Statistics

Most Delivery Payload

Heodo

Show
Average Takedown Time

4 days, 11 hours, 17 minutes

Show
Top Malware Hosting Network

AS4134 CHINANET-BACKBONE

Show

Number of submissions (past 30 days)


The chart below documents the number of submissions (unique malware URL) to URLhaus per day over a period of 30 days.


Top Reporters


It wouldn't be possible to operate URLhaus without the help of volunteers who report malware URLs to URLhaus. The table below shows the top reporters and their Twitter handle.

RankReporterSubmissions
1@lrz_urlhaus803'389
2@geenensp207'148
3@zbetcheckin112'831
4@Gandylyan187'399
5@Cryptolaemus180'220
6@p5yb34m48'052
7@spamhaus38'730
8@tammeto28'293
9@abuse_ch27'316
10@tolisec20'654
11@shotgunner10119'131
12@JayTHL19'037
13@JRoosen16'485
14@0xrb13'691
15@JAMESWT_MHT9'707

Blocklist Comparison


URLhaus reports malware distribution sites to Spamhaus DBL, SURBL and Google Safe Browsing (GSB). In addition, several vendors of IT-security software are consuming URLhaus feeds to enrich their product(s). The statistics below measures the perfomance of several blocklists and DNS providers by counting the number of blacklisted domain names and compare them against each other.

Spamhaus DBL

SURBL

AdGuard DNS

Quad9 DNS

Cloudflare DNS

Disclaimer: The blacklist comparison does only consider active malware distribution sites tracked by URLhaus.

Most Delivered Payload


Malware URLs deliver all kind of different payloads. This chart shows the number of payload per malware family (signature) identified / crawled by URLhaus.

Top Tags


Most seen tag associated with malware URLs tracked by URLhaus.

Top Malware Hosting Networks


The chart below shows the top malware hosting network by ASN. Please consider that some of them just offer CDN or proxy services and are hence not hosting the malicious content it self rather than facilitate delivering the malicious payload to the user.

Top malware hosting networks in total (counting online and offline malware distribution sites):

RankASNCountryAverage Reaction TimeMalware URLs
1AS4837 CHINA169-BACKBONE CHINA UNICOM China169 Backbone- CN2 days, 19 hours, 39 minutes442'909
2AS17488 HATHWAY-NET-AP Hathway IP Over Cable Internet- IN5 hours, 20 minutes132'022
3AS9829 BSNL-NIB National Internet Backbone- IN8 hours, 33 minutes123'230
4AS8661 PTK PTK IP/MPLS Network- AL2 days, 1 hours, 16 minutes89'598
5AS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CN5 days, 4 hours, 15 minutes69'333
6AS17622 CNCGROUP-GZ China Unicom Guangzhou network- CN23 hours, 0 minutes37'228
7AS17816 CHINA169-GZ China Unicom IP network China169 Guangdong province- CN1 day, 6 hours, 27 minutes35'643
8AS13335 CLOUDFLARENET- US9 days, 5 hours, 6 minutes33'047
9AS46606 UNIFIEDLAYER-AS-1- US12 days, 16 hours, 6 minutes26'465
10AS15169 GOOGLE- US14 days, 20 hours, 49 minutes24'257
11AS14061 DIGITALOCEAN-ASN- US4 days, 4 hours, 58 minutes22'885
12AS17813 MTNL-AP Mahanagar Telephone Nigam Limited- IN11 hours, 14 minutes18'826
13AS15169 GOOGLE- 14 days, 20 hours, 49 minutes17'802
14AS36352 AS-COLOCROSSING- US8 days, 22 hours, 37 minutes15'624
15AS16276 OVH- FR10 days, 8 hours, 9 minutes13'548

Top malware hosting networks, hosting active malware content (counting online malware distribution sites only):

RankASNCountryAverage Reaction TimeMalware URLs
1AS4837 CHINA169-BACKBONE CHINA UNICOM China169 Backbone- CN2 days, 19 hours, 39 minutes3'041
2AS15169 GOOGLE- US14 days, 20 hours, 49 minutes1'205
3AS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CN5 days, 4 hours, 15 minutes1'168
4AS8068 MICROSOFT-CORP-MSN-AS-BLOCK- US29 days, 8 hours, 51 minutes845
5AS36352 AS-COLOCROSSING- US8 days, 22 hours, 37 minutes345
6AS9808 CMNET-GD Guangdong Mobile Communication Co.Ltd.- CN16 days, 6 hours, 50 minutes288
7AS46606 UNIFIEDLAYER-AS-1- US12 days, 16 hours, 6 minutes208
8AS4766 KIXS-AS-KR Korea Telecom- KR15 days, 10 hours, 59 minutes172
9AS17816 CHINA169-GZ China Unicom IP network China169 Guangdong province- CN1 day, 6 hours, 27 minutes170
10AS17622 CNCGROUP-GZ China Unicom Guangzhou network- CN23 hours, 0 minutes162
11AS9829 BSNL-NIB National Internet Backbone- IN8 hours, 33 minutes131
12AS27887 WIND Telecom S.A.- DO2 days, 7 hours, 50 minutes124
13AS53667 PONYNET- US15 days, 11 hours, 45 minutes99
14AS13335 CLOUDFLARENET- US9 days, 5 hours, 4 minutes88
15AS9416 MULTIMEDIA-AS-AP Hoshin Multimedia Center Inc.- TW1 month, 22 days, 23 hours, 53 minutes71

Takedown Statistics


URLhaus is sending out abuse reports to hosting providers, hosting malware distribution sites. The following chart shows the number of active malware distribution sites and the number of unique abuse reports sent per day.


The following table shows the top 15 hosting providers with the fastest abuse desks. To generated these statistics, URLhaus measures the time between when URLhaus sent the abuse complaint to the hosting provider and when the reported content goes offline. Please consider that the accuracy is +/- 1 hour.

RankASN GoodCountryOnlineOfflineAverage Reaction Time
1AS63835 CT-HUNAN-CHANGSHA-IDC No.293,Wanbao Avenue- CN082 minutes
2AS141293 AAHCR953-AS Rajasthan Internet Hub Pvt. Ltd.- IN015 minutes
3AS13022 STREAMS_GMBH- AT015 minutes
4AS133983 SBB-AS-IN Shivraj Broadband Internet Pvt Ltd- IN035 minutes
5AS197746 HYPERHOSTING Georgios Vardikos trading as HYPERHOSTING- GR016 minutes
6AS52564 Biazi Telecomunicacoes Ltda Epp- BR016 minutes
7AS7020 QDATA-AS- ZA017 minutes
8AS263948 NEW LIFE TELECOM- BR017 minutes
9AS45538 ODSJSC-AS-VN ODS Joint Stock Company- VN217 minutes
10AS47141 LITTEL-AS- UZ037 minutes
11AS134929 ORANGECITY-AS ORANGE CITY INTERNET SERVICES PVT. LTD.- IN017 minutes
12AS55486 NETWORX-AS-AP Networx Australia- AU018 minutes
13AS269715 INFINITYGO TELECOM LTDA- BR018 minutes
14AS42960 CLOUD-MANAGEMENT-LLC- US019 minutes
15AS5588 GTSCE GTS Central Europe Antel Germany- HU029 minutes

The following table shows the top 15 hosting providers with the slowest abuse desks. To generated these statistics, URLhaus measures the time between when URLhaus sent the abuse complaint to the hosting provider and when the reported content goes offline. Please consider that the accuracy is +/- 1 hour.

RankASN PoorCountryOnlineOfflineAverage Reaction Time
1AS199391 XGLOBE-199391- US0327 months, 2 days, 20 hours, 28 minutes
2AS16625 AKAMAI-AS- GB1126 months, 11 days, 0 hours, 13 minutes
3AS135523 MULTINET-IE-AS-AP Multinet Broadband- PK0124 months, 20 days, 16 hours, 8 minutes
4AS37230 SWIFTTALK- NG0124 months, 18 days, 0 hours, 32 minutes
5AS37677 SCPT- CD0124 months, 17 days, 0 hours, 51 minutes
6AS201776 MIRANDA-AS- UA0124 months, 16 days, 4 hours, 30 minutes
7AS49893 BITRACE-TELECOM- RU0124 months, 12 days, 5 hours, 3 minutes
8AS11681 INTEGRITY- US0124 months, 10 days, 23 hours, 45 minutes
9AS12556 internet-solutions-ke- UG0123 months, 28 days, 4 hours, 30 minutes
10AS20766 GITOYEN-MAIN-AS The main Autonomous System of Gitoyen (Paris, France).- FR7423 months, 24 days, 20 hours, 25 minutes
11AS35745 PROVECTOR-AS- PL0123 months, 13 days, 15 hours, 59 minutes
12AS28917 FIORD-AS IP-transit operator in Russia, Ukraine and Baltics- RU0123 months, 9 days, 7 hours, 33 minutes
13AS56385 NTKTV-AS- UA0123 months, 2 days, 5 hours, 4 minutes
14AS197013 SPRINTEL-SRO- CZ0122 months, 29 days, 9 hours, 9 minutes
15AS131325 CHINATELECOM-JIANGSU-NANTONG-MAN CHINATELECOM JIANGSU province NANTONG MAN network- CN1622 months, 16 days, 12 hours, 57 minutes

The full list of average reaction time over all hosting providers (ASNs) can be found here:

If you are a hosting provider, network owner or national CERT, you can subscribe to the URLhaus feed for your ASN or country here: