The .US Domain Registry cesspool – Part 2

This post builds upon an observation from our previous quote: “virtually all European Union member state ccTLDs that enforce nexus restrictions also have massively lower levels of abuse [than the .US ccTLD] due to their policies and oversight”. [1-2] In this installment, we’ll validate this insight through a comparative analysis of four European ccTLDs (country-code Top Level Domains). Additionally, we’ll showcase how DomainTools and Generative AI can deepen our understanding of these issues, paving the way for remediation.

Our investigation began by building a peer group data collection of European ccTLDs comparable in size to the .US ccTLD. We used DomainTools TLD Statistics [3] as our data source. (Figure 1) We selected .eu, .ch (Switzerland), .pl (Poland), .es (Spain), and .us (United States). 

Figure 1. DomainTools: Domain Count Statistics for TLDs

Next, we built an analytical data set using the DomainTools Iris® Internet Intelligence Platform. [4] We selected all domains first seen within the last 90 days, filtering for those with a high risk score (95+ out of 100) according to DomainTools classifiers. (Table 1, Figure 2). The .us ccTLD risk ratio was more than triple that of the next highest (.pl) and 14 times higher than .es ccTLD. (Figure 3)

Table 1. Summary Table Derived from DomainTools using Iris

Figure 2. newly observed domain names with high risk domain names in per group within last 90 days
Figure 3. high risk domain names as % of total newly observed domains within last 90 days

While this data indicates a significantly higher reputational risk for the .us ccTLD, it does not explain possible reasons behind it. Machine Learning classifiers used for domain modeling consider numerous domain features, such as domain age, TLD, hosting provider, registration costs, domain name string patterns and length, registrar information, etc. [5-6]. Registrars play a crucial role in domain management. NameSilo and Namecheap have been flagged by Infoblox and the Interisle Consulting Group for lax oversight, [7-8] and are among those few that accept cryptocurrency payments, which is often an indicator of malicious activity. [9-10]

The correlation of the largest lax registrars with malicious .us ccTLD domains is dramatic.  As shown in Table 2, NameSilo, Namecheap and Porkbun are responsible for more than 75% of the malicious domain registrations. All of these accept cryptocurrency payment. 

Table 2. High-risk .us domains by Registrar

Finally, we enlisted Generative AI to help explain the poor performance of the .us ccTLD. We used both ChatGPT 4.0 and the Bing-Chat feature. While both Chat services provided good answers, we found that the Bing-Chat integration response far exceeded expectations in two respects as shown in Figures 4- 5: 

  • First, its answer succinctly approximated the answer we would have expected from a senior analyst after hours of research. (Figure 5) It highlighted with formatting three reasons: 1) less stringent registration requirements and lower costs, 2) less effective monitoring and enforcement of domain abuse, 3) higher perception of trust among users. We were particularly impressed that it cited the same recent KrebsonSecurity research referenced in our previous research with a link. As a bonus, it even found the image we are using for this post, even though we did not ask for it. [2] 
  • Second, the explanations it provided suggest opportunities for further research in future posts. Stay tuned.
Figure 4. Bing-Chat Integration Prompt for ‘why .US ccTLD has higher phishing rate’
Figure 5. Bing-Chat Integration Answer to prompt for ‘why .US ccTLD has higher phishing rate’


3 thoughts on "The .US Domain Registry cesspool – Part 2"

    1. Thanks for the comment. Generally, DomainTools would consider anything 70+ as high risk. The definition I used was 95+ on the DomainTools scale of 0 – 100

