Global DNS and domain activity in Q2 2024 shows a modest rise in newly registered domains (NRDs) and ongoing clustering around popular TLDs, registrars, and MX providers. The report highlights TLD distributions, registrar influence, MX DNS patterns, and IoCs, including hints of DNS tunneling activity; notable mentions include GoDaddy, Google MX resolutions, and (.ru, .cn, .in, .eu) domains, plus a notable .to IoC footprint. #GoDaddy #DNSTunneling
Keypoints
- NRDs in Q2 2024 rose 2.6% quarter-over-quarter, based on analysis of over 21.5 million domains.
- ccTLD registrations grew 6.6% and NRDs with gTLD extensions rose 1.4, signaling shifting domain usage patterns.
- For gTLDs, .com remained dominant, with .xyz, .shop, .org, and .top trailing; for ccTLDs, .cn led the pack, overtaking .uk from the prior quarter.
- Registrar distribution shows GoDaddy with 17.6% of NRDs; Namecheap ranked second, with Squarespace and Alibaba remaining in the top 10.
- In DNS activity, Google accounted for about 40.6% of MX resolutions over a 365-day window, with Google hosting 15 of the top MX FQDNs.
- An MX domain appeared in over 213.5 million resolutions within the top 100 MX FQDNs, but its mail servers did not; this suggests possible DNS tunneling activity.
- IoCs from 3.3 million malicious domains reveal continued use of popular gTLDs (.com/.org/.net) and ccTLDs (.ru/.cn/.in/.eu); notably, more than 24,000 IoCs used the .to extension, yet only 11 new .to domains were registered in Q2.
MITRE Techniques
- [T1583] Acquire Infrastructure β Domains β Malicious domains are registered and used as part of threat infrastructure; βThe malicious domains sported the .ru, .cn, .in, and .eu extensions, which also accounted for thousands of NRDs in Q2.β
- [T1572] Protocol Tunneling β DNS β DNS-based tunneling activities observed in IoCs; βa deeper investigation revealed that this MX domain could be involved in providing DNS tunneling services.β
Indicators of Compromise
- [Domain] IoCs tied to malicious activity using common and ccTLDs β .ru, .cn, .in, .eu, and other extensions; 3.3 million IoCs identified in Q2 2024
Read more: https://circleid.com/posts/20240719-global-dns-and-domain-activity-trends-in-q2-2024