A DNS Investigation of SEO Manipulation via Bad Seed BadIIS | WhoisXML API

A DNS Investigation of SEO Manipulation via Bad Seed BadIIS

Search engine optimization (SEO) manipulation campaigns are not necessarily new in the cybercrime world. Many attacks often target users of popular software and services.

A new report featured such a threat dubbed “BadIIS” that has been trailing its sights on Internet Information Services (IIS) users.1 The campaign redirected victims from Asian countries to illegal gambling websites. The report identified 51 indicators of compromise (IoCs).2

WhoisXML API dove deep into the threat aided by our comprehensive DNS intelligence and found other potentially connected artifacts comprising:

  • 738 email-connected domains, two of which turned out to ba malicious
  • 29 additional IP addresses, 17 of which were associated with various threats
  • 335 IP-connected domains
  • 1,184 string-connected domains, nine of which have already been weaponized for various campaigns

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://www.trendmicro.com/en_us/research/25/b/chinese-speaking-group-manipulates-seo-with-badiis.html
  • [2] https://documents.trendmicro.com/assets/txt/badiis-IOCspbJhGdi.txt
Try our WhoisXML API for free
Get started