Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

White Papers

What Do You Pay For When Buying Commercial Internet Intelligence Data

Developing an effective cybersecurity product takes more than code — it demands access to trusted, high-coverage Internet intelligence.

Free data feeds can help, but they often lack accuracy, depth, and long-term reliability. Building your own data pipelines can offer more control but comes with substantial technical and maintenance costs.

Who Dominates the Internet? A Look at the Top Domain Registrars and Registrant Countries across TLDs

With thousands of gTLDs and ccTLDs to choose from, individuals and organizations wanting to build their online presence have limitless options. Determining which entities and registrant countries are behind the domain registrations can provide relevant insights into registrant preferences. 

The WhoisXML API research team set out to analyze hundreds of millions of domains under selected gTLDs and ccTLDs, allowing us to identify:

Decoding ASN and ISP Data for In-Depth Business Insights

The Internet relies on autonomous systems (ASs) and internet service providers (ISPs) to enable global connectivity. Understanding how Internet traffic is routed through these entities is crucial for improving routing performance and avoiding networking bottlenecks.

Moreover, insights into AS and ISP distribution offer valuable information that organizations can leverage for strategic business and market analysis. With this perspective in mind, the WhoisXML API research team analyzed 4.4 million IP ranges, uncovering findings such as:

Early Homograph Threat Detection: A DNS Study of IDNs and Native-Language Characters

While businesses gained an advantage by using domains with native-language characters to enter local markets, the utilization of Punycode also gave threat actors more leeway to create look-alike domains.

The WhoisXML API research team analyzed the TLD distribution, IP resolution, and WHOIS registration data of 63,105 unique FQDNs containing native-language characters. We also zoomed in on the FQDN dynamics and took a closer look at some homograph clusters, among other checks.

Our analysis yielded these interesting findings, among others:

A Study of APT Groups Known for Targeting European Countries

Europe is home to many international organizations like Europol, INTERPOL, and NATO, among others. That makes it a prime APT group target.

The WhoisXML API research team analyzed the latest attacks launched by six APT groups known for trailing their sights on Europe using current and historical WHOIS and passive DNS data. We uncovered:

A Study of APT Groups Known for Targeting North American Countries

At least 41 advanced persistent threat (APT) groups have reportedly targeted North American countries over the past two decades. And their targets have ranged from individuals (e.g., field experts and think tanks) to entire sectors (e.g., industrial and government).

The WhoisXML API research team analyzed the inner workings of seven of these APT groups1—APT33, APT41, FIN7, Kimsuky, Molerats, Turla, and ZIRCONIUM—by expanding 59 indicators of compromise (IoCs) associated with their latest attacks.

Our study of the seven APT groups known for targeting North America led to the discovery of:

2023 IoC List Expansion for APAC-Based/Targeting APT Groups

WhoisXML API researchers leveraged historical WHOIS intelligence to expand lists of indicators of compromise (IoCs) connected to six APT groups, namely, APT29, APT32, Earth Lusca, Higaisa, Sandworm Team, and Turla.

The report examined the publicly exposed email WHOIS footprints of domain IoCs reported to belong to APT groups. From 44 IoCs studied, we found:

DNS Abuse Trends: Dissecting the Domains Under the Most-Abused TLDs

As DNS abuse and cybercrime remain two sides of the same coin, WhoisXML API researchers decided to build on Spamhaus’s list of TLDs with the worst reputation for spamming.1

Using our WHOIS and DNS intelligence, we retrieved and analyzed thousands of domains under these TLDs that were added in Q4 2022. Our key findings revealed that:

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.