Thursday, 2 February 2023

Entropy analysis of registered domain names relating to the top ten most valuable brands

Introduction and methodology

In our previous analysis[1] we considered the use of the mathematical concept of Shannon entropy[2] - essentially a measure of the amount of information (or 'randomness') in a domain name - as a way of clustering together related registrations, as part of the analysis process for identifying and prioritising threatening domains for enforcement and future monitoring. 

In this follow up, I extend the analysis, to consider domain registrations with names containing any of the top ten most valuable brands in 2022 (according to Interbrand)[3]. The analysis considers all domains registered in a one-month period (from 28-Dec-2022 to 27-Jan-2023) and focuses only on those domains with names containing an exact match to the brand string, rather than considering typos and other fuzzy-match types. When considering trends and patterns in the dataset, I consider only active domains[4] (i.e. where the most recent activity event is a registration or re-registration). This yields a dataset of 7,714 domains. For simplicity, I again also exclude any domains containing non-Latin characters (11 domains, or 0.14% of the total). The total numbers of results for each of the ten brands are shown in Table 1.

Brand string
                                
Number of domain
activity events[5] in
monitoring period
                                         
Number of unique
domains represented
in dataset
                                         
Number of active
domains as of
date of analysis
                                         
  apple 5,821 5,285 2,491
  microsoft 707 639 314
  amazon 4,768 4,186 1,847
  google 1,924 1,844 777
  samsung 608 566 244
  toyota 1,140 1,114 566
  coca(-)cola 65 63 29
  mercedes 617 596 359
  disney 1,032 971 456
  nike 1,595 1,506 631

Table 1: Numbers of domain activity events and unique domains identified during the one-month monitoring period, and the numbers of active domains as of the date of analysis

Findings

Overall, the domains occupy a range of entropy values, from 1.722 (for a second-level domain name (SLD)[6] of gogooglego) to 4.548 (for google-site-verificationuj64c5y9-rkbcpqaxydykjdrj1gop8tzij7nfxu). The set of top 60 names (i.e. those with entropy values of 3.892 or greater) encompasses all domain names within the dataset which appear visually to encompass long, apparently-random character strings (i.e. those which might typically arise in automated bulk registrations), and are listed in the Appendix. 

Seven of the top eight comprise very similar domain names (all targeting the Google brand, and with names beginning ‘google-site-verification’), on the .com and .net TLDs (top-level domains, or domain extensions), and are highly likely to represent a coordinated registration campaign, or to have been generated using similar automated registration algorithms. Note that, although all have similar (high) entropy values, the values are not identical (even amongst those with SLDs of the same length), because of the differing numbers of repeated characters in the apparently-random character strings. Although all seven domains are registered using a privacy-protection service, six of the seven appear explicitly to relate to the same entity (with the same 'Contact Privacy Inc.' customer number). These same contact details are actually given for 31 of the top 60 domains in the list, comprising what appears to be a significant cluster of related registrations, all registered via the same registrar (Google LLC), and targeting the Google (6 domains) and Microsoft (25 domains) brands[7]

Other clusters of potentially related domain names are also apparent within the dataset, such as seven domains all with A-records associated with the same IP address, targeting the Amazon (4 domains), Microsoft (2 domains) and Disney (1 domain) brands, and all resolving to webpages monetised through the inclusion of pay-per-click (PPC) links.

The following other observations (all correct as of 27-Jan-2023) from the dataset of top 60 highest-entropy domain names are also of note:

  • Only five of the 60 domains resolve to any significant site content. All of these relate to the Amazon brand, and have names featuring multiple keywords (with SLDs such as amazonproductreviewblog and amazonmysteryboxtruckload), rather than strings of apparently-random characters (suggesting deliberate choice of domain name, rather than automated registrations).
  • 33 of the domains (55% of the total) display no active website, with the remainder resolving to generally low-threat content, such as pay-per-click (PPC) sites (11 domains; 18%), domain-for-sale pages (2 domains; 3%), or other placeholder pages or pages with no significant content. 
  • 39 of the domains (65%) are configured with MX records, indicating that they are able to send and receive e-mails, and could be associated with phishing activity, even where no site content is present.
  • 58 of the domains (97%) display no whois information, have redacted whois records, or use privacy-protection services. Although this is relatively common since the introduction of GDPR legislation, it can indicate an attempt by the domain owner to conceal their identity, and may be indicative of malicious use[8,9].
  • The dataset is dominated by domains registered via consumer-grade registrars (with a top five of: Google LLC (31 domains); GoDaddy.com, LLC (11); Tucows, Inc. (3); Wix.com Ltd. (3); Register.com, Inc. (2)), a trend which has also previously been noted for domains registered for infringing use[10]
  • 17 of the domains incorporate long (14 characters or more) apparently random strings of characters (including examples with SLDs such as 2cxqjwitvhtyh0-amazon, googlecb9c4560579f01d3 and microsoftexchange45e6e37e89e2e08e2e. Amongst the remainder of the dataset, there are numerous other domains featuring shorter apparently-random character strings or keyword patterns which may also be indicative of automated and/or bulk registrations (e.g. cloudworkflow-blv14-exec-microsoft365 and cloudworkflow-blv15-exec365-microsoft, or awsnetsuites-mailcloudroam01microsoftechowa and oauthnetsuites-mailcloudroam01promicrosoftechowa). 

Conclusion

The findings presented in this study highlight how trusted brands continue to be targeted by infringers, registering brand-specific domain names which may be intended for a range of malicious purposes. The analysis is also suggestive of the fact that these third parties appear to be utilising automated algorithms, to register large numbers of variant domain names - which may incorporate apparently random character strings - in bulk. This behaviour is consistent with the use of multiple short-lived domain names, to create hard-to-detect attacks such as those used in phishing, botnet creation, or other infringements, as has been noted in previous studies of practices such as domain tasting[11,12]. These observations highlight the importance of ongoing, proactive brand- and domain monitoring and enforcement by brand owners.

The analysis also provides a further illustration of how the concept of domain-name entropy can be used as one criterion to cluster together related domains, on the basis of common features in their domain-name structure. For example, domain names registered using automated algorithms which generate long, random or pseudo-random character strings will tend to share similar or identical high entropy values. 

Appendix: Top 60 domain names in the dataset, by entropy values

SLD
 
TLD
                    
Brand
                    
SLD len.
(chars)
                    
Shannon
entropy
                    
  google-site-verificationuj64c5y9-rkbcpqaxydykjdrj1gop8tzij7nfxu   net   google 63 4.548
  google-site-verification2mxn0odchxhbhbphzzzkmv2rf3cyblumd6wvfbg   com   google 63 4.529
  google-site-verificationdcgyugw3srf3zzz1anas0thyuegawdj2kcxniew   com   google 63 4.389
  google-site-verificationngi9szdebvea6fop2-zalcux1sgrb7ozrdz4ump   com   google 63 4.342
  notallowedscript63cef0c674953googlesyndication   com   google 46 4.320
  google-site-verificationtszjjwyzw7wbjaotv59rpthglhhg4snojfrc4   com   google 61 4.310
  google-site-verification0mqfjnhkxaxvtftff6psxtgzoqyatc-dszzzjq4   net   google 63 4.301
  google-site-verificationiz8rx-lrwrfx8qmjryrlebc5e1acsia2ao8rhyd   net   google 63 4.279
  amazon-ec3kh4ayn7a5a8czcza64jhstim448dd6namway746eca9549cjw0eea   com   amazon 63 4.210
  logworkflow83microsoftexchange365   com   microsoft 33 4.208
  workflow83-microsoftexchange365   com   microsoft 31 4.149
  mail-workflow83-microsoftexchange365   com   microsoft 36 4.105
  servworkflow83microsoftexchangeonline   com   microsoft 37 4.098
  amz-haifhnakojankertyrewiqhhfoovpidjjjmicrosoft   net   microsoft 47 4.093
  officeleadershipus02microsoftexchange   com   microsoft 37 4.091
  microsoftexchange45e6e37e89e2e08e2e   com   microsoft 35 4.086
  admin-mailcloudcitysend01workflowmicrosoftech   com   microsoft 45 4.084
  cloudworkflow-blv14-exec10-microsoft365   com   microsoft 39 4.081
  metanamegoogle-site-verificationcontenteszeodw7p1vrb4pj   com   google 55 4.081
  fgwlockappsecurekjfdnamazon   com   amazon 27 4.060
  amazonproductreviewblog   com   amazon 23 4.056
  servworkflow83microsofttrade365   com   microsoft 31 4.051
  log-workflow83-microsoftexchange365   com   microsoft 35 4.047
  mail-workflow-microsoftexchange365   com   microsoft 34 4.023
  admin-mailregistr2roam01workflowmicrosoftech   com   microsoft 44 4.018
  cloudworkflows-blv14-exec-microsoft365   com   microsoft 38 4.015
  bestamazonproducts2023   com   amazon 22 4.005
  amazonkdpselfpublishing   com   amazon 23 4.002
  cloudworkflow-blv14-exec-microsoft365   com   microsoft 37 4.000
  payroll365microsoftdynamics   cloud   microsoft 27 3.986
  amazonsecurityauth2023   com   amazon 22 3.971
  amazonpublishingservice   com   amazon 23 3.969
  gonetsuites-mailcloudroam01microsoftechpro   com   microsoft 42 3.959
  officeleadership02-microsoftexchange   com   microsoft 36 3.953
  bestsellingproductonamazon   com   amazon 26 3.950
  bestsellingproductonamazon   co   amazon 26 3.950
  oauthnetsuites-mailcloudroam01promicrosoftechowa   com   microsoft 48 3.949
  cloudworkflow-blv15-exec365-microsoft   com   microsoft 37 3.946
  amazonmysteryboxtruckload   com   amazon 25 3.943
  skynetsuites-mailcloudtect01microsoftechserve   com   microsoft 45 3.942
  microsoftpurviewday   com   microsoft 19 3.932
  blueamazonfirestick   com   amazon 19 3.932
  admin-mailcloudroam01workflowmicrosoftech   com   microsoft 41 3.927
  metaversedisneyworldsmagickingdom   com   disney 33 3.923
  amazonkdpselfpublish   com   amazon 20 3.922
  mailcloudotp-10workflowhostmicrosoftech   com   microsoft 39 3.921
  rivianamazondeliverytrucks   com   amazon 26 3.921
  awsnetsuites-mailcloudroam01microsoftechowa   com   microsoft 43 3.919
  amazonpublishingstore   com   amazon 21 3.916
  microsoft365emailplus   com   microsoft 21 3.916
  amazonpublishingworld   com   amazon 21 3.916
  amz-haifhnakoajdjbfhiswiqhhfoovpidjjjmicrosoft   net   microsoft 46 3.916
  googlecb9c4560579f01d3   com   google 22 3.914
  thewbialtdisneycompany   com   disney 22 3.914
  applegatekitchensandbathrooms   uk   apple 29 3.909
  applegatekitchensandbathrooms   co.uk   apple 29 3.909
  partnetsuites-mailcloudroar01microsoftechpros   com   microsoft 45 3.898
  2cxqjwitvhtyh0-amazon   com   amazon 21 3.897
  fvnexwopsdqb21-amazon   com   amazon 21 3.897
  mailweb23-microsofts365   com   microsoft 23 3.892

References

[1] https://www.linkedin.com/pulse/investigating-use-domain-name-entropy-clustering-results-barnett/

[2] https://arxiv.org/ftp/arxiv/papers/1405/1405.2061.pdf

[3] https://interbrand.com/best-global-brands-2022-download-form/; the brand strings considered are: 'apple', 'microsoft', 'amazon', 'google', 'samsung', 'toyota', 'coca(-)cola', 'mercedes', 'disney', 'nike'

[4] As of the date of analysis (27-Jan-2023)

[5] A domain activity event is defined as an instance of a registration, re-registration, or domain drop (lapse)

[6] The SLD is the part of the domain name before the dot

[7] Note that, in general, even if two domain names targeting two different brands utilised identical styles of apparently-random character strings, we would not necessarily expect the domains to have identical entropy values, because the lengths and structures of the brand strings themselves may differ

[8] https://www.cscdbs.com/en/resources-news/supply-chain-report/

[9] https://www.cscdbs.com/en/resources-news/threatening-domains-targeting-top-brands/

[10] https://www.cscdbs.com/en/resources-news/impact-of-covid-on-internet-security/

[11] https://www.cscdbs.com/blog/patterns-and-trends-in-domain-tasting-of-the-top-10-global-brands/

[12] https://www.linkedin.com/pulse/patterns-trends-domain-tasting-top-ten-global-brands-david-barnett/

This article was first published on 2 February 2023 at:

https://www.linkedin.com/pulse/entropy-analysis-registered-domain-names-relating-top-david-barnett/

Investigating the use of domain-name entropy for clustering results

by Lan Huang and David Barnett

Introduction

The importance of being able to 'cluster' together similar or connected brand infringements has been noted in numerous studies[1]. Clustering has a number of benefits, including the ability to identify serial infringers for prioritised enforcement action, reveal instances of bad-faith activity, and providing the potential for efficient bulk enforcement actions. 

A key associated idea is the concept of quantifying threat - i.e. determining which domains (or other results) may pose the greatest potential for infringing use in the future, even where no content is currently present - allowing prioritisation of results for initial analysis, enforcement or tracking for content changes. 

Expanding on these ideas, previous work[2] has revealed that large coordinated infringement or attack campaigns (such as the registration of domains for use in spamming activity, malware distribution or botnet creation) are often associated with batches of domains purchased through registrars who offer easy access to bulk registrations using automated algorithms. These registrations can be generated via automated recommendations by the registrar, or through the upload of lists of requested domain names. In many cases, the domain names used for these purposes may contain no meaningful keywords (appearing just as random strings of characters), and may be very long. It is also noteworthy that the use of (pseudo-)random domain names may be beneficial to bad actors, as they are unlikely to contain brand terms and are therefore more difficult to detect using classic brand-monitoring techniques.

In order to explore domain registrations of this type, we utilise the concept of Shannon entropy[3]. This is a mathematical concept in information theory, used to quantify the amount of information (or 'surprise') stored in a string or, equivalently, the number of bits needed to optimally encode the string (i.e. a lower bound). In this study, we apply the idea to domain names by calculating the Shannon entropy associated with the second-level domain (SLD) name string[cf. 4] (i.e. the part of the domain name before the dot, and excluding the TLD (domain extension))[5]. Broadly, this means that domain names which are short and/or have large numbers of repeated characters will have low entropy, and domain names which are longer and/or contain large numbers of distinct characters will have high entropy. Our hypothesis is that a batch of domains registered for a coordinated campaign, with a specific algorithm used to generate the domain names, will tend to be clusterable together on the basis that they will share a common date of registration, common registrar, and will have similar entropy values. Overall, long random domain-name strings associated with automated registrations will tend to have high entropy values. 

Methodology and analysis

In order to look more closely at these ideas, we consider the case study of all domains registered on a particular day (13-Dec-2022), using zone-file information. This dataset consists of approximately 205,000 domains - however, for simplicity we exclude from the analysis those featuring non-Latin characters (i.e. Punycode, or homoglyph, domains - accounting for 0.6% of the total), and focus on the remainder, consisting of domain names containing the characters a-z, 0-9, and the hyphen ('-'). 

Across the dataset, the domains are associated with a range of entropy values, from 0.000 to 4.700, as shown in Figure 1.

Figure 1: Distribution of Shannon entropy values for the set of all (non-Punycode) domains registered on a single day (divided into entropy-value 'bins' of width 0.1)

The top and bottom domain names in the dataset (by entropy values) are shown in Tables 1 and 2.

SLD-name string TLD
(domain
extension)
 
SLD length
(chars.)
 
Shannon
entropy
                  
  abcdefghijklmnopqrstuvwxyz   space 26 4.700
  viqxacb7wo6l3hfujw3agf3stcce6eenl4kovfza3rzri4gwyxg6auid   com 56 4.642
  b4su4qo65fkefg3cpd5muxwekbn4vx6fr7ieroavxqwco2xrqmrrwlad   com 56 4.591
  oz5winfavnvbmgdspa633wdnpmbjjrp6crwutyt4uxgxkvytbjdmdc   com 54 4.569
  hydraclubbioknikokex7njhwuahc2l67lfiz7z36md2jvopda7nchidshop   com 60 4.550
  q374uuwdlgtkveh2acqi6ubhic4m3bnwb32kc2yqmxf2ilv36leujnid   com 56 4.539
  mekck2mf2uju3ssjl2woyddfrunwcnevfql3imp4tfr3z6wmjmo4jvid   com 56 4.497
  facebook-domain-verificationyx7q3wstorn4idf9xqtzdz842q0b6x   com 58 4.475
  vh6bjre5lw9iuegs1b9fspitswrdnbtsm1emunvlulbo6uc0   top 48 4.470
  skjcd-98729871cnf5bnb8ewr2e-vq438vnjy0mtg1mdcumty2n   xyz 51 4.464
  a3n3mq7c3xl7u4mfvhhjyjz2x7lqd7sf5jfm66mhf33fxlyodb5pibyd   com 56 4.455
  osli77ygq5myyquqzc2sva7wgnjc2m7yozz67k3kkgkrync4puw3cqyd   com 56 4.439
  7tl2qxwot624do6kbkvqwsg6knaz6jnlx5kfktni7bzt3qlo4imk4tqd   com 56 4.412
  q6g5o01vsfyw95all7x1krjdki   com 26 4.393
  12mnbvcxzasdfghjklpoi   com 21 4.392
  qwertyuiop12asdfghjkkl   com 22 4.369
  owsyeuxoyy4qtm4bkazrkxjtzhydedxgoxkd2yqddmxgcjevmhnbenyd   com 56 4.327
  metanamepdomainverifycontent38656d7bbe27c23f182336255   com 53 4.306
  fqskypondteieqxoxgizamgqrwlb   info 28 4.280
  zaqwsxcderfvbgtgbnhy12   com 22 4.278
  vij8q5xcentralr2hm910v   sbs 22 4.278

Table 1: Top domain names by entropy values

SLD-name string TLD
(domain
extension)
 
SLD length
(chars.)
 
Shannon
entropy
                  
  n   camp 1 0.000
  d   supplies 1 0.000
  s   camera 1 0.000
  4   flights 1 0.000
  n   reise 1 0.000
  n   clinic 1 0.000
  0   condos 1 0.000
  9   events 1 0.000
  9   photography 1 0.000
  rr   center 2 0.000
  cc   degree 2 0.000
  999   guide 3 0.000
  7777   best 4 0.000
  44444   tel 5 0.000
  88888   tel 5 0.000
  ooooo   events 5 0.000
  vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv   vip 63 0.000
  00-00   co.uk 5 0.258
  000000004   xyz 9 0.503
  000000002   xyz 9 0.503
  000000002   com 9 0.503

Table 2: Bottom domain names by entropy values

In order to look more closely at the characteristics of the highest-entropy sites, we conducted a deeper dive into the top 1,000 domain names within the dataset (those with entropy values of 3.823 and above, incorporating the majority of the examples which appear visually to consist of apparently 'random' strings).

Of these top 1,000 domain names:

  • 847 (84.7%) have active A records (i.e. are associated with a specific IP address, and potentially live website content)
  • 275 (27.5%) have active MX records (i.e. are configured to be able to send and receive e-mails and which may therefore be associated with phishing activity)
  • 777 (77.7%) use domain privacy services or have redacted registration information (see also Table 3) (demonstrating the domain owners' attempts to mask their identity and which could indicate nefarious intentions[6]).

The top registrants and registrars represented within the dataset (for those domains where whois information is available) are shown in Tables 3 and 4.

Registrant
 
No. domains
                           
  Domains By Proxy, LLC 219
  REDACTED FOR PRIVACY 197
  Privacy service provided by Withheld for Privacy ehf 82
  Contact Privacy Inc. Customer 7151571251 75
  c/o whoisproxy.com 36
  Privacy Protect, LLC (PrivacyProtect.org) 29
  Wix.com Ltd. 15
  PrivacyGuardian.org llc 11
  Data Protected 9
  Domain Protection Services, Inc. 7

Table 3: Top registrants

Registrant
 
No. domains
                           
  GoDaddy.com LLC 219
  DYNADOT LLC 128
  Google LLC 78
  NAMECHEAP INC 78
  TUCOWS, INC. 53
  Key-Systems GmbH 43
  Wix.Com Ltd. 30
  PDR Ltd. d/b/a PublicDomainRegistry.com 16
  Tucows Domains Inc. 13
  Atak Domain Hosting 12
  Ionos SE 12

Table 4: Top registrars

The top registrars within the dataset are almost exclusively consumer-grade registrars, as would be expected for domains associated with automated registrations for infringing use, and which mirrors the landscape seen in other studies of infringing and potentially threatening domains[7,8]. Furthermore, just a small number of registrars accounts for the vast majority of the high-entropy domain names; the top eleven shown in Table 4 together account for 682 of the domains within the dataset (i.e. 68.2% of the total). 

Furthermore, the dataset does incorporate the types of domain clusters we might expect to see arising from automated registrations for infringing use. The best example is a set of 125 domains with the following characteristics:

  • All with SLD names consisting of apparently-random 15-character alphanumeric strings, and with identical entropy values (all 3.907[9])
  • All hosted on the .buzz extension (one of the top thirty overall highest-threat TLDs, according to a recent CSC study[10])
  • All registered through Dynadot LLC with redacted whois records
  • (Of the 114 with active A records), associated with just 5 distinct IP addresses, most of which are in similar netblocks

It is highly likely that this cluster comprises a coordinated registration event by a single entity, and may well have been registered with intention of use for threatening or infringing activity. 

As of the date of analysis (15-Dec-2022; two days after registration), the domains resolved to a mix of Chinese-language gambling-portal pages (see Figure 2) and dead pages. Whilst this may be the ultimate intended content (potentially as part of a revenue-generating affiliate scheme), it could also be just 'placeholder' content, uploaded until the sites are weaponised for higher-threat purposes, or may be material designed to be visible only from certain geographical regions to mask the 'real' content and evade detection (so-called 'geotargeted' content[11]). In any case, these sites may certainly warrant further monitoring for changes.

Figure 2: Examples of webpage content visible within the cluster of related .buzz domain names

Conclusion

This analysis highlights how the determination of entropy values for the SLD-name strings of registered domain names can be a valuable component of algorithms to determine which examples are most likely to be intended for infringing or fraudulent use. The calculation can also help to link together clusters of related domain names, to build up a picture of activity by specific bad actors, even in cases where the individual whois records are redacted.

These ideas can be applied in the development of technology allowing brand owners to identify key threat vectors and areas of risk, and determine where mediating action is most urgently required.

References

[1] https://www.linkedin.com/pulse/holistic-brand-fraud-cyber-protection-using-domain-threat-barnett/

[2] https://interisle.net/sub/CriminalDomainAbuse.pdf

[3] https://arxiv.org/ftp/arxiv/papers/1405/1405.2061.pdf

[4] https://www.farsightsecurity.com/blog/txt-record/automatingdetection-20190517/ 

[5]  The Shannon entropy (H) of the SLD-name string is calculated as:

H = - Î£i [ pi × log2(pi) ] 

where pi is the proportion of the string made of the ith character (the 'probability'). The summation is carried out over the pool of possible characters. 

[6] https://www.cscdbs.com/en/resources-news/supply-chain-report/

[7] https://www.cscdbs.com/en/resources-news/impact-of-covid-on-internet-security/

[8] https://www.cscdbs.com/en/resources-news/threatening-domains-targeting-top-brands/

[9]  This value arises because, rather than actually being truly random, the SLD names in all cases consist of 15 distinct characters. Therefore: 

H = - 15 × [ (1/15) × log2(1/15) ] = log2(15) = 3.907

[10] https://www.cscdbs.com/blog/the-highest-threat-tlds-part-2/

[11] https://www.cscdbs.com/blog/do-you-see-what-i-see-geotargeting-in-brand-infringements/

This article was first published on 2 February 2023 at:

https://www.linkedin.com/pulse/investigating-use-domain-name-entropy-clustering-results-barnett/

Tuesday, 31 January 2023

Four new case studies of domain registration activity spikes driven by real-world events

Introduction

A variety of previous studies have demonstrated how real-world events can trigger subsequent spikes in domain registrations and infringement activity. Previous CSC articles and reports have focused on issues as diverse as the COVID pandemic[1], the war in Ukraine[2], supply-chain issues affecting the baby-milk and semiconductor industries[3], the Euro 2020 competition[4], the Black Friday and Cyber Monday holiday shopping events[5], and the Reddit stock manipulation campaign targeting the GameStop organisation[6]

When a high-impact event or news story takes place, there is typically a resulting burst of public interest and online searches for associated content, and bad actors can take advantage of this 'buzz' for their own gain. There are a number of ways in which this can be implemented, including: the production of content (which can include areas such as the sale of goods via e-commerce sites) relating to the issue at hand; misdirection of users to infringing, unofficial or potentially malicious websites; phishing activity utilising branded domain names to host fraudulent websites or for their e-mail functionality; or monetisation of dormant high-traffic domains through the emplacement of pay-per-click (PPC) links. In some cases, potentially desirable names may also be seized with the intention of subsequent sale to the infringed brand owner (i.e. cybersquatting) or any other interested party. 

In this article, I look at four recent events or news stories, and focus on the manifestation of associated spikes in potential infringements, by considering patterns in domain registration activity. The analysis includes consideration of new registrations ('N'), re-registrations ('R') and domain drops (lapses) ('D').

Findings

Study 1: Changes of UK Prime Minister (Summer 2022)

Summer 2022 was a time of rapid political change in the UK, resulting in two changes of Prime Minister. The associated analysis considers registration activity of domains containing the names of the three leaders, specifically: (i) 'liz' plus 'truss'; (ii) 'rishi' plus 'sunak'; and (iii) 'borisjohnson' (or typos / variations). The findings are shown in Figure 1, where peaks in registration activity can be seen to correspond to associated key news events.

Figure 1: Daily numbers of new registrations ('N') and re-registrations ('R') combined, and dropped ('D') domains, with names relating to the three 2022 UK Prime Ministers (Boris Johnson (top), Liz Truss (middle), Rishi Sunak (bottom)). Key events in the news timeline[7,8] are denoted according to the key shown below.

A: Boris Johnson announces resignation (07-Jul-2022)
B: Liz Truss enters leadership contest (10-Jul-2022)
C: Rishi Sunak frontrunner in leadership contest following second round of voting (13-Jul-2022)
D: Liz Truss confirmed as new Conservative leader and PM following party-member vote (05-Sep-2022)
E: Boris Johnson tenders resignation (06-Sep-2022)
F: Liz Truss faces political rebellion following economic turmoil (04-Oct-2022)
G: Liz Truss announces resignation following appointment of new Chancellor and reversal of 'mini-budget' policies (20-Oct-2022)
H: Rishi Sunak confirmed as new Conservative leader and PM (24-Oct-2022)

In this case, many of the registrations were associated with websites featuring satirical or commentary-related content (Figure 2), though some were of greater concern (misdirection to third-party content or potential phishing activity) (Figure 3). In general, political content can also be of particular concern in cases where it is found to be associated with the spread of misinformation, or be attempting to manipulate voting patterns[9].

Figure 2: Examples of satirical websites identified in the registration dataset - second-level domain names (SLDs) (i.e. the part of the domain name to the left of the dot) are: borisjonson (registered 07-Sep-2022) (top); liztrussgame (registered 23-Oct-2022) (middle); hasrishisunakresignedyet (registered 15-Oct-2022) (bottom)

Figure 3: Examples of other websites identified in the registration dataset - SLDs are: trussliz and wetruzzliz (but displaying content relating to the UK opposition party) (registered 02-Jun-2022) (top); rishisunakforpm (registered 25-Oct-2022) (bottom)

Study 2: FIFA World Cup Qatar 2022

In this study, I consider domain registration activity relating to the 2022 FIFA World Cup competition which took place in Qatar between 20-Nov and 18-Dec 2022. The initial searches focused on all domains containing the keywords 'qatar' or 'world(-)cup', for which over 10,000 registration activity events were identified (comprising 8,690 unique domain names) during a one-year analysis period from December 2021 to December 2022. Continuous activity was identified throughout the year, though unsurprisingly with a ramp-up in new registrations towards the time of the event itself (Figure 4).

Figure 4: Daily (top) and monthly (bottom) numbers of new registrations ('N'), re-registrations ('R'), and dropped ('D') domains with names containing 'qatar' or 'world(-)cup'

In order to take a deeper dive into the highest-relevance domain names, I then focus on searches utilising keywords indicating that the domains under consideration are likely to pertain specifically to the event, rather than just referencing the more generic terms 'Qatar' or 'World Cup'. Specifically, this considers domains with names containing:

  • 'world(-)cup' AND 'qatar'

        OR

  • ['world(-)cup' OR 'qatar'] AND ['football' OR 'futbol' OR 'soccer' OR '2022' OR 'fi(-)fa']

The methodology also considers only those domains which were still active as of the time of analysis (02-Dec-2022) (i.e. those for which the most recent activity event was not a domain drop ('D')). 

This focused analysis yields a dataset of 977 domains, for which the pattern of registration activity (considering only the most recent activity event for each unique domain name) is shown in Figure 5.

Figure 5: Daily (top) and monthly (bottom) numbers of new registrations ('N') and re-registrations ('R') combined, for high-relevance domain names relating to the Qatar World Cup (considering the most recent activity event for each unique domain name)

In this more focused dataset, the overall activity pattern is broadly similar, though an additional peak in registrations is also apparent in early April 2022. This relates to what appears to be one or two specific, short-lived, coordinated registration campaigns of domains with names of the form 'qatar-2022-iX.xyz' and 'worldcup2022-jYYX.buzz' (where 'X' is an additional digit and 'Y' is an additional character). Although none of these domains was found to resolve to any live site at the time of analysis, the .xyz and .buzz new-gTLD domain extensions have been noted as previously being frequently associated with malicious or infringing content[10,11].

Of the 977 high-relevance domains overall, 633 were found to yield an active website response (i.e. an HTTP status code of 200) at the time of analysis. Within this set, a range of (where non-official) potentially infringing or high-threat content types were observed (Figure 6).

Figure 6: Examples of live websites relating to the Qatar World Cup, representing a range of content types of potential concern (with the SLD shown in each case in square brackets) - top to bottom: potential phishing [qatar2022]; piracy [worldcuplivefifa]; gambling [worldcupbet]; ticket sales [qatar-worldcup]; other e-commerce [qatarfootballcup]; cryptocurrency-related [qatarfifaworldcup]; NFT-related [worldcupnft2022]

Study 3: New Year 2023

The new year can be a prime time for brand owners to launch new products, campaigns and marketing activity, and one way in which this can be promoted in a topical fashion is through the registration of new domains making explicit reference to the year. However, similar tactics can also be employed by bad actors, through the registration of desirable domain names. In some cases, these domains may be registered well in advance of the start of the new year itself, as a way of 'getting ahead of the curve'. Accordingly, this study considers activity associated with the registration of domains with names beginning or ending with the string '2023' (i.e. 'left- or right-matches') throughout the calendar year 2022.

Over the course of 2022, 6,730 domain activity events (representing 6,458 unique domain names) were identified for '2023-specific' domains, as shown in Figure 7. 

Figure 7: Daily (top) and monthly (bottom) numbers of new registrations ('N'), re-registrations ('R') and dropped ('D') domains with names beginning or ending with '2023'

Figure 8 shows the growth across 2022 of the cumulative total number of registered domains with names beginning or ending with '2023'.

Figure 8: Daily cumulative total number of registered domains with names beginning or ending with '2023'

Unsurprisingly, the greatest levels of activity (dominated by new registrations) occurred during the latter parts of 2022 (particularly in December), but it is significant that registrations were taking place throughout the year, with a continual growth in the number of registered '2023' domains. It is also worth noting that there were already 2,380 such domains registered at the start of 2022 (compared with 7,524 at the end).

Considering the unique domains represented in the 2022 activity dataset, a range of TLDs (domain extensions) were represented (Figure 9), including significant numbers of new-gTLDs, many of which are of concern due to the previously-noted frequency of their association with infringing activity[12].

Figure 9: Top TLDs amongst the unique '2023' domains represented in the 2022 activity dataset

Significant numbers of these domains were found to be associated with potentially infringing websites, including several with names including top brand names (Figure 10). 

Figure 10: Examples of potentially infringing websites with domain names including references to both '2023' and a brand name from the Interbrand top 20 list of 'best global brands'[13] (SLDs shown in square brackets): (top) potentially fraudulent cryptocurrency-related site [2023-tesla] (registered 27-Dec-2022); (bottom) traffic misdirection / re-direction to a site offering potentially unauthorised or unofficial informational content [2023bmw] and [2023-toyota] (both registered 07-Oct-2022)

A variety of other sites of potential concern were also identified in the dataset, including a range of examples where no brand name was present in the domain name itself. Some of these were, however, found to feature website content which appears to be infringing against specific brands (Figure 11).

Figure 11: Examples of websites offering the sale of potentially counterfeit products and with domain names including a reference to '2023' (SLDs are replicascamisetanba2023 and 2023freerunshoesshop)

Many of the domain names incorporate popular keywords, in apparent attempts to attract traffic in response to common web searches. These included examples such as 'nft' (present in 7 domains) and 'blackfriday' (present in 5 examples, despite Black Friday 2023 being 11 months away). Significantly, 'covid' and 'corona' both appeared in only one example each, perhaps indicating that the online buzz associated with the pandemic is subsiding. The dataset also included some more surprising examples, such as 'keto' (present in 522 domains in the dataset, in addition to several others featuring misspellings such as 'keeto'), perhaps reflective of the continuing popularity of keto diets. Many of these 'keto' domains appear to be part of one or more coordinated registration campaigns, with large numbers of examples with SLDs beginning '2023keto' followed by strings of random characters, across new-gTLDs such as .cyou, .click and .buzz. Even amongst groups of such domains registered on the same day and TLD, a range of content types were observed, including nutrition-related sites, sites advertising a business promotion service provider, and even adult content.

Study 4: Southwest Airlines’ logistics crisis

In December 2022, US air operator Southwest Airlines experienced a 'travel meltdown' in which a series of logistical failures resulted in the cancellation of more than 16,000 flights between 21-Dec and 31-Dec, resulting in tens of thousands of customer refund claims per day, and overall losses to the organisation of between $725 million and $825 million[14]

In this case, I considered domains with names containing 'southwest' (or variants), over a one-month period between 12-Dec-2022 and 11-Jan-2023, to determine whether the story generated activity in response to the increased interest in the company and the desire by customers to claim refunds.

Overall, 708 domain activity events, representing 674 unique domain names, were identified during the monitoring period, including a general spike in overall registration activity around the 11-day period in which the incident took place (Figure 12).

Figure 12: Daily numbers of new registrations ('N'), re-registrations ('R') and dropped ('D') domains with names containing 'southwest' (or variants)

Since the term 'southwest' is relatively generic, I then focused on the subset of ('high-relevance') domains which appear relate specifically to Southwest Airlines and the associated events of the story. This was done by considering those domain names which also feature relevant keywords (such as 'air' (but excluding false positives such as 'repairs', 'fairs', etc.), 'aviation', 'aerospace', 'bookings', 'claim' or 'classaction'), or where the domain name itself is a misspelling of Southwest's official website (southwest.com). This yielded a dataset of 46 domain activity events, comprising 43 unique domain names. Within this reduced dataset, the spike in activity around the time of interest can be seen to be much more pronounced (Figure 13).

Figure 13: Daily numbers of new registrations ('N') and re-registrations ('R') combined, and drops ('D'), for high-relevance domains with names containing 'southwest' (or variants)

Of the 36 registration or re-registration events within the dataset of high-relevance domains, 30 (83%) occurred in the four-day period between 27-Dec and 31-Dec.

Of the 43 unique high-relevance domain names in total, 10 were inactive as of the date of analysis (12-Jan-2023). Of the remainder, 27 (68% of the total) resolved to parking pages featuring pay-per-click (PPC) links, indicating an effort by the site owners to monetise the traffic received by the sites. One domain resolved to a site which may be associated with a recruitment scam (Figure 14), one re-directed to the website of a legal-service provider (apparently abusing the Southwest brand name in order to attempt to take advantage of the potential customer desire to take legal action against the company), and one generated a browser warning indicating that dangerous content was formerly present, in addition to other content types.

Figure 14: Example of a website associated with a possible recruitment scam, hosted on a high-relevance, brand-specific domain name

Four (9%) of the high-relevance domain names are configured with MX records, indicating the ability to send and receive e-mails, and suggesting that the domains may be associated with phishing or brand-impersonation activity.

Within the dataset, two instances of domain 'tasting'[15] were identified, comprising domains (with SLDs of southwest-air-line and southwest-bookings) being registered and then dropped the following day, and possibly indicating efforts by the owners to determine the levels of traffic received by the sites, or to launch short-lived (and thereby difficult to detect) phishing attacks.

31 of the high-relevance domains had registration (whois) information available, all of which used privacy-protection providers or had redacted contact information, possibly indicating efforts by the owners to maintain anonymity and potentially nefarious intentions.

Additionally, several individual 'clusters' of domains, potentially representing coordinated registration campaigns by specific entities, were identified. These included:

  • One group of 12 domains all registered on 28-Dec-2022, comprising misspellings of 'southwest.com' and hosted on a group of four consecutive IP addresses
  • One group of five domains all registered on 30-Dec or 31-Dec and all hosted at the same IP address, with names comprising references to 'southwestairlinesclassaction' (or variants)
  • One group of eight domains all registered on 29-Dec or 30-Dec and all hosted at the same IP address

All of the above domains resolved to parking pages featuring PPC links at the time of analysis.

Conclusion

The above news stories or events are all of different types, including examples which are regional or global in scope, and those which may be relevant mainly to specific corporations or industry areas. However, in all cases, resulting spikes in associated domain registration activity were observed. In general, this activity incorporates a mixture of both legitimate and non-legitimate (potentially threatening) registrations, comprising responses both by the official organisations concerned, and by nefarious bad actors.

The findings highlight that, in addition to the construction and maintenance of official domain portfolios by brand owners - and the protection of critical domains using appropriate domain security measures[16,17] - monitoring for third-party activity remains of crucial importance. Particular additional focus must be taken when external events drive increased public interest in associated content, which can result from industry-relevant events, news stories, marketing activity or product releases, corporate changes, and a range of other factors. Accordingly, the monitoring strategy needs to be flexible enough to evolve in response to emerging issues as they develop. Also key to the protection of the brand is a robust enforcement programme incorporating a wide range of approaches, to ensure the swift takedown of damaging infringing content.

It is also striking that so much of the observed activity is carried out so far in advance of the date of the events themselves, showing the significance of proactivity and timeliness in brand protection initiatives, combined with a robust strategy of defensive registrations, to obtain required domains in advance of their registration by wily third parties.

References

[1] https://www.cscdbs.com/en/resources-news/impact-of-covid-on-internet-security/ 

[2] https://www.cscdbs.com/blog/how-to-manage-the-online-effects-of-the-ukraine-war/

[3] https://www.cscdbs.com/en/resources-news/supply-chain-report-form/

[4] https://www.cscdbs.com/blog/euro-2020-part-3-domains-revisited-and-other-channels/

[5] https://www.cscdbs.com/blog/holiday-shopping-events-part-2/

[6] 'The GameStop saga - how online activity and news stories can create feedback loops', Brand Journal, issue no. 21 (April 2021) (internal CSC publication)

[7] https://www.euronews.com/2022/10/14/truss-timeline-key-events-in-three-months-of-political-chaos-in-british-politics

[8] https://www.cnn.com/uk/live-news/uk-prime-minister-announcement-monday-gbr-intl/index.html

[9] https://www.ox.ac.uk/news/2021-01-13-social-media-manipulation-political-actors-industrial-scale-problem-oxford-report

[10] https://www.cscdbs.com/blog/the-highest-threat-tlds-part-1/

[11] https://www.cscdbs.com/blog/the-highest-threat-tlds-part-2/

[12] https://www.cscdbs.com/en/resources-news/threatening-domains-targeting-top-brands/

[13] https://interbrand.com/best-global-brands-2022-download-form/

[14] https://www.cnn.com/travel/article/southwest-airlines-dot-complaints/index.html

[15] https://www.cscdbs.com/blog/patterns-and-trends-in-domain-tasting-of-the-top-10-global-brands/

[16] https://www.linkedin.com/pulse/holistic-brand-fraud-cyber-protection-using-domain-threat-barnett/

[17] https://www.cscdbs.com/en/resources-news/domain-security-report/ (2022)

This article was first published on 31 January 2023 at:

https://www.linkedin.com/pulse/four-new-case-studies-domain-registration-activity-spikes-barnett/

A browse around the “.shop”s

This article explores the ecosystem of domains hosted on the .shop ('dot-shop') extension, which is popularly used for e-commerce we...