Scams & Phishing News Massive spike in use of .es domains for phishing abuse

Parkinsond

Level 23
Thread author
Dec 6, 2023
1,245
Because you have an entire continent (except Brazil) plus Spain speaking Spanish.

Cybersecurity experts are reporting a 19x increase in malicious campaigns being launched from .es domains, making it the third most common, behind only .com and .ru.

The .es top-level domain (TLD) is the domain reserved for the country of Spain, or websites targeting Spanish-speaking audiences.

Cofense said the abuse of the .es TLD started to pick up in January, and as of May, 1,373 subdomains were hosting malicious web pages on 447 .es base domains.

The researchers said that 99 percent of these were focused on credential phishing, while the other 1 percent were devoted to distributing remote access trojans (RATs) such as ConnectWise RAT, Dark Crystal, and XWorm.
 

Marko :)

Level 26
Verified
Top Poster
Well-known
Aug 12, 2015
1,573
A lot of countries have very relaxed rules for registering their ccTLDs and this is what leads to abuse. Mine is very strict and also the reason why you never see .hr,.com.hr or .iz.hr/.from.hr associated with malicious activity. Foreigners living outside EU can't even register it. On the other hand, anyone can register .com.hr domain, but needs to provide government-issued document to verify the identitity. If you don't pass verification, or refuse to provide government-issued ID, registration is automatically cancelled.

Beside, paid .hr domains are expensive (65-85€ registration fee, around 80€ yearly extension).

Screenshot_2.png
Screenshot_3.png
 

Parkinsond

Level 23
Thread author
Dec 6, 2023
1,245
A lot of countries have very relaxed rules for registering their ccTLDs and this is what leads to abuse. Mine is very strict and also the reason why you never see .hr,.com.hr or .iz.hr/.from.hr associated with malicious activity. Foreigners living outside EU can't even register it. On the other hand, anyone can register .com.hr domain, but needs to provide government-issued document to verify the identitity. If you don't pass verification, or refuse to provide government-issued ID, registration is automatically cancelled.

Beside, paid .hr domains are expensive (65-85€ registration fee, around 80€ yearly extension).

View attachment 289410 View attachment 289411
I thought all EU members have similar standards!
 
  • Like
Reactions: Marko :)

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top