Table of Contents
Fetching ...

Infrastructure Patterns in Toll Scam Domains: A Comprehensive Analysis of Cybercriminal Registration and Hosting Strategies

Morium Akter Munny, Mahbub Alam, Sonjoy Kumar Paul, Daniel Timko, Muhammad Lutfor Rahman, Nitesh Saxena

TL;DR

This study presents the first large-scale analysis of toll scam domain infrastructure using a dataset of 67,907 verified scam domains. It uncovers extreme concentration in five non-mainstream TLDs and across a few registrars, along with highly coordinated bursts of registrations in early 2025. A lightweight model based solely on registration metadata achieves 80.4% accuracy and 92.3% sensitivity in predicting suspension, offering an actionable early-warning signal. The findings inform registrar and hosting-provider interventions, though the authors note that richer features from URL and content could further enhance detection capabilities.

Abstract

Toll scams involve criminals registering fake domains that pretend to be legitimate transportation agencies to trick users into making fraudulent payments. Although these scams are rapidly increasing and causing significant harm, they have not been extensively studied. We present the first large-scale analysis of toll scam domains, using a newly created dataset of 67,907 confirmed scam domains mostly registered in 2025. Our study reveals that attackers exploit permissive registrars and less common top-level domains, with 86.9% of domains concentrated in just five non-mainstream TLDs and 72.9% registered via a single provider. We also discover specific registration patterns, including short bursts of activity that suggest automated, coordinated attacks, with over half of domains registered in the first quarter of 2025. This extreme temporal clustering reflects highly synchronized campaign launches. Additionally, we build a simple predictive model using only domain registration data to predict which scam domains are likely to be suspended -- a proxy for confirmed abuse -- achieving 80.4% accuracy, and 92.3% sensitivity. Our analysis reveals attacker strategies for evading detection -- such as exploiting obscure TLDs, permissive registrars, and coordinated registration bursts -- which can inform more targeted interventions by registrars, hosting providers, and security platforms. However, our results suggest that registration metadata alone may be insufficient, and incorporating features from domain URLs and webpage content could further improve detection.

Infrastructure Patterns in Toll Scam Domains: A Comprehensive Analysis of Cybercriminal Registration and Hosting Strategies

TL;DR

This study presents the first large-scale analysis of toll scam domain infrastructure using a dataset of 67,907 verified scam domains. It uncovers extreme concentration in five non-mainstream TLDs and across a few registrars, along with highly coordinated bursts of registrations in early 2025. A lightweight model based solely on registration metadata achieves 80.4% accuracy and 92.3% sensitivity in predicting suspension, offering an actionable early-warning signal. The findings inform registrar and hosting-provider interventions, though the authors note that richer features from URL and content could further enhance detection capabilities.

Abstract

Toll scams involve criminals registering fake domains that pretend to be legitimate transportation agencies to trick users into making fraudulent payments. Although these scams are rapidly increasing and causing significant harm, they have not been extensively studied. We present the first large-scale analysis of toll scam domains, using a newly created dataset of 67,907 confirmed scam domains mostly registered in 2025. Our study reveals that attackers exploit permissive registrars and less common top-level domains, with 86.9% of domains concentrated in just five non-mainstream TLDs and 72.9% registered via a single provider. We also discover specific registration patterns, including short bursts of activity that suggest automated, coordinated attacks, with over half of domains registered in the first quarter of 2025. This extreme temporal clustering reflects highly synchronized campaign launches. Additionally, we build a simple predictive model using only domain registration data to predict which scam domains are likely to be suspended -- a proxy for confirmed abuse -- achieving 80.4% accuracy, and 92.3% sensitivity. Our analysis reveals attacker strategies for evading detection -- such as exploiting obscure TLDs, permissive registrars, and coordinated registration bursts -- which can inform more targeted interventions by registrars, hosting providers, and security platforms. However, our results suggest that registration metadata alone may be insufficient, and incorporating features from domain URLs and webpage content could further improve detection.
Paper Structure (31 sections, 6 figures)

This paper contains 31 sections, 6 figures.

Figures (6)

  • Figure 1: The Toll Scam Attack Life Cycle
  • Figure 2: Distribution of domain suspension rates across ASNs. Suspension rates range from 0.0% to 98.1% across hosting providers, with sample sizes indicated.
  • Figure 3: Comparison of IP address clustering between suspended and active toll scam domains. Suspended domains show significantly higher clustering compared to active domains.
  • Figure 4: TLD concentration patterns showing extreme concentration in non-mainstream TLDs. The donut chart emphasizes the total scale of 67,907 domains while highlighting the systematic preference for non-mainstream TLDs. The visualization clearly demonstrates the deliberate avoidance of traditional, well-monitored domain spaces.
  • Figure 5: Registrar concentration patterns illustrating remarkable concentration through a horizontal bar chart. The annotations highlight how the top three registrars account for 91.8% of all registrations. The visualization emphasizes the systematic targeting of registrars with minimal verification requirements.
  • ...and 1 more figures