WHOIS API
Analysis of Funnull Infrastructure and Typosquatting Domains
Pages
21
Time to read
14 mins
Language
English
Pages
21
Time to read
14 mins
Language
English
This technical report presents an analysis of the Funnull infrastructure, which has been linked to cryptocurrency investment fraud scams, based on indicators of compromise (IoCs) provided by the FBI. The report outlines the extraction of 176,656 root domains from two lists, which include 549 Funnull CNAMEs and 332,696 URLs. The analysis reveals that 101,123 new typosquatting domains were identified, with 82,261 of these domains likely to turn malicious upon creation. The report details the DNS traffic data collected from the Internet Abuse Signal Collective (IASC), which recorded significant querying activity across various client IP addresses. Additionally, the report investigates the geographical distribution of IP addresses and registrant countries, highlighting overlaps between the FBI domains and the newly identified typosquatting domains. The findings underscore the importance of monitoring these domains to mitigate potential threats associated with the Funnull infrastructure.