• About
    • History of Dallas SEO
  • Contact
  • Topics
    • Bing
    • Blogging
    • Branding
    • Domain Names
    • Google
    • Internet Marketing
    • Link Building
    • Local Search
    • Marketing
    • Public Relations
    • Reputation Management
    • Search Engine Marketing
    • Search Engine Optimization
    • Search Engines
    • Social Media
    • Tech
  • Advertise
  • Services
    • Search Engine Optimization
    • Ongoing SEO Services
    • SEO Expert Witness
    • Google Penalty Recovery
    • Mini SEO Audit
    • Link Audit
    • Keyword Research
    • Combine Websites SEO Services
    • PPC Management
    • Online Reputation Management
    • Domain Name Consultant
    • Domain Names & Expired Domains
    • Domain Name Appraisal

Bill Hartzer

GoDaddy Airo: Register your .com domain name today!
Home » Domain Names » 106 Million Domains Later—Here’s What Cybercriminals Keep Getting Wrong

106 Million Domains Later—Here’s What Cybercriminals Keep Getting Wrong

Posted on April 24, 2025 Written by Bill Hartzer

domaintools report 2024

 

Cybercriminals are nothing if not repetitive. DomainTools’ inaugural Domain Intelligence Year in Review confirms this: threat actors follow recognizable patterns, and their reliance on domain infrastructure leaves behind a trail that security professionals can analyze. The 2024 report offers a comprehensive breakdown of how domains are being used—and misused—at scale.

In 2024 alone, over 106 million new domains were registered, averaging around 289,000 per day. Among them, nearly 395,000 were confirmed as malicious, used for phishing, credential harvesting, malware distribution, and managing botnets. With the right tools and data, defenders can catch these threats early.Key Findings

Jump To

Toggle
  • Domains Are Central to Modern Attacks
  • Domain Registrars: The Gatekeepers Facing an Uphill Battle
  • Attackers Reuse Infrastructure
    • Keyword Triggers Are Telltale Signs
    • High-Volume Registration Spikes Signal Risk
    • Entropy Analysis Reveals Algorithmically Generated Domains
  • New Top-Level Domains (TLDs) Are Being Exploited
  • Why It Matters

Domains Are Central to Modern Attacks

Cybercriminals used newly created domains for a variety of malicious purposes:

  • Phishing

  • Malware delivery

  • Command and Control (C2) infrastructure

  • Credential theft

  • Financial scams

More than 30% of malicious domains scored 100 on DomainTools’ risk scale, the maximum threat score possible.

Domain Registrars: The Gatekeepers Facing an Uphill Battle

Domain registrars sit at the entry point of the internet’s naming system, issuing digital real estate to businesses, governments, and unfortunately, malicious actors. While their role is foundational to web infrastructure, the increasing misuse of domain names for fraud, phishing, and disinformation has spotlighted the registrar’s responsibility in addressing abuse.

The challenges are significant. Despite being bound by ICANN (Internet Corporation for Assigned Names and Numbers) policies that require action against fraudulent activity, some registrars continue to be linked to high-profile abuses. Investigations published by The New York Times and The Record have traced domains used in state-backed disinformation campaigns—such as those out of Iceland and Russia—back to specific registration providers.

The primary issue isn’t a lack of rules. It’s enforcement at scale. Millions of domains are registered every month. Identifying which ones pose a threat, especially when attackers deliberately mimic legitimate domains or use automated scripts to generate them, can overwhelm even well-intentioned registrars.

Registrars operate under a shared responsibility model. They handle the domain name system logistics, while registrants control the actual content. This separation complicates intervention. Even when Acceptable Use Policies (AUPs) prohibit malicious activity, registrars may struggle to detect policy violations until after damage has occurred.

This creates a dilemma: registrars are held accountable for registrations that may, at first glance, appear benign. But with reputation and security increasingly intertwined, the industry is under pressure to improve vetting processes, monitor high-risk behavior, and collaborate more closely with cybersecurity firms and threat intelligence providers.

Security teams, meanwhile, must remain vigilant. Recognizing patterns in registrar usage—especially among domains that repeatedly score high on risk metrics—can help organizations anticipate where the next wave of abuse may emerge. As attackers continue to exploit registrar blind spots, defenders must treat registrar behavior as a key signal in threat detection.

Attackers Reuse Infrastructure

The report identifies repeated use of specific registrars, nameservers, and ISPs across malicious domains. Patterns in combinations—such as domains registered with “NameSilo LLC” and hosted via “cloudflare[.]com”—suggest preferred platforms that should receive extra scrutiny from defenders.

Keyword Triggers Are Telltale Signs

Malicious domains frequently include red-flag terms. These vary by campaign type:

  • Credential theft: login, verify, reset, password, portal

  • Malware delivery: download, install, patch, update

  • Financial scams: bitcoin, airdrop, profit, wallet

Keyword spikes often correlate with news cycles and global events. In 2024, domain activity spiked around the U.S. Presidential Election and the boom in generative AI.

High-Volume Registration Spikes Signal Risk

Two large surges in domain registrations were recorded:

  • July 3, 2024: 681,099 new domains in a single day

    • About 129,154 (19%) of them were flagged as irregular

  • November 2024: Another major spike, closely aligned with election timelines

These surges often align with disinformation campaigns or spam deployments.

Entropy Analysis Reveals Algorithmically Generated Domains

DomainTools used Shannon entropy to detect DGA (Domain Generation Algorithm) patterns. These domains often appear as jumbled, nonsensical strings. Highlights:

  • Average entropy score across domains: 3.34

  • Over 31.8 million domains fell outside one standard deviation

    • Low entropy outliers (e.g., ooooooooooo[.]ooo): 16.3 million

    • High entropy outliers (e.g., urytwegjsb0953kflqwdn1249aiai[.]com): 15.5 million

High entropy domains were strongly associated with botnet infrastructure and evasion tactics.

New Top-Level Domains (TLDs) Are Being Exploited

Malicious actors flocked to newly launched domain extensions in 2024. Notable examples:

  • .lifestyle – 2,474 domains

  • .music – 6,124 domains

  • .now – 7,035 domains

  • .tr – 67,556 domains

Security tools relying on static TLD allow/block lists risk missing threats hosted on these emerging namespaces.How Security Teams Can Use This Data

  • Incident Response: Prioritize investigation of domains with high entropy, risky infrastructure, or known malicious keywords.

  • Brand Protection: Monitor for typosquatting and lookalike domains using homoglyphs or topical terms tied to your brand or industry.

  • Threat Hunting: Use registrar-hosting-SSL combinations as pivot points to uncover related domains in large campaigns.

  • Detection Engineering: Customize alerting logic around keyword patterns, risk scores, and entropy thresholds.

Why It Matters

Cyber attackers rely on scale and automation. But scale works both ways—analysts who study large-scale trends in domain data can anticipate how and where attackers will strike next. The DomainTools 2024 report doesn’t just look back; it provides a tactical roadmap for what’s coming.

The domain layer remains one of the earliest, most consistent indicators of cyber threats. By recognizing entropy irregularities, keyword clustering, and infrastructure overlap, security teams gain a measurable edge. As the threat landscape continues to evolve, domain intelligence isn’t a nice-to-have—it’s foundational to modern defense.

Filed Under: Domain Names

About Bill Hartzer

Bill Hartzer is the CEO of Hartzer Consulting and founder of DNAccess, a domain name protection and recovery service. A recognized authority in digital marketing and domain strategy, Bill is frequently called upon as an Expert Witness in internet-related legal cases. He's been sharing insights and research here on BillHartzer.com for over two decades.

Bill Hartzer on Search, Marketing, Tech, and Domains.

Recent Posts

  • Internet Marketing Ninjas Acquired by Previsible.IO July 9, 2025
  • Metricool Brings Real Analytics to Personal LinkedIn Profiles July 8, 2025
  • This Cleveland Agency Found a Smarter Way to Rank in Every Suburb—Without Opening More Offices July 8, 2025
  • Survey: Gen Z Reuses Passwords but Demands Bank-Level Security From Small Businesses July 8, 2025
  • Liftoff Reveals What’s Actually Working in Mobile Ads July 7, 2025
  • EasySend’s Big Move: AI Tools That Make Static Forms Obsolete July 7, 2025
  • Is Social Media Failing Small Businesses? New Survey Reveals a Hidden Blind Spot July 7, 2025
  • Why Cloudflare’s Pay Per Crawl Is a Trap for 99% of Websites July 2, 2025
  • The Hidden Risk of Double Letters in Brand and Domain Names July 2, 2025
  • GEO Verified™ Launches to Help Brands Survive the AI Search Shakeup July 1, 2025
  • RetailOnline.com Hits the Market After 25 Years—And It’s Built for the Future of E-Commerce July 1, 2025
  • AI-Powered Task Planning: The Future of Business Efficiency and Personal Productivity June 30, 2025
  • New Yoast Add-On Turns Google Docs Into an SEO Power Tool June 26, 2025
  • Simon Data Flips the Script on Marketing with AI Agents June 26, 2025
  • IAB Lays Down the Law for Gaming Ads—Here’s What Brands Need to Know June 26, 2025
  • Google Review Extortion Text Message – Scam Warning for Business Owners June 25, 2025
  • Google Names SearchKings Top AI Innovator for Transforming Lead Quality June 24, 2025
  • Marketing Exec Buys Social Media Firm in Deal That Signals Big Plans June 24, 2025
  • Amsive Takes on ChatGPT and Gemini with Next-Gen SEO for the AI Search Era June 23, 2025
  • Reddit Sued After Google’s AI Overviews Allegedly Gutted Traffic June 19, 2025

Hartzer Domains

Bare-Metal Servers by HostDime

DFWSEM logo

Bill Hartzer is a Brand Ambassador for:

Industry Friends

I Love SEO
WTFSEO
SEO By the Sea
Brian Harnish
Jeff Lenney
Jeff Gabriel
Scott Hendison
Dixon Jones
Brian Hartzer
Navah Hopkins
DNAccess
SEO Dallas
Confirmed Stolen

Connect With Bill Hartzer

Bill Hartzer on Twitter
Bill Hartzer on BlueSky
Bill Hartzer on Instagram
Hartzer Consulting on Facebook
Bill Hartzer on Facebook
Bill Hartzer on YouTube

Categories

  • Advertising (109)
  • AI (201)
  • Bing Search Engine (8)
  • Blogging (43)
  • Branding (19)
  • Domain Names (315)
  • Google (260)
  • Internet Marketing (51)
  • Internet Usage (95)
  • Link Building (53)
  • Local Search (63)
  • Marketing (232)
  • Marketing Foo (34)
  • Pay Per Click (9)
  • Podcast (19)
  • Public Relations (9)
  • Reputation Management (14)
  • Search Engine Marketing (46)
  • Search Engine Marketing Events (60)
  • Search Engine Marketing Firms (94)
  • Search Engine Marketing Jobs (33)
  • Search Engine Optimization (189)
  • Search Engines (223)
  • Social Media (302)
  • Social Media Marketing (58)
  • Tech (16)
  • Web Analytics (21)
  • Webinars (1)

Note: All product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only, and are mentioned only to help my readers. All other trademarks cited herein are the property of their respective owners. Use of these names, logos, and brands does not imply endorsement.

 

Hartzer Consulting

Website, Content, and Marketing by Hartzer Consulting, LLC.

Disclaimer - Privacy Policy - Terms of Use

Copyright © 2025 ·