← Latest papers
💻 computer science

A Longitudinal Study of Recently Observed Malicious Domains: Characteristics, Infrastructure, and Abuse Patterns

This paper presents a longitudinal analysis of 1.52 million malicious domains observed on VirusTotal between January and May 2026, characterizing their infrastructure and abuse patterns across eight dimensions to reveal trends such as short-lived attacker-created domains, heavy reliance on specific registrars and Cloudflare for fronting, widespread bulk registration, and significant brand impersonation.

Original authors: Fathima Mashood, Mohamed Nabeel

Published 2026-06-10
📖 5 min read🧠 Deep dive

Original authors: Fathima Mashood, Mohamed Nabeel

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the internet as a massive, bustling city. In this city, there are millions of "houses" (websites) where people live, shop, and work. But there's also a dark side: a criminal underworld where scammers build fake houses to trick people, steal their mail, or hide their illegal activities.

This paper is like a five-month surveillance report (from January to May 2026) on a specific group of these criminal houses. The researchers looked at about 1.52 million suspicious addresses flagged by a global security watchdog called VirusTotal. They wanted to understand how these bad actors build their operations, where they hide, and how they trick people.

Here is the breakdown of their findings, using simple analogies:

1. The Two Types of Criminal Houses

The researchers found that almost 9 out of 10 of these bad houses were brand new constructions built specifically by the criminals.

  • Attacker-Created (89.3%): These are like "pop-up tents" or "shanties" built overnight in an empty lot just to scam people. They are designed to be used for a short time and then abandoned.
  • Compromised (10.7%): These are like legitimate, old family homes that the criminals broke into. The house belonged to a nice family for years, but the criminals sneaked in, changed the locks, and started using it for illegal business.

2. The "Flash in the Pan" Lifestyle

The criminals are incredibly fast.

  • The Speed: For the new "shanties," the median time between building the house and using it for a crime is only 60 days.
  • The Rush: Some are so fast that they are caught doing bad things within one day of being built. It's like a criminal building a fake bank, opening the doors, robbing it, and running away before the police even finish writing the permit paperwork. This gives defenders very little time to stop them.

3. The "Bad Neighborhoods" (Registrars and TLDs)

Just as some real-world neighborhoods have a higher crime rate, the internet has specific "landlords" and "street names" where criminals love to operate.

  • The Landlords: The researchers found that just 10 specific domain registrars (companies that sell website addresses) are responsible for 60% of all the bad houses. If you were a city planner, you'd focus your anti-crime efforts on these specific landlords.
  • The Street Names: Similarly, a few specific endings to website names (like .com, .top, and .xyz) are used for 68% of the crimes. Criminals pick the cheapest, easiest-to-get street names to set up their traps.

4. Hiding in Plain Sight (The Cloudflare Problem)

This is one of the most interesting findings. You might think criminals hide in dark, shady alleys, but they are actually hiding in the most reputable, high-tech office buildings in the city.

  • The Cloudflare Effect: The top 10 "addresses" (IPs) where these bad houses are hosted belong to Cloudflare, a massive company that provides security and speed for legitimate websites.
  • The Analogy: It's like a group of thieves renting a room in a luxury 5-star hotel because the hotel's security is so good that the police rarely check inside. The criminals use these trusted services to mask their true location, making it very hard to find their "real" base.

5. The "Factory Line" of Bad Addresses

The paper found evidence of mass production.

  • The Batches: On single days, criminals registered thousands of domains at once. For example, on one day, a single company registered 2,168 new bad addresses.
  • The Pattern: These addresses often look like random gibberish (e.g., 10jfr.top). It's like a factory churning out thousands of fake ID cards in an hour. This proves they are using automated scripts to build their criminal fleets instantly.

6. Stealing Famous Names (Brand Impersonation)

Criminals love to wear a disguise.

  • The Disguise: They create fake websites that look like famous brands to trick people.
  • The Top Targets: The most impersonated "brands" were WhatsApp, Logitech, and Google.
  • The Goal: If you see a fake WhatsApp site, you might think it's the real thing and type in your password, which the criminals then steal. They also targeted crypto exchanges and gambling sites, likely to steal money or login details.

7. The "Traffic Jam" of Harm

Not all bad houses are equally dangerous.

  • The Power Law: The researchers looked at how many people visited these bad sites. They found that a tiny handful of the bad houses were visited millions of times, while most were visited very few times.
  • The Takeaway: If the police (or internet defenders) could shut down just that tiny, high-traffic group of bad houses, they would stop the vast majority of the harm. It's like clearing a single major traffic jam rather than trying to fix every pothole on every side street.

Summary

In short, this paper tells us that the internet's criminal underworld is fast, automated, and concentrated.

  • They build fake houses quickly and use them briefly.
  • They rely on a few specific "landlords" and "street names."
  • They hide inside the most trusted, high-security buildings (Cloudflare) to avoid detection.
  • They mass-produce fake identities to steal from famous brands.

The researchers suggest that to fight this, we need to focus on those specific landlords, stop the mass-production scripts, and prioritize shutting down the high-traffic fake sites. They have also shared their list of bad addresses so other researchers can study them further.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →