Domain Abuse: 2023

Domain Abuse: 2023

Overview

The below statistics shows the advance fee fraud related domain abuse per quarter for 2023 as recorded by Artists Against 419. This records abuse per registrar and ccTLD, exposing the registrars and registries that are problematic and where malicious domains find a foothold to target internet consumers. The details are broken down by Registrar and TLD/ccTLDs/free sub-domains. We do a comparison of malicious domains. We list All Domains per entity vs Active Domains for 2023. It’s our contention that no consumer facing registrar can stop their services being abused. However they most certainly can, and should, mitigate malicious domains. As such the All vs Active comparison is indicative of a Registrar or Registry’s tolerance for fraud. We include a cumulative malicious domain count column in the Active Domains, showing how many malicious domains were active in total at each Registrar / Registry by the end of 2023.

In a continuation from previous years, the South African co.za ccTLD continued it’s pattern growing abuse to remain the second highest abused TLD/ccTLD, growing from 32 recorded malicious domains in 2017 to 637 in 2023. We break this anomaly down by registrar to highlight where this abuse came from.

Definitions Matter

The Artists Against 419 definition of a malicious domain is in line with the ICANN GAC, ICANN CCT and the European Commission definitions. We only list a domain name as malicious in incidents where the domain name was deliberately registered by a bad actor to defraud consumers.

ICANN GAC says the following in the ICANN 46 Beijing Communique:

the domain name registration is being used to facilitate or promote malware, operation of botnets, phishing, piracy, trademark or copyright infringement, fraudulent or deceptive practices, counterfeiting or otherwise engaging in activity contrary to applicable law.

https://gac.icann.org/advice/communiques/public/gac-46-beijing-communique.pdf

ICANN GAC also has this to say in a Sept 2019 statement on DNS Abuse:

Noting that ICANN community findings demonstrated that “consensus exists on what constitutes DNS Security Abuse, or DNS Security Abuse of DNS infrastructure,” the CCT Review Team referred to DNS Abuse as “intentionally deceptive, conniving, or unsolicited activities that actively make use of the DNS and/or the procedures used to register domain names.”

https://gac.icann.org/file-asset/public/gac-statement-dns-abuse-final-18sep19.pdf

From the European Commission, we find:

Domain Name System (DNS) abuse is any activity that makes use of domain names or the DNS protocol to carry out harmful or illegal activity.

European Commission, Directorate-General for Communications Networks, Content and Technology, Paulovics, I., Duda, A., Korczynski, M., Study on Domain Name System (DNS) abuse, Publications Office of the European Union, 2022, https://data.europa.eu/doi/10.2759/616244

Despite these clear plain language definitions, some registrars fail to honor these definitions, instead trying to define their own (rather self serving) abuse definitions. While the few mentioned abuse types recognized by a subsection of the registrar fraternity are certainly valid, these limited definitions vs annual IC3 statistics shows a disconnect. In turn this gaming leads to much consumer harm with such registrars facilitating cyber crime and money laundering through inaction, further overwhelming already constrained law enforcement resources. It’s also a known fact that many of these domain registrations are funded with stolen money.


Abuse by Registrar

Registrar Quarterly: 2023-01-01 to 2023-12-31 (All Domains)

RegistrarQ1:TotalQ2:TotalQ3:TotalQ4:TotalPeriod:Total
NAMESILO, LLC1613292592921041
NAMECHEAP, INC.322245234168969
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM948111364352
OWNREGISTRAR, INC.118806833299
1API GMBH77637950269
HOSTINGER, UAB51607581267
GODADDY.COM, LLC59624547213
WEB COMMERCE COMMUNICATIONS LIMITED DBA WEBNIC.CC6374756146
DYNADOT, LLC6574027130
INTERNET DOMAIN SERVICE BS CORP859011114
TUCOWS DOMAINS INC.11243147113
HOSTING CONCEPTS B.V. DBA OPENPROVIDER1318184897
DOMAINS.CO.ZA1937141585
GANDI SAS8616681
KEY-SYSTEMS GMBH1129221678
DOMAINSHYPE.COM, INC49001564
ENOM, INC.28971862
CRAZY DOMAINS FZ-LLC234191056
FREE SUBDOMAIN125122049
HOSTAFRICA181061347
DNS AFRICA LTD7266746
UPPERLINK LIMITED8331143
LAUNCHPAD.COM, INC.2023741
LIQUIDNET LTD.0004141
TRUEHOST CLOUD LIMITED111271141
NETEARTH ONE INC. D/B/A NETEARTH85121338
GRANSY S.R.O. D/B/A SUBREG.CZ21181637
ATAK TEKNOLOJI2533536
HOSTKING.CO.ZA13561236
REGISTER DOMAIN SA889732
NICENIC8741231
COSMOTOWN, INC.6138330
WHOGOHOST LIMITED8515230
NAME.COM, INC.7471028
GMO0217524
SA WEBHOSTS756624
FASTDOMAIN INC.2113622
REALTIME REGISTER B.V.905822
SHINJIRU MSC SDN BHD245819
INSTRA CORPORATION PTY LTD.337518
SA DOMAIN0311418
BIGROCK SOLUTIONS LTD319417
DREAMHOST, LLC741517
NETIM SARL184417
URL SOLUTIONS, INC.924116
LEXSYNERGY LIMITED1212015
WEB4AFRICA INC.752115
WILD WEST DOMAINS, LLC1311015
WIX.COM LTD.434415
PSI-USA, INC. DBA DOMAIN ROBOT005914
ERANET INTERNATIONAL LIMITED104813
1&1 INTERNET511512
VEHOST.CO.ZA115512
EPAG DOMAINSERVICES GMBH232310
PORKBUN, LLC442010
ONLINENIC, INC.50319
SAV.COM, LLC24028
WEBAFRICA NETWORKS51118
EPIK INC.43007
FRIKKADEL20136
NETWORK SOLUTIONS, LLC11136
ALIBABA CLOUD04015
MONIKER ONLINE SERVICES LLC10315
DNC HOLDINGS, INC.01124
FREE DOMAIN01304
GNAME.COM40004
HOSTPINNACLE KENYA LIMITED00404
CLOUDFLARE, INC.00303
DENIC11103
GLOBAL DOMAIN GROUP LLC00213
GOOGLE LLC20103
HALOWEB.CO.ZA00213
REG-ROUTEAFRICA10203
REGTIME LTD.03003
101DOMAIN GRS LIMITED00022
123-REG LIMITED T/A 123-REG01012
AMPLEHOSTING01102
CENTER OF UKRAINIAN INTERNET NAMES DBA UKRNAMES10012
DOMAIN.COM, LLC00022
DOMAINPEOPLE, INC.02002
IN2NET NETWORK INC.01012
MAFF INC.00022
ONE.COM A/S11002
RAPHUS LTD00022
REGISTRAR OF DOMAIN NAMES REG.RU10012
SQUARESPACE DOMAINS00022
TLD REGISTRAR SOLUTIONS LTD.00202
AFRIHOST01001
AXXESS DSL10001
BLACKNIGHT INTERNET SOLUTIONS LTD.10001
CV. RUMAHWEB INDONESIA00011
DANESCO TRADING LTD.00101
DDD TECHNOLOGY PTE. LTD.00101
GKG.NET, INC.00011
HELLO INTERNET CORP.00011
ICPS01001
INTERNET INVEST, LTD. DBA IMENA.UA00011
JIANGSU BANGNING TECHNOLOGY CO., LTD.00101
METAREGISTRAR BV00101
NIVACITY00101
REBEL LTD00101
RED.ES01001
REGIONAL NETWORK INFORMATION CENTER, JSC DBA RU-CENTER00101
REGISTER.COM, INC.00101
REGISTERAM.COM LIMITED00101
SPACESHIP, INC.01001
UA.REGERY00101
UKIT10001
VAUTRON RECHENZENTRUM AG10001
VEBONIX.COM00101

Back to top


Registrar Quarterly: 2023-01-01 to 2023-12-31 (Active Domains)

RegistrarQ1:ActiveQ2:ActiveQ3:ActiveQ4:ActivePeriod:ActiveCumulative Active
NAMESILO, LLC101211205264781909
NAMECHEAP, INC.52107141134434590
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM63598556263342
1API GMBH53577250232267
OWNREGISTRAR, INC.53506029192242
HOSTINGER, UAB26495362190215
GODADDY.COM, LLC35553843171252
WEB COMMERCE COMMUNICATIONS LIMITED DBA WEBNIC.CC6304255133170
DYNADOT, LLC4524024120134
INTERNET DOMAIN SERVICE BS CORP758911112128
HOSTING CONCEPTS B.V. DBA OPENPROVIDER1014134885136
TUCOWS DOMAINS INC.511214582127
GANDI SAS130646868
DOMAINS.CO.ZA83213126581
KEY-SYSTEMS GMBH6242185961
ENOM, INC.26861555116
FREE SUBDOMAIN113102044228
DNS AFRICA LTD624574242
DOMAINSHYPE.COM, INC2700154244
HOSTAFRICA1575134045
LAUNCHPAD.COM, INC.102374045
TRUEHOST CLOUD LIMITED10127114042
LIQUIDNET LTD.000373738
GRANSY S.R.O. D/B/A SUBREG.CZ1116153336
HOSTKING.CO.ZA1056123347
UPPERLINK LIMITED312212741
NICENIC534122435
GMO021552225
SA WEBHOSTS45662124
ATAK TEKNOLOJI140242022
COSMOTOWN, INC.49432027
FASTDOMAIN INC.001361936
REGISTER DOMAIN SA64541919
NAME.COM, INC.125101831
NETEARTH ONE INC. D/B/A NETEARTH34741825
REALTIME REGISTER B.V.60381718
SHINJIRU MSC SDN BHD23481741
URL SOLUTIONS, INC.92411617
SA DOMAIN011131516
WHOGOHOST LIMITED42811517
WILD WEST DOMAINS, LLC131101518
CRAZY DOMAINS FZ-LLC52341420
NETIM SARL05441313
WIX.COM LTD.43241322
BIGROCK SOLUTIONS LTD21541215
ERANET INTERNATIONAL LIMITED10381214
LEXSYNERGY LIMITED91201212
PSI-USA, INC. DBA DOMAIN ROBOT00571215
VEHOST.CO.ZA11551214
DREAMHOST, LLC24141113
EPAG DOMAINSERVICES GMBH23231042
1&1 INTERNET2115923
WEB4AFRICA INC.2420811
WEBAFRICA NETWORKS4111714
ONLINENIC, INC.3021612
SAV.COM, LLC040269
EPIK INC.320055
INSTRA CORPORATION PTY LTD.1301522
MONIKER ONLINE SERVICES LLC1031511
NETWORK SOLUTIONS, LLC011359
DNC HOLDINGS, INC.011245
FRIKKADEL201145
GNAME.COM400044
PORKBUN, LLC1120410
ALIBABA CLOUD0201315
GLOBAL DOMAIN GROUP LLC002133
HALOWEB.CO.ZA002133
REG-ROUTEAFRICA102033
101DOMAIN GRS LIMITED000224
123-REG LIMITED T/A 123-REG010122
AMPLEHOSTING011025
CLOUDFLARE, INC.002022
DOMAIN.COM, LLC000227
GOOGLE LLC101028
HOSTPINNACLE KENYA LIMITED002023
IN2NET NETWORK INC.010122
MAFF INC.000222
ONE.COM A/S110022
RAPHUS LTD000222
REGTIME LTD.020023
SQUARESPACE DOMAINS000222
TLD REGISTRAR SOLUTIONS LTD.0020210
AFRIHOST010013
CV. RUMAHWEB INDONESIA000111
DANESCO TRADING LTD.001012
DENIC010014
DOMAINPEOPLE, INC.010012
FREE DOMAIN001011
HELLO INTERNET CORP.000111
ICPS010014
INTERNET INVEST, LTD. DBA IMENA.UA000112
JIANGSU BANGNING TECHNOLOGY CO., LTD.001011
METAREGISTRAR BV001011
NIVACITY001011
REBEL LTD001011
RED.ES010011
REGIONAL NETWORK INFORMATION CENTER, JSC DBA RU-CENTER001011
REGISTER.COM, INC.0010110
REGISTERAM.COM LIMITED001011
REGISTRAR OF DOMAIN NAMES REG.RU000115
UKIT100011
VEBONIX.COM001011
AXXESS DSL000003
BLACKNIGHT INTERNET SOLUTIONS LTD.000000
CENTER OF UKRAINIAN INTERNET NAMES DBA UKRNAMES000003
DDD TECHNOLOGY PTE. LTD.000000
GKG.NET, INC.000000
SPACESHIP, INC.000000
UA.REGERY000000
VAUTRON RECHENZENTRUM AG000000

Back to top


Abuse by TLD, ccTLD and Free Sub-Domain

Domains by TLD: Quarterly 2023-01-01 to 2023-12-31 (All Domains)

Domain EndQ1:TotalQ2:TotalQ3:TotalQ4:TotalPeriod:Total
com9431020103510204018
co.za170157159151637
org54374355189
net29315418132
online2320242390
com.au203281869
co.uk66121741
us9931637
education0002828
de875121
wixsite.com534618
co545317
info236516
live166013
shop035311
store111811
university0001111
business.site102710
cc621110
site31408
me00347
blog02406
club05005
co.ke00505
eu02215
ltd04105
nl13004
sbs11114
uk20024
biz30003
cf00303
co.tz10203
es21003
icu20013
one00123
trade03003
weebly.com10113
world01113
yolasite.com10023
cfd20002
co.nz10012
dog10102
fr20002
in.net20002
nz00112
org.za10012
se00112
top10102
website00202
wordpress.com00022
xyz00202
zohosites.com00112
3-a.net00101
army00101
art00011
au00011
blogspot.com00101
bond00101
business00011
click01001
com 00101
com.ng00101
com.ua00101
company10001
es.tl10001
godaddysites.com01001
gold10001
help01001
homes10001
ink10001
international01001
io00011
jimdofree.com01001
kz01001
life01001
link01001
marketing01001
ml01001
mozello.com00101
net.cn00101
page.tl10001
pro10001
pw10001
report01001
services00011
sitebeat.crazydomains.com10001
su10001
tech10001
unaux.com00101
webnode.page00011
webs.com10001

Back to top


Domains by TLD: Quarterly 2023-01-01 to 2023-12-31 (Active Domains)

Domain EndQ1:ActiveQ2:ActiveQ3:ActiveQ4:ActivePeriod:ActiveCumulative Active
com45269982293829113823
co.za121137147141546677
org22263151130160
net1511481892131
education000282828
us562152845
co.uk236122332
wixsite.com53461847
live16601314
info02541115
university000111111
business.site10271023
co32321013
de23411018
shop0342913
cc411179
me0034717
blog024067
club050055
eu0221511
online1103514
co.ke003034
co.tz102033
es210033
weebly.com1011314
biz200026
fr200023
in.net200022
ltd011022
org.za100122
uk000223
wordpress.com0002223
world010122
xyz002022
yolasite.com0002214
zohosites.com001128
3-a.net001011
army001011
au000111
blogspot.com0010124
business000111
cf001011
click010011
com 001011
com.au000111
com.ng001013
dog001011
es.tl100011
help010011
icu000112
ink100011
kz010014
marketing010011
net.cn001011
nl010013
nz001011
page.tl100018
report010011
sbs001011
se000115
services000111
sitebeat.crazydomains.com100011
su100014
top100011
webnode.page000113
webs.com100014
art000000
bond000000
cfd000000
co.nz000000
com.ua000001
company000000
godaddysites.com000000
gold000000
homes000001
international000000
io000003
jimdofree.com000001
life000000
link000000
ml000000
mozello.com000000
one000000
pro000000
pw000000
site000001
store000000
tech000000
trade000000
unaux.com000000
website000000

Back to top


The co.za ccTLD Abuse

In 2023, the .co.za ccTLD was once again the second most abused TLD after .com. These statistics shows via which sponsoring registrar this abuse occurred.

.co.za ccTLD Quarterly: 2023-01-01 to 2023-12-31 (All Domains)

RegistrarQ1:TotalQ2:TotalQ3:TotalQ4:TotalPeriod:Total
1API GMBH73567746252
DOMAINS.CO.ZA1833141580
HOSTAFRICA181061347
TRUEHOST CLOUD LIMITED111261140
HOSTKING.CO.ZA13561236
REGISTER DOMAIN SA889732
SA WEBHOSTS756624
DNS AFRICA LTD646319
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM238518
SA DOMAIN0311317
DYNADOT, LLC076215
VEHOST.CO.ZA115512
EPAG DOMAINSERVICES GMBH232310
WEBAFRICA NETWORKS51118
FRIKKADEL20136
KEY-SYSTEMS GMBH02024
HALOWEB.CO.ZA00213
WEB4AFRICA INC.10113
1&1 INTERNET20002
AMPLEHOSTING01102
INSTRA CORPORATION PTY LTD.02002
RAPHUS LTD00022
AFRIHOST01001
AXXESS DSL10001
NIVACITY00101

.co.za ccTLD Quarterly: 2023-01-01 to 2023-12-31 (Active Domains)

RegistrarQ1:ActiveQ2:ActiveQ3:ActiveQ4:ActivePeriod:ActiveCumulative Active
1API GMBH51527246221254
DOMAINS.CO.ZA82813126175
HOSTAFRICA1575134044
TRUEHOST CLOUD LIMITED10126113941
HOSTKING.CO.ZA1056123347
SA WEBHOSTS45662124
REGISTER DOMAIN SA64541919
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM23851818
DNS AFRICA LTD52531515
DYNADOT, LLC07621515
SA DOMAIN011121415
VEHOST.CO.ZA11551214
EPAG DOMAINSERVICES GMBH23231041
WEBAFRICA NETWORKS4111714
FRIKKADEL201145
KEY-SYSTEMS GMBH020244
HALOWEB.CO.ZA002133
AMPLEHOSTING011025
INSTRA CORPORATION PTY LTD.020025
RAPHUS LTD000222
WEB4AFRICA INC.101023
AFRIHOST010013
NIVACITY001011
1&1 INTERNET000000
AXXESS DSL000003

It should be noted that these domains are used in ways that are at odds with South Africa’s laws, namely the Consumer Protection Act of 2008 and also the new newer Cyber Crimes Act of 2020. They are also used in ways prohibited by the registry’s own terms as reflected it it’s own Anti-Abuse and Takedown Policy.

Back to top


Note to registrars, registries and law enforcement

Artists Against 419 does not just say it, we can also prove it. We record numerous attributes for each entry in our database. While some of these are publicly visible at https://db.aa419.org, we record additional evidence of maliciousness. These includes website snapshots with embedded EXIF data, source code of interesting pages, email headers and/or linking data.

We appreciate outreach from any registrar and registry alike where they are keen to understand the nature of this maliciousness and wish to mitigate. You are the parties either abused or used as an entry point for this fraud on the web. We are more than happy to share data with you for mitigation purposes and we even have an API for you to use. The choice is yours to be part of the solution or the problem. Remember, these domains are purchased with the proceeds of fraud to facilitate further fraud.

We may mitigate till the cows come home to protect consumers, but you are the parties that ultimately stop this illegal abuse.

We do not charge any fees for such cooperation.

Back to top