Domain Abuse: 2022

Domain Abuse: 2022

Overview

The below statistics shows the advance fee fraud related domain abuse per quarter for 2022 as recorded by Artists Against 419. This records abuse per registrar and ccTLD, exposing the registrars and registries that are problematic and where malicious domains find a foothold to target internet consumers. The details are broken down by Registrar and TLD/ccTLDs/free sub-domains. We do a comparison of malicious domains. We list All Domains per entity vs Active Domains for 2022. It’s our contention that no consumer facing registrar can stop their services being abused. However they most certainly can, and should, mitigate malicious domains. As such the All vs Active comparison is indicative of a Registrar or Registry’s tolerance for fraud. We include a cumulative malicious domain count column in the Active Domains, showing how many malicious domains were active in total at each Registrar / Registry by the end of 2022.

In a continuation from previous years, the South African co.za ccTLD continued it’s pattern growing abuse to remain the second highest abused TLD/ccTLD, growing from 32 recorded malicious domains in 2017 to 555 in 2022. We break this anomaly down by registrar to highlight where this abuse came from.

Definitions Matter

The Artists Against 419 definition of a malicious domain is in line with the ICANN GAC and ICANN CCT definitions. We only list a domain name as malicious in incidents where the domain name was deliberately registered to defraud consumers.

ICANN GAC says the following in the ICANN 46 Beijing Communique:

the domain name registration is being used to facilitate or promote malware, operation of botnets, phishing, piracy, trademark or copyright infringement, fraudulent or deceptive practices, counterfeiting or otherwise engaging in activity contrary to applicable law.

https://gac.icann.org/advice/communiques/public/gac-46-beijing-communique.pdf

ICANN GAC also has this to say in a Sept 2019 statement on DNS Abuse:

Noting that ICANN community findings demonstrated that “consensus exists on what constitutes DNS Security Abuse, or DNS Security Abuse of DNS infrastructure,” the CCT Review Team referred to DNS Abuse as “intentionally deceptive, conniving, or unsolicited activities that actively make use of the DNS and/or the procedures used to register domain names.”

https://gac.icann.org/file-asset/public/gac-statement-dns-abuse-final-18sep19.pdf

Despite these clear plain language definitions, some registrars fail to honor these definitions, instead trying to define their own (rather self serving) abuse definitions. While the few mentioned abuse types are certainly valid, these limited definitions vs annual IC3 statistics show this disconnect. In turn this gaming leads to much consumer harm with such registrars facilitating cyber crime and money laundering through inaction, further overwhelming already constrained law enforcement resources. It’s also a known fact that many of these domain registrations are funded with stolen money.


Abuse by Registrar

Registrar Quarterly: 2022-01-01 to 2022-12-31 (All Domains)

RegistrarQ1:TotalQ2:TotalQ3:TotalQ4:TotalPeriod:Total
NAMECHEAP, INC.5713504183811720
NAMESILO, LLC89156137116498
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM15114468135498
OWNREGISTRAR, INC.59934763262
1API GMBH57325268209
GODADDY.COM, LLC18252829100
DOMAINS.CO.ZA126225393
HOSTING CONCEPTS B.V. DBA OPENPROVIDER2422341090
HOSTINGER, UAB138482089
WEB COMMERCE COMMUNICATIONS LIMITED DBA WEBNIC.CC191663576
REGISTER DOMAIN SA124615275
COSMOTOWN, INC.10591474
ENOM, INC.2512171569
TUCOWS DOMAINS INC.126271358
ALIBABA CLOUD14373155
DYNADOT, LLC85231652
DNS AFRICA LTD12911445
UPPERLINK LIMITED3462143
FREE SUBDOMAIN1169834
HOSTAFRICA05151333
INTERNET DOMAIN SERVICE BS CORP17141133
REGISTRAR OF DOMAIN NAMES REG.RU3210033
SHINJIRU MSC SDN BHD14151333
TRUEHOST CLOUD LIMITED46111132
ATAK TEKNOLOJI4224030
HOSTKING.CO.ZA5812530
VEHOST.CO.ZA1755128
NAME.COM, INC.9251127
FASTDOMAIN INC.3415123
LAUNCHPAD.COM, INC.0910322
BIGROCK SOLUTIONS LTD1321521
NETEARTH ONE INC. D/B/A NETEARTH3170121
NICENIC0313521
ONLINENIC, INC.1910121
WIX.COM LTD.645419
1&1 INTERNET2110316
PORKBUN, LLC391316
DREAMHOST, LLC472114
WHOGOHOST LIMITED006814
INSTRA CORPORATION PTY LTD.435113
101DOMAIN GRS LIMITED192012
123-REG LIMITED T/A 123-REG127212
WEB4AFRICA INC.363012
KEY-SYSTEMS GMBH224311
SA WEBHOSTS271111
SAV.COM, LLC503311
DENIC037010
GOOGLE LLC216110
EPAG DOMAINSERVICES GMBH13329
GMO33129
REALTIME REGISTER B.V.00279
CRAZY DOMAINS FZ-LLC01258
DOMAIN.COM, LLC21328
IN2NET NETWORK INC.24028
CENTER OF UKRAINIAN INTERNET NAMES DBA UKRNAMES30317
ERANET INTERNATIONAL LIMITED42107
GANDI SAS02136
NETIM SARL20406
AXXESS DSL23005
INSLYHOST.COM23005
LIQUIDNET LTD.03205
MIJN INTERNETOPLOSSING B.V.05005
MONIKER ONLINE SERVICES LLC00145
WEBAFRICA NETWORKS04015
35.COM00044
FE.RU00404
REGISTER.COM, INC.12014
CNOBIN INFORMATION TECHNOLOGY LIMITED20013
DANESCO TRADING LTD.02013
EPIK INC.00303
FRIKKADEL10023
ICPS00033
NETWORK SOLUTIONS, LLC21003
007NAMES, INC.00022
DNC HOLDINGS, INC.00112
ONE.COM A/S01102
PSI-USA, INC. DBA DOMAIN ROBOT00202
TLD REGISTRAR SOLUTIONS LTD.00202
URL SOLUTIONS, INC.00112
WILD WEST DOMAINS, LLC01102
XNEELO (PTY) LTD10012
AFRIHOST00101
AMPLEHOSTING00101
AUTOMATTIC INC.10001
BIZCN.COM, INC.00101
BOTTLE DOMAINS, INC.01001
CHENGDU WEST DIMENSION DIGITAL TECHNOLOGY CO., LTD.00011
DOMAINPEOPLE, INC.10001
DOMAINSHYPE.COM, INC00011
EURODNS S.A.01001
FREE DOMAIN10001
GRANSY S.R.O. D/B/A SUBREG.CZ01001
HOSTNOWNOW00101
INTERNET INVEST, LTD. DBA IMENA.UA00011
INWX GMBH & CO. KG00101
IVECLOUD10001
JIANGSU BANGNING SCIENCE AND TECHNOLOGY CO. LTD.00011
LIGNE WEB SERVICES SARL DBA LWS00101
NOTFOUND00011
R01-RU00101
REGTIME LTD.10001
SA DOMAIN00101
THE REGISTRY AT INFO AVENUE, LLC D/B/A SPIRIT COMMUNICATIONS10001
UA.IMENA10001
VAUTRON RECHENZENTRUM AG10001
WEBSPACEBAR01001
XIN NET TECHNOLOGY CORPORATION00101
ZA DOMAINS01001

Back to top


Registrar Quarterly: 2022-01-01 to 2022-12-31 (Active Domains)

RegistrarQ1:ActiveQ2:ActiveQ3:ActiveQ4:ActivePeriod:ActiveCumulative Active
NAMECHEAP, INC.172106182182642908
NAMESILO, LLC48125127112412511
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM556860126309342
OWNREGISTRAR, INC.22663563186286
1API GMBH29294863169199
DOMAINS.CO.ZA45205180100
HOSTINGER, UAB77461979137
COSMOTOWN, INC.0059137272
GODADDY.COM, LLC715172867179
WEB COMMERCE COMMUNICATIONS LIMITED DBA WEBNIC.CC14145346785
HOSTING CONCEPTS B.V. DBA OPENPROVIDER151622861109
ENOM, INC.1511151556128
DNS AFRICA LTD1281144446
DYNADOT, LLC2422154361
ALIBABA CLOUD1122213640
HOSTAFRICA0515133335
TUCOWS DOMAINS INC.5513103380
FREE SUBDOMAIN868830191
TRUEHOST CLOUD LIMITED4311112932
INTERNET DOMAIN SERVICE BS CORP1313112860
HOSTKING.CO.ZA271142445
NAME.COM, INC.614112243
FASTDOMAIN INC.241211937
NICENIC021251931
SHINJIRU MSC SDN BHD68131834
ATAK TEKNOLOJI111401616
BIGROCK SOLUTIONS LTD81141415
LAUNCHPAD.COM, INC.06531418
NETEARTH ONE INC. D/B/A NETEARTH112011420
WIX.COM LTD.43341421
REGISTER DOMAIN SA09311317
1&1 INTERNET20731233
WHOGOHOST LIMITED00481213
SA WEBHOSTS27111113
DREAMHOST, LLC34211012
KEY-SYSTEMS GMBH21431018
EPAG DOMAINSERVICES GMBH1332934
ONLINENIC, INC.7101917
REALTIME REGISTER B.V.0027913
123-REG LIMITED T/A 123-REG105288
DENIC035089
WEB4AFRICA INC.1430815
GOOGLE LLC0151711
SAV.COM, LLC2032712
VEHOST.CO.ZA222178
IN2NET NETWORK INC.130266
PORKBUN, LLC0402613
UPPERLINK LIMITED2121623
CENTER OF UKRAINIAN INTERNET NAMES DBA UKRNAMES1031512
DOMAIN.COM, LLC210258
INSTRA CORPORATION PTY LTD.0140530
LIQUIDNET LTD.032055
MIJN INTERNETOPLOSSING B.V.050055
MONIKER ONLINE SERVICES LLC0014511
35.COM000444
ERANET INTERNATIONAL LIMITED310045
FE.RU004044
NETIM SARL004045
REGISTRAR OF DOMAIN NAMES REG.RU4000428
WEBAFRICA NETWORKS0301416
101DOMAIN GRS LIMITED021035
AXXESS DSL120035
CRAZY DOMAINS FZ-LLC0003322
EPIK INC.003033
GANDI SAS011136
GMO110134
ICPS000333
REGISTER.COM, INC.1101312
007NAMES, INC.000222
DANESCO TRADING LTD.010122
DNC HOLDINGS, INC.001123
FRIKKADEL000222
TLD REGISTRAR SOLUTIONS LTD.0020216
URL SOLUTIONS, INC.001123
XNEELO (PTY) LTD100126
AFRIHOST001012
AMPLEHOSTING001014
AUTOMATTIC INC.100011
BIZCN.COM, INC.001011
BOTTLE DOMAINS, INC.010010
CHENGDU WEST DIMENSION DIGITAL TECHNOLOGY CO., LTD.000111
DOMAINSHYPE.COM, INC000112
EURODNS S.A.010012
FREE DOMAIN100016
HOSTNOWNOW001010
INSLYHOST.COM100012
INTERNET INVEST, LTD. DBA IMENA.UA000111
INWX GMBH & CO. KG001011
JIANGSU BANGNING SCIENCE AND TECHNOLOGY CO. LTD.000112
LIGNE WEB SERVICES SARL DBA LWS0010110
NETWORK SOLUTIONS, LLC010016
NOTFOUND000112
ONE.COM A/S010011
R01-RU001011
SA DOMAIN001011
UA.IMENA100011
WILD WEST DOMAINS, LLC0010110
XIN NET TECHNOLOGY CORPORATION001011
CNOBIN INFORMATION TECHNOLOGY LIMITED000000
DOMAINPEOPLE, INC.000000
GRANSY S.R.O. D/B/A SUBREG.CZ000005
IVECLOUD000000
PSI-USA, INC. DBA DOMAIN ROBOT000001
REGTIME LTD.000001
THE REGISTRY AT INFO AVENUE, LLC D/B/A SPIRIT COMMUNICATIONS000000
VAUTRON RECHENZENTRUM AG000000
WEBSPACEBAR000000
ZA DOMAINS000000

Back to top


Abuse by TLD, ccTLD and Free Sub-Domain

Domains by TLD: Quarterly 2022-01-01 to 2022-12-31 (All Domains)

Domain EndQ1:TotalQ2:TotalQ3:TotalQ4:TotalPeriod:Total
com10459239258523745
co.za117134145159555
org43313021125
online2820261488
net2218201272
us11315837
co.uk1074930
de2416628
com.au2111822
shop247922
info2311218
co224614
store106613
xyz360110
site12328
cc03137
eu33107
live00617
biz13015
weebly.com30115
se00404
su00404
world13004
blogspot.com10023
business.site02103
icu10203
in02103
kz00033
uk11103
wixsite.com00123
wordpress.com30003
zohosites.com10113
com.ng00112
delivery10102
epizy.com00202
homes00112
ltd10102
monster20002
nl11002
site123.me00112
support20002
tech11002
webnode.page01012
yolasite.com11002
ae01001
best01001
br.com00101
cash10001
charity10001
cn00101
co.com01001
com.ua10001
company.site00101
dog00101
email01001
farm10001
fund10001
ga00101
group00011
life00011
ml10001
net.in10001
org.za10001
pl00011
ru00101
space10001
top01001
trycloudflare.com10001
ueniweb.com01001
webflow.io01001
webnode.com10001
x10.bz00101

Back to top


Domains by TLD: Quarterly 2022-01-01 to 2022-12-31 (Active Domains)

Domain EndQ1:ActiveQ2:ActiveQ3:ActiveQ4:ActivePeriod:ActiveCumulative Active
com39051863064521833267
co.za4875123150396530
org1215201865104
net13816946102
online0416113146
de141342230
co.uk44392030
us51941941
info12921416
shop01391313
store0045910
co0124710
live006177
eu3210611
biz130159
se004048
site011246
su004044
weebly.com2011411
blogspot.com1002323
business.site0210313
com.au0003318
in021036
kz000333
wixsite.com0012332
wordpress.com3000321
zohosites.com101136
cc000222
com.ng001124
homes001123
site123.me001127
support200022
webnode.page010122
yolasite.com1100212
ae010011
br.com001011
cash100011
charity100011
cn001011
com.ua100012
company.site001011
delivery001011
dog001011
epizy.com001011
farm100011
fund100011
ga001012
group000111
icu001012
life000111
ml100013
nl010014
pl000113
ru001011
ueniweb.com010011
uk010011
webflow.io010011
world010011
x10.bz001011
xyz010011
best000000
co.com000000
email000000
ltd000000
monster000000
net.in000000
org.za000001
space000000
tech000000
top000001
trycloudflare.com000000
webnode.com000005

com: Excludes zohosites.com wordpress.com yolasite.com weebly.com trycloudflare.com webnode.com blogspot.com co.com ueniweb.com epizy.com wixsite.com br.com 

uk: Excludes co.uk

site: Excludes business.site company.site 

in: Excludes net.in

Back to top


The co.za ccTLD Abuse

In 2022, the .co.za ccTLD was once again the second most abused TLD after .com. These statistics shows via which sponsoring registrar this abuse occurred.

.co.za ccTLD Quarterly: 2022-01-01 to 2022-12-31 (All Domains)

RegistrarQ1:TotalQ2:TotalQ3:TotalQ4:TotalPeriod:Total
1API GMBH55314867201
DOMAINS.CO.ZA114164980
REGISTER DOMAIN SA124615275
HOSTAFRICA05151333
TRUEHOST CLOUD LIMITED46111132
HOSTKING.CO.ZA5812530
VEHOST.CO.ZA1755128
SA WEBHOSTS271111
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM045110
EPAG DOMAINSERVICES GMBH13329
1&1 INTERNET11608
AXXESS DSL23005
INSLYHOST.COM23005
INSTRA CORPORATION PTY LTD.22105
WEBAFRICA NETWORKS04015
DNS AFRICA LTD00134
FRIKKADEL10023
WEB4AFRICA INC.00202
XNEELO (PTY) LTD10012
AFRIHOST00101
AMPLEHOSTING00101
GANDI SAS00101
IVECLOUD10001
SA DOMAIN00101
WEBSPACEBAR01001
ZA DOMAINS01001

.co.za ccTLD Quarterly: 2022-01-01 to 2022-12-31 (Active Domains)

RegistrarQ1:ActiveQ2:ActiveQ3:ActiveQ4:ActivePeriod:ActiveCumulative Active
1API GMBH29284662165192
DOMAINS.CO.ZA4314476886
HOSTAFRICA0515133335
TRUEHOST CLOUD LIMITED4311112932
HOSTKING.CO.ZA271142445
REGISTER DOMAIN SA09311317
SA WEBHOSTS27111113
EPAG DOMAINSERVICES GMBH1332933
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM024177
VEHOST.CO.ZA222178
1&1 INTERNET105066
DNS AFRICA LTD001346
WEBAFRICA NETWORKS0301416
AXXESS DSL120035
FRIKKADEL000222
INSTRA CORPORATION PTY LTD.011025
WEB4AFRICA INC.002022
XNEELO (PTY) LTD100126
AFRIHOST001012
AMPLEHOSTING001014
GANDI SAS001011
INSLYHOST.COM100012
SA DOMAIN001011
IVECLOUD000000
WEBSPACEBAR000000
ZA DOMAINS000000

Back to top


Note to registrars, registries and law enforcement

Artists Against 419 does not just say it, we can also prove it. We record numerous attributes for each entry in our database. While some of these are publicly visible at https://db.aa419.org, we record additional evidence of maliciousness. These includes website snapshots with embedded EXIF data, source code of interesting pages, email headers and/or linking data.

We appreciate outreach from any registrar and registry alike where they are keen to understand the nature of this maliciousness and wish to mitigate. You are the parties either abused or used as an entry point for this fraud on the web. The choice is yours to be part of the solution or the problem. Remember, these domains are purchased with the proceeds of fraud to facilitate further fraud.

We may mitigate till the cows come home to protect consumers, but you are the parties that ultimately stop this illegal abuse.

We do not charge any fees for such cooperation.

Back to top