logo

Parked Domains Become Weapons with Direct Search Advertising

ID: cafa1c36-a03f-512d-861a-4957bb62a4e1

STIX ID: report--cafa1c36-a03f-512d-861a-4957bb62a4e1

Feed Name: Infoblox Blog

Threat Score
78/100

Date Published: 2025-12-16

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

This report analyzes how parked and lookalike domains are weaponized through direct-search/zero-click parking and traffic distribution systems to deliver scams, scareware, and malware. It profiles three distinct domain portfolio operators — a torresdns holder with ~3,000 lookalikes (including gmai.com), a double "fast flux" operator rotating authoritative name servers and IPs (e.g., ic3.org), and domaincntrol.com which typos GoDaddy’s name servers and selectively targets Cloudflare (1.1.1.1) users — and details techniques such as device fingerprinting, multi-stage TDS redirection, cloaking, name server typosquatting, and selective resolver responses. The investigation observed active exploitation (Tedy, Babar, ClickFix attacks, BEC via typosquat mail) and provides indicators including SHA256 hashes, domains, nameserver domains, and IP addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.