Domain Abuse: 2024

Domain Abuse: 2024

Overview

The below statistics shows the advance fee fraud related domain abuse per quarter for 2024 as recorded by Artists Against 419. This records abuse per registrar and ccTLD, exposing the registrars and registries that are problematic and where malicious domains find a foothold to target internet consumers. The details are broken down by Registrar and TLD/ccTLDs/free sub-domains. We do a comparison of malicious domains. We list All Domains per entity vs Active Domains for 2024. It’s our contention that no consumer facing registrar or registry can stop their services being abused. However they most certainly can, and should, mitigate malicious domains. As such the All vs Active comparison is indicative of a Registrar or Registry’s tolerance for fraud. We include a cumulative malicious domain count column in the Active Domains, showing how many malicious domains were active in total at each Registrar / Registry by the end of 2024.

The Australian Domain Name Authority (auDA) set a commendable example in 2024 by effectively protecting their registry from abuse. We recorded 73 abuse attempts, none of which remained online for more than a working day after being reported. One absusive domain was suspened in less than five hours on a Saturday! This swift action highlights auDA’s dedication to maintaining a secure and trustworthy domain environment for Australians.

In a continuation from previous years, the South African co.za ccTLD continued it’s pattern growing abuse to remain the second highest abused TLD/ccTLD, growing from 32 recorded malicious domains in 2017 to 637 in 2023, with a slight drop to 597 in 2024. We break this anomaly down by registrar to highlight where this abuse came from.

Definitions Matter

The Artists Against 419 definition of a malicious domain is in line with the ICANN GAC, ICANN CCT and the European Commission definitions. We only list a domain name as malicious in incidents where the domain name was deliberately registered by a bad actor to defraud consumers.

ICANN GAC says the following in the ICANN 46 Beijing Communique:

the domain name registration is being used to facilitate or promote malware, operation of botnets, phishing, piracy, trademark or copyright infringement, fraudulent or deceptive practices, counterfeiting or otherwise engaging in activity contrary to applicable law.

https://gac.icann.org/advice/communiques/public/gac-46-beijing-communique.pdf

ICANN GAC also has this to say in a Sept 2019 statement on DNS Abuse:

Noting that ICANN community findings demonstrated that “consensus exists on what constitutes DNS Security Abuse, or DNS Security Abuse of DNS infrastructure,” the CCT Review Team referred to DNS Abuse as “intentionally deceptive, conniving, or unsolicited activities that actively make use of the DNS and/or the procedures used to register domain names.”

https://gac.icann.org/file-asset/public/gac-statement-dns-abuse-final-18sep19.pdf

From the European Commission, we find:

Domain Name System (DNS) abuse is any activity that makes use of domain names or the DNS protocol to carry out harmful or illegal activity.

European Commission, Directorate-General for Communications Networks, Content and Technology, Paulovics, I., Duda, A., Korczynski, M., Study on Domain Name System (DNS) abuse, Publications Office of the European Union, 2022, https://data.europa.eu/doi/10.2759/616244

Despite these clear plain language definitions, some registrars fail to honor these definitions, instead trying to define their own (rather self serving) abuse definitions. While the few mentioned abuse types recognized by a subsection of the registrar fraternity are certainly valid, these limited definitions vs annual IC3 statistics shows a disconnect. In turn this gaming leads to much consumer harm with such registrars facilitating cyber crime and money laundering through inaction, further overwhelming already constrained law enforcement resources. It’s also a known fact that many of these domain registrations are funded with stolen money.


Abuse by Registrar

Registrar Quarterly: 2024-01-01 to 2024-12-31 (All Domains)

RegistrarQ1:TotalQ2:TotalQ3:TotalQ4:TotalPeriod:Total
NAMESILO, LLC172258222111763
HOSTINGER, UAB116145144197602
NAMECHEAP, INC.114143121107485
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM1161186887389
1API GMBH66699146272
WEB COMMERCE COMMUNICATIONS LIMITED DBA WEBNIC.CC66295299246
OWNREGISTRAR, INC.45816053239
COSMOTOWN, INC.40953846219
GODADDY.COM, LLC52635543213
DYNADOT, LLC4332975177
HOSTING CONCEPTS B.V. DBA OPENPROVIDER46703427177
TUCOWS DOMAINS INC.33392719118
ONLINENIC, INC.4751107115
GMO22272238109
HOSTAFRICA1823253096
WEST263 INTERNATIONAL LIMITED2229261390
REALTIME REGISTER B.V.1626231681
ATAK TEKNOLOJI33672470
GLOBAL DOMAIN GROUP LLC44712669
NAME.COM, INC.52724359
FREE SUBDOMAIN1510171355
WILD WEST DOMAINS, LLC1018111554
PSI-USA, INC. DBA DOMAIN ROBOT22143342
TRUEHOST CLOUD LIMITED111131742
GNAME.COM2826541
INSTRA CORPORATION PTY LTD.14581138
KEY-SYSTEMS GMBH15154438
DREAMHOST, LLC16163237
BIGROCK SOLUTIONS LTD8381433
SA WEBHOSTS13251333
NICENIC1384732
ENOM, INC.599730
GRANSY S.R.O. D/B/A SUBREG.CZ15401130
WHOGOHOST LIMITED6511527
SA DOMAIN7215226
CRAZY DOMAINS FZ-LLC974525
UPPERLINK LIMITED2173325
NETEARTH ONE INC. D/B/A NETEARTH2111124
NETWORK SOLUTIONS, LLC2710322
DOMAINS.CO.ZA564520
SAV.COM, LLC284620
FRIKKADEL3313019
INTERNET DOMAIN SERVICE BS CORP663217
NAME SRS AB433717
SHINJIRU MSC SDN BHD1151017
WIX.COM LTD.334616
GANDI SAS2130015
NETIM SARL541515
ZACR735015
METAREGISTRAR BV531514
SPACESHIP, INC.131914
ERANET INTERNATIONAL LIMITED1003013
INWX GMBH222713
TLD REGISTRAR SOLUTIONS LTD.1102013
ALIBABA CLOUD0111012
DOMAINSHYPE.COM, INC037111
SQUARESPACE DOMAINS214411
LAUNCHPAD.COM, INC.810110
LIGNE WEB SERVICES SARL DBA LWS009110
RAPHUS LTD243110
1&1 INTERNET43119
HOSTKING.CO.ZA24219
ONE.COM A/S05218
VEBONIX.COM01348
PORKBUN, LLC13217
WEBSPACEBAR25007
CLOUDFLARE, INC.20226
INSLYHOST.COM21216
EPAG DOMAINSERVICES GMBH01225
FASTDOMAIN INC.20215
LINK, FOR TECHNOLOGY & GENERAL TRADING LTD.00055
REGIONAL NETWORK INFORMATION CENTER, JSC DBA RU-CENTER00505
123-REG LIMITED T/A 123-REG04004
CENTER OF UKRAINIAN INTERNET NAMES DBA UKRNAMES31004
DNS AFRICA LTD12014
DOMAIN.COM, LLC20103
HELLO INTERNET CORP.30003
HOSTPINNACLE KENYA LIMITED00303
JOKER.COM21003
LIQUIDNET LTD.11103
REGISTER DOMAIN SA01113
VEHOST.CO.ZA20103
WEB4AFRICA INC.01113
AXXESS DSL10102
CV. JOGJACAMP10102
DENIC10102
DNSPOD, INC.00022
HALOWEB.CO.ZA20002
KOUMING10102
MONIKER ONLINE SERVICES LLC01012
REGISTER.COM, INC.20002
TONIC.TO10012
WEBAFRICA NETWORKS00202
ZA DOMAINS20002
AFRIHOST10001
ARUBA SPA00101
BIZCN.COM, INC.00011
CNOBIN INFORMATION TECHNOLOGY LIMITED10001
COMBELL00011
DANESCO TRADING LTD.00101
DDD TECHNOLOGY PTE. LTD.00101
DIGITALBES00011
EASYDNS TECHNOLOGIES, INC.10001
EPIK INC.01001
EURODNS S.A.10001
GKG.NET, INC.10001
HOGANHOST.COM.NG01001
HOSTNOWNOW00011
HOSTOPIA CANADA CORP.10001
ICENETWORKS10001
INTERNET INVEST, LTD. DBA IMENA.UA01001
INTERNETX GMBH00011
KENYAWEBEXPERTS.CO.KE01001
LCN.COM LTD00011
NETCETERA00101
NETREGISTRY WHOLESALE PTY LTD00011
NUXIT00011
ONLINE SAS00101
OVH SAS00011
PAKNIC (PRIVATE) LIMITED01001
PLANETHOSTER INC.00101
PURPLE IT LTD01001
REGISTER S.P.A.10001
REGISTER.IT SPA10001
REGISTRAR OF DOMAIN NAMES REG.RU10001
REGISTRAR.EU01001
ROUTE AFRICA00101
SAREK OY00101
SYNERGY WHOLESALE ACCREDITATIONS00101
URL SOLUTIONS, INC.10001
VERPEX LTD01001
WEBMANAGER.NG01001

Back to top


Registrar Quarterly: 2024-01-01 to 2024-12-31 (Active Domains)

RegistrarQ1:ActiveQ2:ActiveQ3:ActiveQ4:ActivePeriod:ActiveCumulative Active
NAMESILO, LLC9321819994604851
HOSTINGER, UAB49106113161429486
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM37856075257369
NAMECHEAP, INC.29528885254395
1API GMBH29507540194238
WEB COMMERCE COMMUNICATIONS LIMITED DBA WEBNIC.CC33174882180246
OWNREGISTRAR, INC.15615048174251
COSMOTOWN, INC.27583545165173
GODADDY.COM, LLC27424839156236
HOSTING CONCEPTS B.V. DBA OPENPROVIDER27583026141199
DYNADOT, LLC1923875134169
GMO82221358695
HOSTAFRICA132023308689
TUCOWS DOMAINS INC.2122111569119
REALTIME REGISTER B.V.102218156566
ONLINENIC, INC.533955256
WILD WEST DOMAINS, LLC81810155162
FREE SUBDOMAIN128171350253
NAME.COM, INC.3222124862
WEST263 INTERNATIONAL LIMITED5102194545
GLOBAL DOMAIN GROUP LLC1671053838
TRUEHOST CLOUD LIMITED0912173845
ATAK TEKNOLOJI1175133644
DREAMHOST, LLC1015212831
NICENIC125372737
ENOM, INC.48862680
SA WEBHOSTS423132227
UPPERLINK LIMITED017322239
WHOGOHOST LIMITED431142230
NETWORK SOLUTIONS, LLC26932029
BIGROCK SOLUTIONS LTD31691923
SAV.COM, LLC28361921
FRIKKADEL321301819
GRANSY S.R.O. D/B/A SUBREG.CZ520101731
KEY-SYSTEMS GMBH45441733
WIX.COM LTD.32461526
ZACR73501515
DOMAINS.CO.ZA15351431
SHINJIRU MSC SDN BHD103101440
INTERNET DOMAIN SERVICE BS CORP45221363
NETEARTH ONE INC. D/B/A NETEARTH111011319
GANDI SAS012001236
NAME SRS AB20371212
GNAME.COM11631111
CRAZY DOMAINS FZ-LLC43121014
ERANET INTERNATIONAL LIMITED80201015
INWX GMBH01271011
SPACESHIP, INC.01181010
1&1 INTERNET4311922
DOMAINSHYPE.COM, INC0351924
SQUARESPACE DOMAINS1134911
HOSTKING.CO.ZA2321826
LIGNE WEB SERVICES SARL DBA LWS0071811
METAREGISTRAR BV120477
NETIM SARL210478
ONE.COM A/S052078
VEBONIX.COM003477
INSLYHOST.COM212166
PSI-USA, INC. DBA DOMAIN ROBOT1410610
TLD REGISTRAR SOLUTIONS LTD.042069
CLOUDFLARE, INC.102255
EPAG DOMAINSERVICES GMBH0122546
FASTDOMAIN INC.2021517
LINK, FOR TECHNOLOGY & GENERAL TRADING LTD.000555
PORKBUN, LLC0221510
RAPHUS LTD122056
REGIONAL NETWORK INFORMATION CENTER, JSC DBA RU-CENTER005056
SA DOMAIN211159
ALIBABA CLOUD021037
HELLO INTERNET CORP.300034
LAUNCHPAD.COM, INC.200134
WEB4AFRICA INC.011136
AXXESS DSL101023
CENTER OF UKRAINIAN INTERNET NAMES DBA UKRNAMES110024
CV. JOGJACAMP101022
DENIC101024
DNSPOD, INC.000223
DOMAIN.COM, LLC101027
JOKER.COM110022
LIQUIDNET LTD.011024
MONIKER ONLINE SERVICES LLC010128
REGISTER DOMAIN SA010122
TONIC.TO100122
VEHOST.CO.ZA1010210
WEBAFRICA NETWORKS002026
ZA DOMAINS200022
ARUBA SPA001011
BIZCN.COM, INC.000111
COMBELL000111
DANESCO TRADING LTD.001011
DDD TECHNOLOGY PTE. LTD.001011
DIGITALBES000111
EASYDNS TECHNOLOGIES, INC.100011
EPIK INC.010013
HALOWEB.CO.ZA100011
HOGANHOST.COM.NG010011
HOSTNOWNOW000111
HOSTOPIA CANADA CORP.100011
HOSTPINNACLE KENYA LIMITED001012
ICENETWORKS100011
INSTRA CORPORATION PTY LTD.1000112
INTERNET INVEST, LTD. DBA IMENA.UA010013
INTERNETX GMBH000111
KENYAWEBEXPERTS.CO.KE010011
KOUMING001011
NETREGISTRY WHOLESALE PTY LTD000111
NUXIT000111
ONLINE SAS001011
PAKNIC (PRIVATE) LIMITED010011
PLANETHOSTER INC.001011
REGISTRAR OF DOMAIN NAMES REG.RU100012
REGISTRAR.EU010011
ROUTE AFRICA001011
SAREK OY001011
URL SOLUTIONS, INC.100011
VERPEX LTD010011
123-REG LIMITED T/A 123-REG000000
AFRIHOST000001
CNOBIN INFORMATION TECHNOLOGY LIMITED000000
DNS AFRICA LTD000004
EURODNS S.A.000001
GKG.NET, INC.000000
LCN.COM LTD000000
NETCETERA000000
OVH SAS000001
PURPLE IT LTD000000
REGISTER S.P.A.000000
REGISTER.COM, INC.000007
REGISTER.IT SPA000000
SYNERGY WHOLESALE ACCREDITATIONS000000
WEBMANAGER.NG000000
WEBSPACEBAR000000

Back to top


Abuse by TLD, ccTLD and Free Sub-Domain

Domains by TLD: Quarterly 2024-01-01 to 2024-12-31 (All Domains)

Domain EndQ1:TotalQ2:TotalQ3:TotalQ4:TotalPeriod:Total
com106812389818584145
co.za136133187141597
org49763846209
online21352920105
us3718181487
net3123161484
com.au1913221973
shop71513843
co.uk12116736
wixsite.com55121133
de7113728
info3108627
store2104723
education1160017
pro1211014
eu432413
live252413
co222612
sbs0001212
uk205411
xyz242210
site01618
es12407
ca22116
top10416
icu01045
biz13004
cc10124
co.ke01304
nl01214
weebly.com12104
com.ng02013
delivery10113
tech03003
wordpress.com20103
au00202
blog11002
business.site20002
cfd00202
company.site10102
epizy.com01102
farm00022
foundation00112
in10102
to10012
vip01102
webflow.io01012
webnode.page10102
website00112
army00101
at01001
bond00101
buzz10001
capital00101
cloud10001
club00101
cn00101
co.in10001
co.tz00101
email00011
energy01001
expert10001
fr00101
group00101
in.net01001
institute00101
is10001
jp00011
la00101
lease01001
life00101
ltd00011
mailchimpsites.com10001
net.ng01001
onrender.com01001
org.za10001
pw10001
ru00101
se00011
services01001
space00101
uk.com00101
ukit.me00011
university01001
webnode.fr10001
websites.co.in10001

Back to top


Domains by TLD: Quarterly 2024-01-01 to 2024-12-31 (Active Domains)

Domain EndQ1:ActiveQ2:ActiveQ3:ActiveQ4:ActivePeriod:ActiveCumulative Active
com46285786876829554213
co.za66100148133447608
org25503135141185
net1617141259106
us12131394761
online1519814351
wixsite.com5512113379
shop39862626
de69372534
info25751923
co.uk38251827
education014001430
pro111101313
eu23241115
co02261014
live0423912
es014056
store003255
top004155
uk002357
cc1012411
nl012145
weebly.com1210416
biz030038
delivery101133
tech030033
business.site2000220
ca010122
co.ke011023
com.ng010122
company.site101023
in101023
site011022
to100122
vip011022
webflow.io010123
webnode.page101024
wordpress.com1010224
army001011
at010011
blog010012
capital001011
club001011
cn001012
co.in100011
co.tz001011
email000111
epizy.com001011
farm000111
foundation000111
fr001012
group001011
icu010012
in.net010013
is100012
jp000111
la001011
lease010011
life001011
ltd000111
net.ng010011
org.za100011
ru001011
se000115
space001011
ukit.me000111
university010014
website000111
websites.co.in100012
xyz001011
au000000
bond000000
buzz000000
cfd000000
cloud000000
com.au000000
energy000000
expert000000
institute000000
mailchimpsites.com000000
onrender.com000000
pw000000
sbs000000
services000000
uk.com000000
webnode.fr000000

Back to top


The co.za ccTLD Abuse

In 2024, the .co.za ccTLD was once again the second most abused TLD after .com. These statistics shows via which sponsoring registrar this abuse occurred.

.co.za ccTLD Quarterly: 2024-01-01 to 2024-12-31 (All Domains)

RegistrarQ1:TotalQ2:TotalQ3:TotalQ4:TotalPeriod:Total
1API GMBH60618644251
HOSTAFRICA1823253096
TRUEHOST CLOUD LIMITED111131742
SA WEBHOSTS13251333
SA DOMAIN7215226
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM5211321
DOMAINS.CO.ZA563418
FRIKKADEL2313018
ZACR735015
RAPHUS LTD243110
HOSTKING.CO.ZA24219
DYNADOT, LLC02608
GRANSY S.R.O. D/B/A SUBREG.CZ00088
WEBSPACEBAR25007
INSLYHOST.COM21216
EPAG DOMAINSERVICES GMBH01225
REGISTER DOMAIN SA01113
VEHOST.CO.ZA20103
AXXESS DSL10102
HALOWEB.CO.ZA20002
KEY-SYSTEMS GMBH01012
WEB4AFRICA INC.01012
WEBAFRICA NETWORKS00202
ZA DOMAINS20002
AFRIHOST10001
EURODNS S.A.10001
GANDI SAS10001
HOSTING CONCEPTS B.V. DBA OPENPROVIDER00011
INSTRA CORPORATION PTY LTD.00101
REALTIME REGISTER B.V.00011

.co.za ccTLD Quarterly: 2024-01-01 to 2024-12-31 (Active Domains)

RegistrarQ1:ActiveQ2:ActiveQ3:ActiveQ4:ActivePeriod:ActiveCumulative Active
1API GMBH26447038178220
HOSTAFRICA132023308689
TRUEHOST CLOUD LIMITED0912173845
SA WEBHOSTS423132227
FRIKKADEL221301718
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM121131717
ZACR73501515
DOMAINS.CO.ZA15241227
DYNADOT, LLC0260810
GRANSY S.R.O. D/B/A SUBREG.CZ000888
HOSTKING.CO.ZA2321826
INSLYHOST.COM212166
EPAG DOMAINSERVICES GMBH0122545
RAPHUS LTD122056
SA DOMAIN211159
AXXESS DSL101023
KEY-SYSTEMS GMBH010124
REGISTER DOMAIN SA010122
VEHOST.CO.ZA1010210
WEB4AFRICA INC.010123
WEBAFRICA NETWORKS002026
ZA DOMAINS200022
HALOWEB.CO.ZA100011
HOSTING CONCEPTS B.V. DBA OPENPROVIDER000114
REALTIME REGISTER B.V.000111
AFRIHOST000001
EURODNS S.A.000000
GANDI SAS000000
INSTRA CORPORATION PTY LTD.000001
WEBSPACEBAR000000

It should be noted that these domains are used in ways that are at odds with South Africa’s laws, namely the Consumer Protection Act of 2008 and also the new newer Cyber Crimes Act of 2020. They are also used in ways prohibited by the registry’s own terms as reflected it it’s own Anti-Abuse and Takedown Policy.

Back to top


Note to registrars, registries and law enforcement

Artists Against 419 does not only say it, we can also prove it. We record numerous attributes for each entry in our database. While some of these are publicly visible at https://db.aa419.org, we also record additional evidence of maliciousness. These includes website snapshots with embedded EXIF data, source code of interesting pages, email headers and/or linking data.

We appreciate outreach from any registrar and registry alike where they are keen to understand the nature of this maliciousness and wish to mitigate. You are the parties either abused or used as an entry point for this fraud on the web. We are more than happy to share data with you for mitigation purposes and we even have an API for you to use. The choice is yours to be part of the solution or part of passive crime facilitation. It may be worthwhile reading Towards an Understanding of Enablement in Online Non-delivery Fraud by Dr Jack Whittaker. Remember, these domains are purchased with the proceeds of fraud to facilitate further fraud.

We may mitigate till the cows come home to protect consumers, but you are the parties that ultimately stop this illegal abuse.

We do not charge any fees for such cooperation.

Back to top