Statistics

Most Delivery Payload

Heodo

Show
Average Takedown Time

3 days, 2 hours, 51 minutes

Show
Top Malware Hosting Network

AS4134 CHINANET-BACKBONE

Show

Number of submissions (past 30 days)


The chart below documents the number of submissions (unique malware URL) to URLhaus per day over a period of 30 days.


Top Reporters


It wouldn't be possible to operate URLhaus without the help of volunteers who report malware URLs to URLhaus. The table below shows the top reporters and their Twitter handle.

RankReporterSubmissions
1 lrz_urlhaus1'183'865
2 geenensp452'362
3 Cryptolaemus1257'352
4 zbetcheckin130'579
5 Gandylyan1121'101
6 tammeto71'515
7 abuse_ch52'278
8 p5yb34m48'052
9 spamhaus38'730
10 tolisec35'648
11 Petras_Simeon26'161
12 shotgunner10119'193
13 r3dbU7z19'057
14 JayTHL19'037
15 0xrb13'773

Blocklist Comparison


URLhaus reports malware distribution sites to Spamhaus DBL, SURBL and Google Safe Browsing (GSB). In addition, several vendors of IT-security software are consuming URLhaus feeds to enrich their product(s). The statistics below measures the perfomance of several blocklists and DNS providers by counting the number of blacklisted domain names and compare them against each other.

Spamhaus DBL

SURBL

AdGuard DNS

Quad9 DNS

Cloudflare DNS

dns0.eu DNS

ProtonDNS

Disclaimer: The blacklist comparison does only consider active malware distribution sites tracked by URLhaus.

Most Delivered Payload


Malware URLs deliver all kind of different payloads. This chart shows the number of payload per malware family (signature) identified / crawled by URLhaus.

Top Tags


Most seen tag associated with malware URLs tracked by URLhaus.

Top Malware Hosting Networks


The chart below shows the top malware hosting network by ASN. Please consider that some of them just offer CDN or proxy services and are hence not hosting the malicious content it self rather than facilitate delivering the malicious payload to the user.

Top malware hosting networks in total (counting online and offline malware distribution sites):

RankASNCountryAverage Reaction TimeMalware URLs
1AS4837 CHINA169-BACKBONE CHINA UNICOM China169 Backbone- CN2 days, 15 hours, 25 minutes734'947
2AS9829 BSNL-NIB National Internet Backbone- IN9 hours, 41 minutes251'143
3AS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CN4 days, 1 hours, 42 minutes164'349
4AS17488 HATHWAY-NET-AP Hathway IP Over Cable Internet- IN5 hours, 45 minutes141'418
5AS8661 PTK PTK IP/MPLS Network- AL2 days, 1 hours, 21 minutes97'519
6AS17816 CHINA169-GZ China Unicom IP network China169 Guangdong province- CN1 day, 8 hours, 7 minutes82'473
7AS46606 UNIFIEDLAYER-AS-1- US13 days, 22 hours, 8 minutes67'942
8AS13335 CLOUDFLARENET- US3 days, 11 hours, 12 minutes61'860
9AS14061 DIGITALOCEAN-ASN- US4 days, 6 hours, 51 minutes54'314
10AS17622 CNCGROUP-GZ China Unicom Guangzhou network- CN22 hours, 38 minutes50'801
11AS15169 GOOGLE- US10 days, 14 hours, 24 minutes40'044
12AS16276 OVH- FR10 days, 5 hours, 50 minutes29'081
13AS8075 MICROSOFT-CORP-MSN-AS-BLOCK- US11 days, 1 hours, 0 minutes28'370
14AS36352 AS-COLOCROSSING- US11 days, 8 hours, 59 minutes24'761
15AS26496 AS-26496-GO-DADDY-COM-LLC- US19 days, 13 hours, 27 minutes24'117

Top malware hosting networks, hosting active malware content (counting online malware distribution sites only):

RankASNCountryAverage Reaction TimeMalware URLs
1AS211252 AS_DELIS- US12 days, 13 hours, 54 minutes315
2AS4766 KIXS-AS-KR Korea Telecom- KR25 days, 14 hours, 12 minutes210
3AS36459 GITHUB- US7 days, 23 hours, 49 minutes134
4AS203727 ALTAWK- UA8 days, 23 hours, 45 minutes123
5AS133530 ATLASSIANPTY-AS-AP ATLASSIAN PTY LTD- AU1 month, 9 days, 8 hours, 58 minutes90
6AS15169 GOOGLE- US10 days, 14 hours, 24 minutes79
7AS13335 CLOUDFLARENET- US3 days, 11 hours, 12 minutes57
8AS4837 CHINA169-BACKBONE CHINA UNICOM China169 Backbone- CN2 days, 15 hours, 25 minutes57
9AS36352 AS-COLOCROSSING- US11 days, 8 hours, 59 minutes54
10AS9416 MULTIMEDIA-AS-AP Hoshin Multimedia Center Inc.- TW2 months, 21 days, 19 hours, 47 minutes48
11AS49943 ITRESHENIYA-AS- RU25 days, 4 hours, 27 minutes46
12AS131596 TBCOM-NET TBC- TW2 months, 12 days, 7 hours, 14 minutes45
13AS211409 GALAXY-AS- RU1 month, 2 days, 20 hours, 11 minutes43
14AS7922 COMCAST-7922- US1 month, 19 days, 23 hours, 4 minutes41
15AS49870 AS49870-BV- NL8 days, 9 hours, 15 minutes40

Takedown Statistics


URLhaus is sending out abuse reports to hosting providers, hosting malware distribution sites. The following chart shows the number of active malware distribution sites and the number of unique abuse reports sent per day.


The following table shows the top 15 hosting providers with the fastest abuse desks. To generated these statistics, URLhaus measures the time between when URLhaus sent the abuse complaint to the hosting provider and when the reported content goes offline. Please consider that the accuracy is +/- 1 hour.

RankASN GoodCountryOnlineOfflineAverage Reaction Time
1AS25369 BANDWIDTH-AS- CH025 minutes
2AS64050 BCPL-SG BGPNET Global ASN- CN215 minutes
3AS13022 STREAMS_GMBH- AT015 minutes
4AS133983 SBB-AS-IN Shivraj Broadband Internet Pvt Ltd- IN035 minutes
5AS197746 HYPERHOSTING Georgios Vardikos trading as HYPERHOSTING- GR016 minutes
6AS52564 Biazi Telecomunicacoes Ltda Epp- BR016 minutes
7AS7020 QDATA-AS- ZA017 minutes
8AS263948 NEW LIFE TELECOM- BR017 minutes
9AS134013 MASSSOHN-AS-IN Mass Computer- IN017 minutes
10AS197684 ASHOSTUA- US027 minutes
11AS134929 ORANGECITY-AS ORANGE CITY INTERNET SERVICES PVT. LTD.- IN017 minutes
12AS55486 NETWORX-AS-AP Networx Australia- AU018 minutes
13AS269715 INFINITYGO TELECOM LTDA- BR018 minutes
14AS41634 SVEA- GB018 minutes
15AS42960 CLOUD-MANAGEMENT-LLC- US019 minutes

The following table shows the top 15 hosting providers with the slowest abuse desks. To generated these statistics, URLhaus measures the time between when URLhaus sent the abuse complaint to the hosting provider and when the reported content goes offline. Please consider that the accuracy is +/- 1 hour.

RankASN PoorCountryOnlineOfflineAverage Reaction Time
1AS23520 COLUMBUS-NETWORKS- BS014 years, 6 months, 14 days, 16 hours, 19 minutes
2AS8245 VIDEOBROADCAST-AS- AT014 years, 3 months, 28 days, 16 hours, 51 minutes
3AS12556 internet-solutions-ke- UG014 years, 0 months, 7 days, 4 hours, 57 minutes
4AS37677 SCPT- CD014 years, 0 months, 3 days, 21 hours, 6 minutes
5AS47655 LINKINTEL- RU013 years, 11 months, 27 days, 15 hours, 32 minutes
6AS8720 ASPAN-AS- KZ013 years, 11 months, 27 days, 4 hours, 57 minutes
7AS135523 MULTINET-IE-AS-AP Multinet Broadband- PK013 years, 11 months, 26 days, 12 hours, 17 minutes
8AS197838 CHEELOO-AS- PL013 years, 8 months, 1 days, 17 hours, 58 minutes
9AS199391 XGLOBE-199391- US033 years, 6 months, 25 days, 19 hours, 21 minutes
10AS263057 Connect Network- BR013 years, 5 months, 14 days, 4 hours, 29 minutes
11AS34471 EXCOM-AS- NL013 years, 0 months, 10 days, 22 hours, 29 minutes
12AS51622 IV-COM-AS- UA012 years, 10 months, 17 days, 7 hours, 29 minutes
13AS35745 PROVECTOR-AS- PL012 years, 10 months, 15 days, 16 hours, 47 minutes
14AS10292 CWJ-1- JM012 years, 7 months, 25 days, 16 hours, 36 minutes
15AS57279 SAURONNET- CZ022 years, 6 months, 0 days, 11 hours, 56 minutes

The full list of average reaction time over all hosting providers (ASNs) can be found here:

If you are a hosting provider, network owner or national CERT, you can subscribe to the URLhaus feed for your ASN or country here: