Threat intelligence API Docs Pricing Solutions Resources Contact us

Threat reports

Read other reports

Profiling a Massive Portfolio of Domains Involved in Ransomware Campaigns





Ransomware is a real and immense threat that can cost organizations millions or, worse, their reputation after a potential data exposure.

To help the cybersecurity community and law enforcement agencies with threat attribution, detection, and disruption, TIP researchers analyzed a sample taken from 62,000+ domains known to be involved in ransomware campaigns. Our key findings include:

  • A total of 72.7% of the domains had unredacted WHOIS records.
  • DropCatch was the top registrar, while Team Internet AG was the leading ISP.
  • About 36% of the domains were less than a year old and newly or recently registered upon weaponization.
  • The U.S. was the top registrant country and IP geolocation.

Download a sample of the threat research materials now.

Read other reports
To download the full report in PDF, please fill in the form.
I have read and agree to the Terms of Service and Privacy Policy
Please keep me updated on news, events, and offers.

Try our Threat Intelligence API for free

Get FREE trial
Have questions?

We work hard to improve our services for you. As part of that, we welcome your feedback, questions and suggestions. Please let us know your thoughts and feelings, and any way in which you think we can improve our product.

For a quick response, please select the request type that best suits your needs.

Or shoot us an email to

Threat Intelligence Platform uses cookies to provide you with the best user experience on our website. They also help us understand how our site is being used. Find out more here. By continuing to use our site you consent to the use of cookies.