Statistics

Most Delivery Payload

Heodo

Show
Average Takedown Time

5 days, 4 hours, 0 minutes

Show
Top Malware Hosting Network

AS4134 CHINANET-BACKBONE

Show

Number of submissions (past 30 days)


The chart below documents the number of submissions (unique malware URL) to URLhaus per day over a period of 30 days.


Top Reporters


It wouldn't be possible to operate URLhaus without the help of volunteers who report malware URLs to URLhaus. The table below shows the top reporters and their Twitter handle.

RankReporterSubmissions
1@lrz_urlhaus375'084
2@geenensp111'250
3@zbetcheckin104'829
4@Gandylyan164'958
5@Cryptolaemus159'691
6@p5yb34m47'939
7@spamhaus38'730
8@abuse_ch21'343
9@shotgunner10119'126
10@JayTHL19'037
11@JRoosen16'485
12@0xrb13'650
13@tolisec10'044
14@JAMESWT_MHT9'114
15@unixronin8'945

Blocklist Comparison


URLhaus reports malware distribution sites to Spamhaus DBL, SURBL and Google Safe Browsing (GSB). In addition, several vendors of IT-security software are consuming URLhaus feeds to enrich their product(s). The statistics below measures the perfomance of several blocklists and DNS providers by counting the number of blacklisted domain names and compare them against each other.

Spamhaus DBL

SURBL

AdGuard DNS

Quad9 DNS

Cloudflare DNS

Disclaimer: The blacklist comparison does only consider active malware distribution sites tracked by URLhaus.

Most Delivered Payload


Malware URLs deliver all kind of different payloads. This chart shows the number of payload per malware family (signature) identified / crawled by URLhaus.

Top Tags


Most seen tag associated with malware URLs tracked by URLhaus.

Top Malware Hosting Networks


The chart below shows the top malware hosting network by ASN. Please consider that some of them just offer CDN or proxy services and are hence not hosting the malicious content it self rather than facilitate delivering the malicious payload to the user.

Top malware hosting networks in total (counting online and offline malware distribution sites):

RankASNCountryAverage Reaction TimeMalware URLs
1AS4837 CHINA169-BACKBONE CHINA UNICOM China169 Backbone- CN2 days, 15 hours, 23 minutes247'145
2AS17488 HATHWAY-NET-AP Hathway IP Over Cable Internet- IN5 hours, 8 minutes118'271
3AS9829 BSNL-NIB National Internet Backbone- IN6 hours, 56 minutes38'846
4AS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CN7 days, 8 hours, 17 minutes29'540
5AS14061 DIGITALOCEAN-ASN- US4 days, 12 hours, 3 minutes20'195
6AS46606 UNIFIEDLAYER-AS-1- US12 days, 20 hours, 44 minutes17'830
7AS15169 GOOGLE- US13 days, 10 hours, 53 minutes17'652
8AS13335 CLOUDFLARENET- US7 days, 0 hours, 52 minutes17'030
9AS17813 MTNL-AP Mahanagar Telephone Nigam Limited- IN10 hours, 42 minutes15'900
10AS26496 AS-26496-GO-DADDY-COM-LLC- US18 days, 22 hours, 18 minutes9'651
11AS4766 KIXS-AS-KR Korea Telecom- KR16 days, 6 hours, 6 minutes8'983
12AS36352 AS-COLOCROSSING- US8 days, 11 hours, 59 minutes8'431
13AS16276 OVH- FR10 days, 10 hours, 50 minutes8'382
14AS19551 INCAPSULA- US5 days, 10 hours, 16 minutes7'664
15AS132525 CMNET-HEILONGJIANG-CN HeiLongJiang Mobile Communication Company Limited- CN1 day, 8 hours, 0 minutes5'983

Top malware hosting networks, hosting active malware content (counting online malware distribution sites only):

RankASNCountryAverage Reaction TimeMalware URLs
1AS4837 CHINA169-BACKBONE CHINA UNICOM China169 Backbone- CN2 days, 15 hours, 29 minutes1'555
2AS8661 PTK PTK IP/MPLS Network- AL1 day, 16 hours, 18 minutes554
3AS8068 MICROSOFT-CORP-MSN-AS-BLOCK- US1 month, 29 days, 9 hours, 11 minutes523
4AS9808 CMNET-GD Guangdong Mobile Communication Co.Ltd.- CN17 days, 23 hours, 59 minutes303
5AS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CN7 days, 7 hours, 54 minutes267
6AS9318 SKB-AS SK Broadband Co Ltd- KR1 month, 25 days, 1 hours, 32 minutes192
7AS15169 GOOGLE- US13 days, 11 hours, 32 minutes184
8AS4766 KIXS-AS-KR Korea Telecom- KR15 days, 23 hours, 39 minutes122
9AS33182 DIMENOC- US22 days, 20 hours, 33 minutes98
10AS46606 UNIFIEDLAYER-AS-1- US12 days, 20 hours, 47 minutes79
11AS27887 WIND Telecom S.A.- DO1 day, 13 hours, 2 minutes58
12AS15169 GOOGLE- NL13 days, 11 hours, 32 minutes57
13AS8551 BEZEQ-INTERNATIONAL-AS Bezeqint Internet Backbone- IL3 months, 6 days, 2 hours, 20 minutes54
14AS36352 AS-COLOCROSSING- US8 days, 10 hours, 27 minutes54
15AS9981 SAERONET-AS-KR Saero Network Service LTD- KR1 month, 4 days, 22 hours, 51 minutes49

Takedown Statistics


URLhaus is sending out abuse reports to hosting providers, hosting malware distribution sites. The following chart shows the number of active malware distribution sites and the number of unique abuse reports sent per day.


The following table shows the top 15 hosting providers with the fastest abuse desks. To generated these statistics, URLhaus measures the time between when URLhaus sent the abuse complaint to the hosting provider and when the reported content goes offline. Please consider that the accuracy is +/- 1 hour.

RankASN GoodCountryOnlineOfflineAverage Reaction Time
1AS141293 AAHCR953-AS Rajasthan Internet Hub Pvt. Ltd.- IN015 minutes
2AS13022 STREAMS_GMBH- AT015 minutes
3AS34137 RUAMUR-AS- RU016 minutes
4AS52564 Biazi Telecomunicacoes Ltda Epp- BR016 minutes
5AS22438 CLEAR-RATE-COMMUNICATIONS- US017 minutes
6AS134929 ORANGECITY-AS ORANGE CITY INTERNET SERVICES PVT. LTD.- IN017 minutes
7AS139261 METROLINK-AS-AP Metrolink Business Group Pvt Ltd- NP017 minutes
8AS269715 INFINITYGO TELECOM LTDA- BR018 minutes
9AS17716 NTU-TW National Taiwan University- TW018 minutes
10AS42960 CLOUD-MANAGEMENT-LLC- US019 minutes
11AS34243 WEBAGE- GB019 minutes
12AS55441 TTSLMEIS-AS-AP TTSL-ISP DIVISION- IN039 minutes
13AS202448 MVPS https://www.mvps.net- CY019 minutes
14AS267060 Jspnet servicos de comunicacoes multimidia eireli- BR019 minutes
15AS268824 CONNECTMAX TELECOM- BR0210 minutes

The following table shows the top 15 hosting providers with the slowest abuse desks. To generated these statistics, URLhaus measures the time between when URLhaus sent the abuse complaint to the hosting provider and when the reported content goes offline. Please consider that the accuracy is +/- 1 hour.

RankASN PoorCountryOnlineOfflineAverage Reaction Time
1AS21453 FLEX-AS- RU0121 months, 19 days, 5 hours, 0 minutes
2AS63581 GXRTVNET GUANGXI RADIO & TELEVISION INFORMATION NETWORK CO.,LTD.- CN0120 months, 18 days, 22 hours, 27 minutes
3AS61165 UMOS-AS- RU0119 months, 29 days, 16 hours, 34 minutes
4AS48278 UKRDATACOM-NET-AS- UA0119 months, 28 days, 11 hours, 8 minutes
5AS131325 CHINATELECOM-JIANGSU-NANTONG-MAN CHINATELECOM JIANGSU province NANTONG MAN network- CN2219 months, 2 days, 21 hours, 38 minutes
6AS42841 ANTIK- SK0318 months, 0 days, 0 hours, 2 minutes
7AS137693 CHINATELECOM-GUANGXI-NANNING-IDC CHINATELECOM Guangxi Nanning IDC networkdescr: NanningGuangxi Province, P.R.China.- CN0717 months, 25 days, 21 hours, 44 minutes
8AS43356 COMTECH-AS- CY0117 months, 22 days, 17 hours, 2 minutes
9AS23620 DMM DMM.com LLC- JP0217 months, 15 days, 23 hours, 56 minutes
10AS134768 CHINANET-SHAANXI-CLOUD-BASE CHINANET SHAANXI province Cloud Base network- CN1116 months, 29 days, 21 hours, 3 minutes
11AS18187 WIFICITY-AS-AP WifiCity Inc.- PH0116 months, 27 days, 15 hours, 24 minutes
12AS49893 BITRACE-TELECOM- RU0116 months, 25 days, 2 hours, 3 minutes
13AS37230 SWIFTTALK- NG0116 months, 24 days, 23 hours, 2 minutes
14AS37677 SCPT- CD0116 months, 24 days, 3 hours, 38 minutes
15AS56340 UMNYESETI-AS- RU0116 months, 23 days, 20 hours, 9 minutes

The full list of average reaction time over all hosting providers (ASNs) can be found here:

If you are a hosting provider, network owner or national CERT, you can subscribe to the URLhaus feed for your ASN or country here: