PULSE NAME
Parked Domains Become Weapons with Direct Search Advertising
WHITE AlienVault 2025-12-17 Modified: 2026-01-16
21
IOCs
MEDIUM VOLUME
Parked domains are increasingly being weaponized through direct search advertising, posing significant risks to users. The investigation found that over 90% of visits to parked domains led to scams, malware, or unwanted content. Three key actors were identified: one using lookalike domains and mail collection, another employing sophisticated 'double fast flux' techniques, and a third exploiting DNS configuration typos. These actors actively profile visitors and selectively redirect traffic to malicious advertisers. The complexity of the advertising ecosystem makes it difficult to trace the origin of threats. Recent policy changes and the rise of AI may inadvertently increase risks associated with parked domains.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Tedy Babar
Indicators of Compromise (21)
All FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 4a3497d66a64c22342d855d2da370c9a4351e6403bbd224093c4b348bd611df4 2025-12-17
FileHash-SHA256 86586f6954da38e5a5df7e56334ef98e74838dee68de0355ae4fe03d36c82502 2025-12-17
FileHash-SHA256 c3f1f456419f39f19c9e0d5aae2b50f701abe517a3cc2952869e516b260dbf88 2025-12-17
domain arentmarket.com 2025-12-17
domain chatterjamtagbirdfile.monster 2025-12-17
domain colaureat.icu 2025-12-17
domain echidns.com 2025-12-17
domain gambel.law 2025-12-17
domain installupdate.online 2025-12-17
domain lemaymotors.com 2025-12-17
domain mavilibeyazajans.com 2025-12-17
domain numbatdns.com 2025-12-17
domain safezonefirewall.com 2025-12-17
domain scotaibank.com 2025-12-17
domain uasecho.com 2025-12-17
domain usaconnect.com 2025-12-17
domain velixnero.co.in 2025-12-17
hostname nojs.domaincntrol.com 2025-12-17
hostname ns2.torresdns.com 2025-12-17
hostname ww1.scotaibank.com 2025-12-17
hostname ww2.mavilibeyazajans.com 2025-12-17