Statistics

Most Delivery Payload

Heodo

Show
Average Takedown Time

2 days, 4 hours, 38 minutes

Show
Top Malware Hosting Network

AS4134 CHINANET-BACKBONE

Show

Number of submissions (past 30 days)


The chart below documents the number of submissions (unique malware URL) to URLhaus per day over a period of 30 days.


Top Reporters


It wouldn't be possible to operate URLhaus without the help of volunteers who report malware URLs to URLhaus. The table below shows the top reporters and their Twitter handle.

RankReporterSubmissions
1@lrz_urlhaus1'073'093
2@geenensp328'544
3@cryptolaemus1143'986
4@zbetcheckin121'991
5@Gandylyan1101'817
6@tammeto63'655
7@p5yb34m48'052
8@spamhaus38'730
9@abuse_ch36'006
10@tolisec29'542
11@Petras_Simeon26'161
12@shotgunner10119'193
13@JayTHL19'037
14@0xrb13'773
15@switchcert12'873

Blocklist Comparison


URLhaus reports malware distribution sites to Spamhaus DBL, SURBL and Google Safe Browsing (GSB). In addition, several vendors of IT-security software are consuming URLhaus feeds to enrich their product(s). The statistics below measures the perfomance of several blocklists and DNS providers by counting the number of blacklisted domain names and compare them against each other.

Spamhaus DBL

SURBL

AdGuard DNS

Quad9 DNS

Cloudflare DNS

Disclaimer: The blacklist comparison does only consider active malware distribution sites tracked by URLhaus.

Most Delivered Payload


Malware URLs deliver all kind of different payloads. This chart shows the number of payload per malware family (signature) identified / crawled by URLhaus.

Top Tags


Most seen tag associated with malware URLs tracked by URLhaus.

Top Malware Hosting Networks


The chart below shows the top malware hosting network by ASN. Please consider that some of them just offer CDN or proxy services and are hence not hosting the malicious content it self rather than facilitate delivering the malicious payload to the user.

Top malware hosting networks in total (counting online and offline malware distribution sites):

RankASNCountryAverage Reaction TimeMalware URLs
1AS4837 CHINA169-BACKBONE CHINA UNICOM China169 Backbone- CN2 days, 17 hours, 38 minutes635'944
2AS9829 BSNL-NIB National Internet Backbone- IN8 hours, 38 minutes187'406
3AS17488 HATHWAY-NET-AP Hathway IP Over Cable Internet- IN5 hours, 33 minutes140'084
4AS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CN4 days, 4 hours, 1 minutes126'462
5AS8661 PTK PTK IP/MPLS Network- AL2 days, 1 hours, 20 minutes97'519
6AS17816 CHINA169-GZ China Unicom IP network China169 Guangdong province- CN1 day, 4 hours, 37 minutes69'290
7AS14061 DIGITALOCEAN-ASN- US4 days, 0 hours, 14 minutes51'650
8AS17622 CNCGROUP-GZ China Unicom Guangzhou network- CN22 hours, 38 minutes50'800
9AS13335 CLOUDFLARENET- US2 days, 17 hours, 13 minutes48'282
10AS46606 UNIFIEDLAYER-AS-1- US8 days, 20 hours, 36 minutes36'251
11AS15169 GOOGLE- US9 days, 8 hours, 22 minutes32'068
12AS8075 MICROSOFT-CORP-MSN-AS-BLOCK- US8 days, 21 hours, 40 minutes26'640
13AS16276 OVH- FR9 days, 16 hours, 55 minutes24'403
14AS8068 MICROSOFT-CORP-MSN-AS-BLOCK- US2 days, 0 hours, 29 minutes22'374
15AS17813 MTNL-AP Mahanagar Telephone Nigam Limited- IN11 hours, 15 minutes21'886

Top malware hosting networks, hosting active malware content (counting online malware distribution sites only):

RankASNCountryAverage Reaction TimeMalware URLs
1AS211252 AS_DELIS- US6 days, 23 hours, 50 minutes617
2AS13335 CLOUDFLARENET- US2 days, 17 hours, 13 minutes361
3AS4766 KIXS-AS-KR Korea Telecom- KR20 days, 12 hours, 12 minutes202
4AS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CN4 days, 4 hours, 1 minutes169
5AS46606 UNIFIEDLAYER-AS-1- US8 days, 20 hours, 36 minutes158
6AS15169 GOOGLE- US9 days, 8 hours, 22 minutes134
7AS36352 AS-COLOCROSSING- US10 days, 17 hours, 58 minutes67
8AS4837 CHINA169-BACKBONE CHINA UNICOM China169 Backbone- CN2 days, 17 hours, 38 minutes56
9AS7922 COMCAST-7922- US1 month, 21 days, 8 hours, 56 minutes44
10AS26496 AS-26496-GO-DADDY-COM-LLC- US18 days, 7 hours, 27 minutes43
11AS8151 Uninet S.A. de C.V.- MX5 days, 16 hours, 13 minutes42
12AS9318 SKB-AS SK Broadband Co Ltd- KR2 months, 25 days, 10 hours, 59 minutes40
13AS33182 DIMENOC- US1 month, 5 days, 21 hours, 55 minutes34
14AS37963 CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.,Ltd.- CN1 month, 12 days, 15 hours, 27 minutes34
15AS7552 VIETEL-AS-AP Viettel Group- VN16 days, 23 hours, 4 minutes32

Takedown Statistics


URLhaus is sending out abuse reports to hosting providers, hosting malware distribution sites. The following chart shows the number of active malware distribution sites and the number of unique abuse reports sent per day.


The following table shows the top 15 hosting providers with the fastest abuse desks. To generated these statistics, URLhaus measures the time between when URLhaus sent the abuse complaint to the hosting provider and when the reported content goes offline. Please consider that the accuracy is +/- 1 hour.

RankASN GoodCountryOnlineOfflineAverage Reaction Time
1AS399587 UT- NL011 minute
2AS25369 BANDWIDTH-AS- CH125 minutes
3AS64050 BCPL-SG BGPNET Global ASN- CN215 minutes
4AS141293 AAHCR953-AS Rajasthan Internet Hub Pvt. Ltd.- IN015 minutes
5AS13022 STREAMS_GMBH- AT015 minutes
6AS133983 SBB-AS-IN Shivraj Broadband Internet Pvt Ltd- IN035 minutes
7AS197746 HYPERHOSTING Georgios Vardikos trading as HYPERHOSTING- GR016 minutes
8AS52564 Biazi Telecomunicacoes Ltda Epp- BR016 minutes
9AS7020 QDATA-AS- ZA017 minutes
10AS263948 NEW LIFE TELECOM- BR017 minutes
11AS197684 ASHOSTUA- US027 minutes
12AS134929 ORANGECITY-AS ORANGE CITY INTERNET SERVICES PVT. LTD.- IN017 minutes
13AS55486 NETWORX-AS-AP Networx Australia- AU018 minutes
14AS269715 INFINITYGO TELECOM LTDA- BR018 minutes
15AS24139 WASUHZ Huashu media&Network Limited- 0108 minutes

The following table shows the top 15 hosting providers with the slowest abuse desks. To generated these statistics, URLhaus measures the time between when URLhaus sent the abuse complaint to the hosting provider and when the reported content goes offline. Please consider that the accuracy is +/- 1 hour.

RankASN PoorCountryOnlineOfflineAverage Reaction Time
1AS23520 COLUMBUS-NETWORKS- BS0144 months, 18 days, 15 hours, 6 minutes
2AS197838 CHEELOO-AS- PL0141 months, 18 days, 14 hours, 49 minutes
3AS8720 ASPAN-AS- KZ0134 months, 18 days, 6 hours, 20 minutes
4AS51155 TBTELECOM- PL0134 months, 17 days, 7 hours, 39 minutes
5AS51622 IV-COM-AS- UA0134 months, 17 days, 7 hours, 29 minutes
6AS47655 LINKINTEL- RU0134 months, 17 days, 7 hours, 29 minutes
7AS36937 Neotel-AS- ZA0134 months, 17 days, 6 hours, 42 minutes
8AS37677 SCPT- CD0134 months, 4 days, 2 hours, 41 minutes
9AS43627 KLI-AS- LT1131 months, 26 days, 22 hours, 17 minutes
10AS10292 CWJ-1- JM0131 months, 25 days, 16 hours, 36 minutes
11AS43424 MAGICRETAIL- FR0330 months, 18 days, 5 hours, 19 minutes
12AS48422 IT-STARCOM-AS http://www.itstarcom.net- UA0129 months, 22 days, 11 hours, 30 minutes
13AS203217 HZ- IQ0129 months, 7 days, 3 hours, 9 minutes
14AS54600 PEGTECHINC- HK11628 months, 29 days, 17 hours, 27 minutes
15AS12426 MADNET-AS- SK0128 months, 2 days, 5 hours, 53 minutes

The full list of average reaction time over all hosting providers (ASNs) can be found here:

If you are a hosting provider, network owner or national CERT, you can subscribe to the URLhaus feed for your ASN or country here: