Summary

X-Force has identified a new squatting campaign used by threat actors to target the media sector. The campaign has a global scope assumingly luring users into giving away their login credentials.

Threat Type

Squatting Domain, Phishing Domain, Credential Theft

Overview

We observed 19 squatting domain registrations related to a victim in the media sector. The campaign was identified starting with the registration on 2022-07-27 04:48:11 up to the latest registration on 2022-08-03 12:39:27.

For all registered domains we could identify NameCheap, Inc. as the registrar based in Iceland. The email address used for registering the domains was anonymized.

In addition we were also able to resolve the following IPs as well as the ASNs to the registered domains:

Domain: 1-youtubee.xyz
Resolved IP: 66.29.137.14
ASN: AS22612
ASN country: United States

Domain: 11-youtubee.xyz
Resolved IP: 192.64.119.79
ASN: AS22612
ASN country: United States

Domain: 12-youtubee.xyz
Resolved IP: 192.64.119.221
ASN: AS22612
ASN country: United States

Domain: 13-youtubee.xyz
Resolved IP: 192.64.119.238
ASN: AS22612
ASN country: United States

Domain: 14-youtubee.xyz
Resolved IP: 162.255.119.81
ASN: AS22612
ASN country: United States

Domain: 15-youtubee.xyz
Resolved IP: 162.255.119.164
ASN: AS22612
ASN country: United States

Domain: 16-youtubee.xyz
Resolved IP: 162.255.119.140
ASN: AS22612
ASN country: United States

Domain: 17-youtubee.xyz
Resolved IP: 192.64.119.81
ASN: AS22612
ASN country: United States

Domain: 18-youtubee.xyz
Resolved IP: 162.255.119.115
ASN: AS22612
ASN country: United States

Domain: 19-youtubee.xyz
Resolved IP: 192.64.119.135
ASN: AS22612
ASN country: United States

Domain: 2-youtubee.xyz
Resolved IP: 162.255.119.12
ASN: AS22612
ASN country: United States

Domain: 20-youtubee.xyz
Resolved IP: 192.64.119.70
ASN: AS22612
ASN country: United States

Domain: 3-youtubee.xyz
Resolved IP: 192.64.119.217
ASN: AS22612
ASN country: United States

Domain: 4-youtubee.xyz
Resolved IP: 162.255.119.244
ASN: AS22612
ASN country: United States

Domain: 5-youtubee.xyz
Resolved IP: 192.64.119.11
ASN: AS22612
ASN country: United States

Domain: 6-youtubee.xyz
Resolved IP: 192.64.119.167
ASN: AS22612
ASN country: United States

Domain: 7-youtubee.xyz
Resolved IP: 162.255.119.247
ASN: AS22612
ASN country: United States

Domain: 8-youtubee.xyz
Resolved IP: 162.255.119.93
ASN: AS22612
ASN country: United States

Domain: 9-youtubee.xyz
Resolved IP: 192.64.119.125
ASN: AS22612
ASN country: United States

However the registrar NameCheap, Inc. covers a pool of 178.483.157 domains where at least 0.15% can be considered as potentially malicious.

The following list shows the nameserver that are configured as authoritative nameservers for the domain and their malicious score which is the percentage of malicious domains with the same nameserver.

Domain: 1-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 1-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 11-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 11-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 12-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 12-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 13-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 13-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 14-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 14-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 15-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 15-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 16-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 16-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 17-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 17-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 18-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 18-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 19-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 19-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 2-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 2-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 20-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 20-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 3-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 3-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 4-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 4-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 5-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 5-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 6-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 6-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 7-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 7-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 8-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 8-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 9-youtubee.xyz
Name server: dns1.namecheaphosting.com
Name server malicious score: 0.39%

Domain: 9-youtubee.xyz
Name server: dns2.namecheaphosting.com
Name server malicious score: 0.39%

Not forgetting to mention the WhoIs Server: X-Force was able to retrieve the WhoIs server information where we were also able to determine the number of domains each WhoIs server manages and as well adding the malicious rating of the domains in the pool.

Domain: 1-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 11-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 12-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 13-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 14-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 15-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 16-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 17-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 18-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 19-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 2-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 20-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 3-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 4-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 5-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 6-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 7-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 8-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Domain: 9-youtubee.xyz
Whois server: whois.namecheap.com
Whois server malicious score: 0.15%

Recommendations

  • Do not click or open links in mails directly, instead type in the main URL in your browser or search the brand/company via your preferred search engine.
  • Ensure anti-virus software and associated files are up to date.
  • Search for existing signs of the indicated IOCs in your environment.
  • Block all URL and IP based IOCs at the firewall, IDS, web gateways, routers or other perimeter-based devices, a course of action, resources or applications to remediate this threat.
  • Keep applications and operating systems running at the current released patch level.

Reference

Proprietary IBM X-Force Threat Intelligence

Similar Posts