The whole point of this "kill switch" is that it’s NOT registered. The malware uses it to detect if it runs in the sandbox, as researchers often make all DNS requests succeed in their sandbox. Checking for an domain known to be unregistered is one way of checking that.
How trivial it would be to append a random number at the end, or otherwise randomise it just a little bit.. Quite lucky the programmer didn't think this one through.
Yes, in another thread someone mentionned a trojan that hit five randomly-generated hostnames and, if they all resolve to the same IP, assumes its running in a sandbox.
It's not about the registration status of the domain. It is about an HTTP request succeeding. The same functionality could be achieved by using a valid registered domain with server not listening on the desired port.