LTD. 00011
CLOUD YUQU LLC00011
DENIC01001
DNSGULF.COM00011
DOMAIN.COM, LLC00101
DOMAINKING00101
GODADDY.COM, LLC 01001
HELLO INTERNET CORP.00101
HOSTING UKRAINE LLC01001
HOSTPINNACLE KENYA LIMITED00011
NETIM SARL01001
OPENTLD B.V.01001
OVH SAS00101
PORKBUN, LLC 01001
REALTIME REGISTER B.V.10001
REBEL LTD00101
STALLION HOSTING10001
URL SOLUTIONS, INC.01001
VAUTRON RECHENZENTRUM AG01001
WEB ADDRESS REGISTRATION00101

Back to top


Registrar Quarterly: 2021-01-01 to 2021-12-31 (Active Domains)

RegistrarQ1:ActiveQ2:ActiveQ3:ActiveQ4:ActivePeriod:ActiveCumulative Active
NAMECHEAP, INC.77159264223723890
OWNREGISTRAR, INC.07914759285285
NAMESILO, LLC41348246203210
REGISTRAR OF DOMAIN NAMES REG.RU3273375147180
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM101214109145149
HOSTING CONCEPTS B.V. DBA OPENPROVIDER49333418134153
1API GMBH34183130113135
ENOM, INC.26282324101170
INTERNET DOMAIN SERVICE BS CORP205951599118
GODADDY.COM, LLC3227151690198
DOMAINS.CO.ZA201533188691
HOSTKING.CO.ZA20241897187
INSTRA CORPORATION PTY LTD.015586467
DYNADOT, LLC18275126266
NAME.COM, INC.2181495266
TLD REGISTRAR SOLUTIONS LTD.1925024646
FREE SUBDOMAIN49101538166
INSLYHOST.COM01018103838
ONLINENIC, INC.1141923640
WEB COMMERCE COMMUNICATIONS LIMITED DBA WEBNIC.CC11131023652
HOSTINGER, UAB515643086
UPPERLINK LIMITED47882740
TUCOWS DOMAINS INC.58652464
WILD WEST DOMAINS, LLC016172430
PORKBUN, LLC332142228
GANDI SAS018001819
SHINJIRU MSC SDN BHD27621740
WIX.COM LTD.21561418
CHENGDU WEST DIMENSION DIGITAL TECHNOLOGY CO., LTD.000121213
SAV.COM, LLC03541212
HOSTAFRICA31521113
BIGROCK SOLUTIONS LTD0711911
EPAG DOMAINSERVICES GMBH4320923
VEHOST.CO.ZA012699
CENTER OF UKRAINIAN INTERNET NAMES DBA UKRNAMES1601810
NAMEWEB BVBA200688
ALIBABA CLOUD0430713
GOOGLE LLC2212715
LAUNCHPAD.COM, INC.2131715
1&1 INTERNET3120625
FASTDOMAIN INC.2031627
NETEARTH ONE INC. D/B/A NETEARTH1230620
NICENIC4002612
REGIONAL NETWORK INFORMATION CENTER, JSC DBA RU-CENTER105066
REGISTER DOMAIN SA012368
WEBAFRICA NETWORKS1320610
ATAK TEKNOLOJI040155
DNSPOD, INC.010455
DREAMHOST, LLC002357
ERANET INTERNATIONAL LIMITED001456
MONIKER ONLINE SERVICES LLC0023510
REGISTER.COM, INC.2210511
REGTIME LTD.000555
TRUEHOST CLOUD LIMITED000555
XNEELO (PTY) LTD022155
AXXESS DSL102145
CRAZY DOMAINS FZ-LLC013047
FREE DOMAIN120146
LIGNE WEB SERVICES SARL DBA LWS0103424
WEB4AFRICA INC.001347
123-REG LIMITED T/A 123-REG010233
AFRIHOST011134
ENDURANCE DOMAINS TECHNOLOGY PVT. LTD021033
GMO000333
GRANSY S.R.O. D/B/A SUBREG.CZ003038
IN2NET NETWORK INC.010233
KEY-SYSTEMS GMBH201033
SYNERGY WHOLESALE PTY LTD000333
ARUBA SPA002022
LIQUIDNET LTD.010122
NETWORK SOLUTIONS, LLC0110212
NOTFOUND110023
PSI-USA, INC. DBA DOMAIN ROBOT000223
REGISTER.IT SPA000222
SA WEBHOSTS000223
WEBSPACEBAR020023
ZA DOMAINS110022
101DOMAIN GRS LIMITED001013
ARSYS INTERNET, S.L. DBA NICLINE.COM100011
CHENGDU WEST DIMENSION DIGITAL TECHNOLOGY CO., LTD. 0001113
CLOUD YUQU LLC000111
DANESCO TRADING LTD.001013
DENIC010013
DNSGULF.COM000111
DOMAIN.COM, LLC001014
DOMAINKING001011
GODADDY.COM, LLC 01001198
HELLO INTERNET CORP.001011
HOSTING UKRAINE LLC010011
HOSTPINNACLE KENYA LIMITED000111
NETIM SARL010013
OPENTLD B.V.010011
PORKBUN, LLC 0100128
SA DOMAIN010011
URL SOLUTIONS, INC.010012
VAUTRON RECHENZENTRUM AG010011
WEB ADDRESS REGISTRATION001011
AMPLEHOSTING000003
FRIKKADEL000000
HOSTING CONCEPTS B.V. DBA OPENPROVIDER 00000153
INTERNET INVEST, LTD. DBA IMENA.UA000000
OVH SAS000004
REALTIME REGISTER B.V.000000
REBEL LTD000000
STALLION HOSTING000000

Back to top


Abuse by TLD, ccTLD and Free Sub-Domain

Domains by TLD: Quarterly 2021-01-01 to 2021-12-31 (All Domains)

Domain EndQ1:TotalQ2:TotalQ3:TotalQ4:TotalPeriod:Total
com1350166213158905217
co.za13411513688473
online37353376181
us4246495142
org20443326123
net19493220120
site3871937
co.uk9109230
xyz2106624
co478322
info238518
world385016
club392014
uk1120013
eu334212
biz162110
business.site22239
live14229
ca40228
shop01247
com.au12306
me04206
rest05106
blogspot.com31105
icu12115
ltd13105
space03205
website13105
wixsite.com01135
de31004
fit00044
weebly.com01124
zohosites.com02204
dx.am03003
es21003
in01113
nl00303
pw01203
store01023
tk03003
000webhostapp.com10012
cash02002
dog10012
exchange02002
legal00202
ml11002
ru.com00202
services00112
simplesite.com10012
tech00022
webnode.com01102
wordpress.com00022
work00022
yolasite.com00112
3-a.net00011
agency01001
autos00011
be01001
bid10001
buzz01001
c1.biz00101
cc00101
center00011
cf00011
checkout.webselfsite.net00101
cloud00011
co.in01001
co.ke00011
co.ua00101
com.ng00101
com.ua01001
delivery01001
digital01001
email10001
etempurl.com01001
express10001
ga01001
in.net01001
international10001
irish00101
jimdofree.com01001
mozello.de01001
one00101
otzo.com10001
pet01001
pl10001
sale01001
se00101
systems00101
top01001
usa.cc10001
webself.net00101
website2.me00011
webstarts.com10001
wiki00101
win00011

Back to top


Domains by TLD: Quarterly 2021-01-01 to 2021-12-31 (Active Domains)

Domain EndQ1:ActiveQ2:ActiveQ3:ActiveQ4:ActivePeriod:ActiveCumulative Active
com37960867766823323057
co.za808311987369439
net42415145793
us5211033947
org4812143868
online47482327
co.uk05621322
co24311013
eu1242914
info1233913
business.site1123713
club070077
live032166
shop002466
ca202157
wixsite.com0113525
xyz003255
biz021148
blogspot.com2110420
fit000444
weebly.com011247
es210034
zohosites.com021036
com.au002022
in011022
legal002022
ml110023
simplesite.com100122
site002024
webnode.com011025
wordpress.com0002218
yolasite.com0011210
000webhostapp.com000111
3-a.net000111
autos000111
be010011
center000111
cf000112
checkout.webselfsite.net001011
co.in010012
co.ke000111
co.ua001012
com.ng001012
de010015
delivery010011
digital010011
dx.am010013
ga010011
icu001011
irish001011
jimdofree.com010011
ltd010011
me001018
nl001013
pl100013
pw001011
ru.com001011
services001011
systems001011
tk010011
uk100011
webself.net001016
website001011
website2.me000111
work000111
agency000001
bid000000
buzz000000
c1.biz000000
cash000000
cc000000
cloud000000
com.ua000001
dog000000
email000000
etempurl.com000000
exchange000000
express000000
in.net000000
international000000
mozello.de000000
one000000
otzo.com000000
pet000000
rest000000
sale000000
se000004
space000000
store000000
tech000000
top000000
usa.cc000000
webstarts.com000000
wiki000000
win000000
world000000

com: Excludes blogspot.com 000webhostapp.com webstarts.com otzo.com simplesite.com zohosites.com etempurl.com webnode.com jimdofree.com wixsite.com weebly.com ru.com yolasite.com wordpress.com

net: Excludes in.net checkout.webselfsite.net webself.net 3-a.net

biz: Excludes c1.biz

uk: Excludes co.uk

site: Excludes business.site

ca: Excludes vps.ovh.ca

my: Excludes com.my

de: Excludes mozello.de

in: Excludes co.in

cc: Excludes usa.cc

Back to top


The co.za ccTLD Abuse

In 2020, the .co.za was the most the second most abused TLD/ccTLD after .com. These statistics show where the abuse occurred.

.co.za ccTLD Quarterly: 2021-01-01 to 2021-12-31 (All Domains)

RegistrarQ1:TotalQ2:TotalQ3:TotalQ4:TotalPeriod:Total
1API GMBH41273829135
DOMAINS.CO.ZA29243514102
HOSTKING.CO.ZA3129191089
INSLYHOST.COM010181038
HOSTAFRICA335213
AXXESS DSL344112
REGISTER DOMAIN SA512311
VEHOST.CO.ZA212611
EPAG DOMAINSERVICES GMBH43209
INSTRA CORPORATION PTY LTD.10247
WEBAFRICA NETWORKS14207
101DOMAIN GRS LIMITED60006
AFRIHOST12115
TRUEHOST CLOUD LIMITED00055
XNEELO (PTY) LTD02215
SA DOMAIN31004
WEBSPACEBAR02103
FRIKKADEL10102
SA WEBHOSTS00022
ZA DOMAINS11002
1&1 INTERNET00101
AMPLEHOSTING10001
HOSTING CONCEPTS B.V. DBA OPENPROVIDER01001
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM00101
STALLION HOSTING10001

.co.za ccTLD Quarterly: 2020-01-01 to 2020-12-31 (Active Domains)

RegistrarQ1:ActiveQ2:ActiveQ3:ActiveQ4:ActivePeriod:ActiveCumulative Active
1API GMBH32172829106122
DOMAINS.CO.ZA181533148085
HOSTKING.CO.ZA20241897187
INSLYHOST.COM01018103838
HOSTAFRICA31521113
EPAG DOMAINSERVICES GMBH4320922
VEHOST.CO.ZA012699
INSTRA CORPORATION PTY LTD.002467
REGISTER DOMAIN SA012368
WEBAFRICA NETWORKS1320610
TRUEHOST CLOUD LIMITED000555
XNEELO (PTY) LTD022155
AXXESS DSL102145
AFRIHOST011134
SA WEBHOSTS000223
WEBSPACEBAR020023
ZA DOMAINS110022
1&1 INTERNET001011
HOSTING CONCEPTS B.V. DBA OPENPROVIDER010014
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM001011
SA DOMAIN010011
101DOMAIN GRS LIMITED000001
AMPLEHOSTING000003
FRIKKADEL000000
STALLION HOSTING000000

Back to top


Note to registrars, registries and law enforcement

Artists Against 419 does not just say it, we can also prove it. We record numerous attributes for each entry in our database. While some of these are publicly visible at https://db.aa419.org, we record additional evidence of maliciousness. These includes website snapshots with embedded EXIF data, source code of interesting pages, email headers and/or linking data.

We appreciate outreach from any registrar and registry alike where they are keen to understand the nature of this maliciousness and wish to mitigate. You are the parties either abused or used as an entry point for this fraud on the web. The choice is yours to be part of the solution or the problem. Remember, these domains are purchased with the proceeds of fraud to facilitate further fraud.

We may mitigate till the cows come home to protect consumers, but you are the parties that ultimately stop this illegal abuse.

We do not charge any fees for such cooperation.

Back to top