PULSE NAME
Exploring Newly Released Top-Level Domains
WHITE AlienVault 2024-09-02 Modified: 2024-09-02
22
IOCs
MEDIUM VOLUME
An investigation into 19 new top-level domains (TLDs) released in the past year revealed various malicious activities, including phishing campaigns, distribution of potentially unwanted programs, torrenting websites, and pranking campaigns. The study found a correlation between the TLDs' general availability dates and their popularity, indicating that different groups closely follow the launch of new TLDs to initiate domain registration and usage, including for abuse. The research utilized a graph-based detection system to analyze domain relationships and identify coordinated attack campaigns. Case studies highlighted redirection campaigns, chat bot services, and torrenting clusters. The investigation emphasizes the importance of monitoring domains registered under new TLDs to discover and track new trends and attack campaigns.
Indicators of Compromise (22)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain akira.bot 2024-09-02
domain amsterdam.bot 2024-09-02
domain broadband.bot 2024-09-02
domain chicken.bot 2024-09-02
domain emilia.bot 2024-09-02
domain fluege.bot 2024-09-02
domain harriet.bot 2024-09-02
domain kleinanzeigen.bot 2024-09-02
domain lastminute.bot 2024-09-02
domain leipzig.bot 2024-09-02
domain percy.bot 2024-09-02
domain termin.bot 2024-09-02
domain testvideo.mov 2024-09-02
domain toronto.bot 2024-09-02
domain unblockit.foo 2024-09-02
domain unblockit.ing 2024-09-02
domain valentina.bot 2024-09-02
domain welt.bot 2024-09-02
domain worldfree4u.dad 2024-09-02
domain worldfree4u.foo 2024-09-02
domain worldfree4u.meme 2024-09-02
domain worldfree4u.mov 2024-09-02