Pith. sign in

REVIEW 1 cited by

Uncovering IP Address Hosting Types Behind Malicious Websites

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2111.00142 v2 pith:OQSGTUML submitted 2021-10-30 cs.CR cs.LG

classification cs.CRcs.LG
keywords domainshostingmalicioushostedprovidersattackershostservices
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Hundreds of thousands of malicious domains are created everyday. These malicious domains are hosted on a wide variety of network infrastructures. Traditionally, attackers utilize bullet proof hosting services (e.g. MaxiDed, Cyber Bunker) to take advantage of relatively lenient policies on what content they can host. However, these IP ranges are increasingly being blocked or the services are taken down by law enforcement. Hence, attackers are moving towards utilizing IPs from regular hosting providers while staying under the radar of these hosting providers. There are several practical advantages of accurately knowing the type of IP used to host malicious domains. If the IP is a dedicated IP (i.e. it is leased to a single entity), one may blacklist the IP to block domains hosted on those IPs as welll as use as a way to identify other malicious domains hosted the same IP. If the IP is a shared hosting IP, hosting providers may take measures to clean up such domains and maintain a high reputation for their users.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Mind the Gap: Policy vs Reality in Post-Quantum TLS Deployment

    cs.NI 2026-07 conditional novelty 6.0 of 10

    Across 684k consistently reachable domains, PQ-TLS adoption reached 49% by March 2026, almost entirely via X25519MLKEM768 and managed infrastructure, with no measurable latency increase.

Pith tools