Ransomware authors could come up with better flags than registering a domain since anyone can do it. Why not do something like creating an ipns address in ipfs and check if it contains something? Nobody but them would be able to put content at that address and can be checked through multiple gateways.