Skip to content

Hide Navigation Hide TOC

Domain Registration (ff9b665a-598b-4bcb-8b2a-a87566aa1256)

"Domain Name: Domain Registration" data component captures information about the assignment, ownership, and metadata of domain names. This information is often sourced from registries like WHOIS and includes details such as registrant names, contact information, registration dates, expiration dates, and registrar details. This data is invaluable for tracking domain ownership, detecting malicious domain registrations, and identifying trends in adversary behavior. Examples:

  • Registrant Information: WHOIS lookup of example.com
  • Registration and Expiration Dates: A domain registered a week before being used in phishing attacks.
  • Domain Status: Status codes like clientTransferProhibited or serverHold indicate domain restrictions or potential hijacking activity.
  • Name Server Information: Name servers point to a public DNS provider often associated with malicious campaigns.
  • Privacy Protection: A domain uses WHOIS privacy protection to hide registrant details.

This data component can be collected through the following measures:

  • WHOIS Services: Use tools or services to perform WHOIS lookups:
  • WHOIS APIs: Automate domain registration lookups with APIs:
  • Registrar Platforms: Directly query domain registrars (e.g., GoDaddy, Namecheap) for detailed registration data.
  • Threat Intelligence Platforms: Integrate domain registration data from services like Recorded Future, RiskIQ, or PassiveTotal for enriched analysis.
Cluster A Galaxy A Cluster B Galaxy B Level
Domain Registration (ff9b665a-598b-4bcb-8b2a-a87566aa1256) mitre-data-component Compromise Infrastructure - T1584 (7e3beebd-8bfe-4e7b-a892-e44ab06a75f9) Attack Pattern 1
Domain Registration (ff9b665a-598b-4bcb-8b2a-a87566aa1256) mitre-data-component Acquire Infrastructure - T1583 (0458aab9-ad42-4eac-9e22-706a95bafee2) Attack Pattern 1
Domains - T1583.001 (40f5caa0-4cb7-4117-89fc-d421bb493df3) Attack Pattern Domain Registration (ff9b665a-598b-4bcb-8b2a-a87566aa1256) mitre-data-component 1
Domain Registration (ff9b665a-598b-4bcb-8b2a-a87566aa1256) mitre-data-component Domains - T1584.001 (f9cc4d06-775f-4ee1-b401-4e2cc0da30ba) Attack Pattern 1
Domain Registration (ff9b665a-598b-4bcb-8b2a-a87566aa1256) mitre-data-component Hide Infrastructure - T1665 (eb897572-8979-4242-a089-56f294f4c91d) Attack Pattern 1
Domains - T1583.001 (40f5caa0-4cb7-4117-89fc-d421bb493df3) Attack Pattern Acquire Infrastructure - T1583 (0458aab9-ad42-4eac-9e22-706a95bafee2) Attack Pattern 2
Compromise Infrastructure - T1584 (7e3beebd-8bfe-4e7b-a892-e44ab06a75f9) Attack Pattern Domains - T1584.001 (f9cc4d06-775f-4ee1-b401-4e2cc0da30ba) Attack Pattern 2