Yesterday, at #ICANN81, the INFERMAL project shared its analysis of what makes certain domain registrars and TLDs prime targets for attackers.
π‘Key finding: There's a clear link between domain registration pricing (and discounts) and abuse. No shock here.
While Spamhaus researchers have long had solid indications of this (as seen in Spamhaus' Domain Reputation Reports - see comments for link) - this research now CONFIRMS it.
But that's not all....
An even stronger correlation was identified between API access and abuse, enabling the rapid setup of malicious infrastructures.
Spamhaus would like to thank the INFERMAL group funded by ICANN for their contribution and we look forward to seeing the published results!
INFERMAL Project: Analyzing Features of Malicious Domain Registrations
The ICANN Inferential Analysis of Maliciously Registered Domains (INFERMAL)-INFERMAL Project led by Dr. Maciej Korzynski from KOR Labs institute investigates key features of domain registrars and TLDs that attract cybercriminals for phishing, aiming to uncover the mechanisms behind malicious registrations and improve mitigation strategies.






