NEW | Hunt across all abuse.ch platforms with one simple query - discover if an IPv4 address, domain, URL or file hash has been identified on any platform from a centralized search tool. Test it out here hunting.abuse.ch - and happy hunting 🔍

Statistics

URLhaus produces detailed statistics on malicious URLs shared, including detections - find the available statistics below.

You can also access Spamhaus's Malware Digest report, based on URLhaus data:

Most Delivery Payload

Heodo

Show
Average Takedown Time

1 day, 2 hours, 34 minutes

Show
Top Malware Hosting Network

AS4134 CHINANET-BACKBONE

Show

Number of submissions (past 30 days)


The chart below documents the number of submissions (unique malware URL) to URLhaus per day over a period of 30 days.


Top Reporters


It wouldn't be possible to operate URLhaus without the help of volunteers who report malware URLs to URLhaus. The table below shows the top reporters and their Twitter handle.

RankReporterSubmissions
1 lrz_urlhaus1'249'315
2 geenensp775'997
3 Cryptolaemus1259'825
4 NDA0E176'466
5 Gandylyan1147'270
6 zbetcheckin136'265
7 tammeto73'499
8 abuse_ch64'749
9 abus3reports54'290
10 p5yb34m48'052
11 tolisec41'753
12 spamhaus39'159
13 DaveLikesMalwre36'614
14 Petras_Simeon26'161
15 shotgunner10119'210

Blocklist Comparison


URLhaus reports malware distribution sites to Spamhaus DBL, SURBL and Google Safe Browsing (GSB). In addition, several vendors of IT-security software are consuming URLhaus feeds to enrich their product(s). The statistics below measures the perfomance of several blocklists and DNS providers by counting the number of blacklisted domain names and compare them against each other.

Spamhaus DBL

SURBL

AdGuard DNS

Quad9 DNS

Cloudflare DNS

dns0.eu DNS

ProtonDNS

OpenBLD

Disclaimer: The blacklist comparison does only consider active malware distribution sites tracked by URLhaus.

Most Delivered Payload


Malware URLs deliver all kind of different payloads. This chart shows the number of payload per malware family (signature) identified / crawled by URLhaus.

Top Tags


Most seen tag associated with malware URLs tracked by URLhaus.

Top Malware Hosting Networks


The chart below shows the top malware hosting network by ASN. Please consider that some of them just offer CDN or proxy services and are hence not hosting the malicious content it self rather than facilitate delivering the malicious payload to the user.

Top malware hosting networks in total (counting online and offline malware distribution sites):

RankASNCountryAverage Reaction TimeMalware URLs
1AS4837 CHINA169-Backbone- CN2 days, 13 hours, 27 minutes917'600
2AS9829 BSNL-NIB- IN9 hours, 23 minutes428'537
3AS4134 CHINANET-BACKBONE- CN4 days, 5 hours, 45 minutes190'588
4AS17488 HATHWAY-NET-AP- IN6 hours, 1 minutes142'644
5AS8661 PTK- AL2 days, 1 hours, 28 minutes97'550
6AS207569 I-SERVERS-NORTH-EU- RU23 hours, 17 minutes91'338
7AS13335 CLOUDFLARENET- US3 days, 6 hours, 50 minutes89'218
8AS17816 CHINA169-GZ- CN1 day, 9 hours, 28 minutes84'920
9AS14061 DIGITALOCEAN-ASN- US4 days, 9 hours, 13 minutes58'244
10AS17622 CNCGROUP-GZ- CN22 hours, 37 minutes50'855
11AS46606 UNIFIEDLAYER-AS-1- US13 days, 22 hours, 44 minutes47'192
12AS16509 AMAZON-02- US3 days, 9 hours, 47 minutes39'464
13AS19871 NETWORK-SOLUTIONS-HOSTING- US13 days, 7 hours, 17 minutes37'460
14AS16276 OVH- FR10 days, 7 hours, 39 minutes33'603
15AS36352 AS-COLOCROSSING- US11 days, 3 hours, 4 minutes32'263

Top malware hosting networks, hosting active malware content (counting online malware distribution sites only):

RankASNCountryASN-DROP Average Reaction TimeMalware URLs
1AS36459 GITHUB- US 17 days, 18 hours, 28 minutes2'400
2AS20940 AKAMAI-ASN1- US 16 days, 20 hours, 14 minutes1'097
3AS56873 ELITETEAM-ANTIDDOS- SCBlocked 2 months, 3 days, 9 hours, 13 minutes849
4AS54113 FASTLY- DE 24 days, 21 hours, 5 minutes536
5AS4837 CHINA169-Backbone- CN 2 days, 13 hours, 27 minutes349
6AS13335 CLOUDFLARENET- US 3 days, 6 hours, 50 minutes226
7AS4134 CHINANET-BACKBONE- CN 4 days, 5 hours, 44 minutes202
8AS36352 AS-COLOCROSSING- US 11 days, 3 hours, 4 minutes189
9AS215240 NETRESEARCH- GBBlocked 7 days, 11 hours, 1 minutes175
10AS37963 ALIBABA-CN-NET- CN 1 month, 18 days, 0 hours, 14 minutes151
11AS9829 BSNL-NIB- IN 9 hours, 23 minutes139
12AS60223 NETIFACE-AS- GB 3 days, 14 hours, 0 minutes136
13AS214943 RAILNET- USBlocked 7 days, 9 hours, 21 minutes133
14AS215540 GCS-AS- RU 8 days, 18 hours, 45 minutes102
15AS7713 telkomnet-as-ap- ID 1 month, 9 days, 22 hours, 0 minutes96

Takedown Statistics


URLhaus is sending out abuse reports to hosting providers, hosting malware distribution sites. The following chart shows the number of active malware distribution sites and the number of unique abuse reports sent per day.


The following table shows the top 15 hosting providers with the fastest abuse desks. To generated these statistics, URLhaus measures the time between when URLhaus sent the abuse complaint to the hosting provider and when the reported content goes offline. Please consider that the accuracy is +/- 1 hour.

RankASN GoodCountryOnlineOfflineAverage Reaction Time
1AS58772 ChinaNet-Fujian-Fuzhou-IDC- CN010 minute
2AS13022 STREAMS_GMBH- AT015 minutes
3AS52564 Biazi_Telecom- BR016 minutes
4AS7020 QDATA-AS- NZ017 minutes
5AS263948 NEW_LIFE_TELECOM- BR017 minutes
6AS197684 ASHOSTUA- UA027 minutes
7AS134929 ORANGECITY-AS- None017 minutes
8AS55441 TTSLMEIS-AS-AP- IN017 minutes
9AS55486 NETWORX-AS-AP- None018 minutes
10AS268490 A.I.P._INTERNET- BR019 minutes
11AS267060 Jspnet_servios_de_comunicaes_multimidia_eireli- None019 minutes
12AS268824 CONNECTMAX_TELECOM- BR0210 minutes
13AS139261 METROLINK-AS-AP- None0210 minutes
14AS19517 VISUAL-LINK-INOC- US0110 minutes
15AS267270 MV_COMUNICACOES_LTDA_-_ME- BR0110 minutes

The following table shows the top 15 hosting providers with the slowest abuse desks. To generated these statistics, URLhaus measures the time between when URLhaus sent the abuse complaint to the hosting provider and when the reported content goes offline. Please consider that the accuracy is +/- 1 hour.

RankASN PoorCountryOnlineOfflineAverage Reaction Time
1AS23520 LIBERTY-NETWORKS- US014 years, 6 months, 14 days, 16 hours, 19 minutes
2AS6 BULL-HN- US014 years, 2 months, 23 days, 19 hours, 10 minutes
3AS10099 UNICOM-Global- HK0113 years, 9 months, 6 days, 10 hours, 11 minutes
4AS197838 CHEELOO-AS- PL013 years, 8 months, 1 days, 17 hours, 58 minutes
5AS199391 XGlobe-199391- IL033 years, 6 months, 25 days, 19 hours, 21 minutes
6AS44547 NetundWeb- TR013 years, 5 months, 20 days, 12 hours, 33 minutes
7AS263057 Connect_Network- BR013 years, 5 months, 14 days, 4 hours, 29 minutes
8AS12556 internet-solutions-ke- ZA023 years, 3 months, 11 days, 21 hours, 28 minutes
9AS24164 UBBNET-AS-TW- TW313 years, 1 months, 15 days, 18 hours, 40 minutes
10AS30782 TOYA-KRAKOW-AS- PL013 years, 1 months, 4 days, 20 hours, 34 minutes
11AS37024 Yoprov- ZW012 years, 9 months, 27 days, 23 hours, 58 minutes
12AS60822 WISP1- IT012 years, 9 months, 15 days, 2 hours, 6 minutes
13AS9811 DRCSCNET- CN222 years, 9 months, 5 days, 8 hours, 32 minutes
14AS10292 CWJ-1- US112 years, 7 months, 25 days, 16 hours, 36 minutes
15AS39513 ONECOM-AS- UA012 years, 7 months, 2 days, 21 hours, 22 minutes

The full list of average reaction time over all hosting providers (ASNs) can be found here:

If you are a hosting provider, network owner or national CERT, you can subscribe to the URLhaus feed for your ASN or country here: