Uncovering Potential Black Friday and Thanksgiving Threats with DNS Data | WhoisXML API

Threat Reports

Uncovering Potential Black Friday and Thanksgiving Threats with DNS Data

Thanksgiving may be one of the most awaited holidays in the U.S. along with the day of the biggest sale—Black Friday—typically associated with it. Unfortunately, cybercriminals also lie in wait for unwitting people in search of the best promos and biggest discounts to visit their malware-laden web pages.

We obtained a sample of 2,324 domains containing the text strings blackfriday and thanksgiving from the First Watch Malicious Domains Data Feed and analyzed their DNS footprint.

The WhoisXML API research team’s in-depth DNS investigation led to the discovery of:

  • 318 email-connected domains, one of which turned out to be malicious
  • 786 IP addresses, 635 of which turned out to be malicious
  • 1,975 IP-connected domains, two of which turned out to be malicious
  • 3,521 string-connected subdomains

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

Try our WhoisXML API for free
Get started