Statistics

Most Delivery Payload

Heodo

Show
Average Takedown Time

23 hours, 15 minutes

Show
Top Malware Hosting Network

AS4134 CHINANET-BACKBONE

Show

Number of submissions (past 30 days)


The chart below documents the number of submissions (unique malware URL) to URLhaus per day over a period of 30 days.


Top Reporters


It wouldn't be possible to operate URLhaus without the help of volunteers who report malware URLs to URLhaus. The table below shows the top reporters and their Twitter handle.

RankReporterSubmissions
1 lrz_urlhaus1'189'115
2 geenensp467'065
3 Cryptolaemus1258'902
4 zbetcheckin133'327
5 Gandylyan1123'244
6 tammeto71'924
7 abuse_ch56'159
8 p5yb34m48'052
9 spamhaus38'858
10 tolisec38'817
11 Petras_Simeon26'161
12 shotgunner10119'193
13 r3dbU7z19'057
14 JayTHL19'037
15 0xrb13'773

Blocklist Comparison


URLhaus reports malware distribution sites to Spamhaus DBL, SURBL and Google Safe Browsing (GSB). In addition, several vendors of IT-security software are consuming URLhaus feeds to enrich their product(s). The statistics below measures the perfomance of several blocklists and DNS providers by counting the number of blacklisted domain names and compare them against each other.

Spamhaus DBL

SURBL

AdGuard DNS

Quad9 DNS

Cloudflare DNS

dns0.eu DNS

ProtonDNS

Disclaimer: The blacklist comparison does only consider active malware distribution sites tracked by URLhaus.

Most Delivered Payload


Malware URLs deliver all kind of different payloads. This chart shows the number of payload per malware family (signature) identified / crawled by URLhaus.

Top Tags


Most seen tag associated with malware URLs tracked by URLhaus.

Top Malware Hosting Networks


The chart below shows the top malware hosting network by ASN. Please consider that some of them just offer CDN or proxy services and are hence not hosting the malicious content it self rather than facilitate delivering the malicious payload to the user.

Top malware hosting networks in total (counting online and offline malware distribution sites):

RankASNCountryAverage Reaction TimeMalware URLs
1AS4837 CHINA169-BACKBONE CHINA UNICOM China169 Backbone- CN2 days, 15 hours, 4 minutes746'495
2AS9829 BSNL-NIB National Internet Backbone- IN9 hours, 40 minutes256'764
3AS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CN4 days, 2 hours, 30 minutes168'046
4AS17488 HATHWAY-NET-AP Hathway IP Over Cable Internet- IN5 hours, 55 minutes141'510
5AS8661 PTK PTK IPMPLS Network- AL2 days, 1 hours, 28 minutes97'550
6AS17816 CHINA169-GZ China Unicom IP network China169 Guangdong province- CN1 day, 8 hours, 8 minutes83'334
7AS13335 CLOUDFLARENET- US3 days, 11 hours, 16 minutes65'044
8AS14061 DIGITALOCEAN-ASN- US4 days, 10 hours, 28 minutes55'036
9AS17622 CNCGROUP-GZ China Unicom Guangzhou network- CN22 hours, 37 minutes50'853
10AS46606 UNIFIEDLAYER-AS-1- US13 days, 21 hours, 34 minutes46'799
11ASNone None- None1 day, 1 hours, 3 minutes38'592
12AS19871 NETWORK-SOLUTIONS-HOSTING- US13 days, 4 hours, 14 minutes37'044
13AS16276 OVH- FR10 days, 5 hours, 59 minutes29'764
14AS15169 GOOGLE- US11 days, 9 hours, 13 minutes29'722
15AS8075 MICROSOFT-CORP-MSN-AS-BLOCK- US17 days, 22 hours, 28 minutes28'467

Top malware hosting networks, hosting active malware content (counting online malware distribution sites only):

RankASNCountryAverage Reaction TimeMalware URLs
1AS4837 CHINA169-BACKBONE CHINA UNICOM China169 Backbone- CN2 days, 15 hours, 4 minutes568
2AS15169 GOOGLE- US11 days, 9 hours, 11 minutes127
3AS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CN4 days, 2 hours, 30 minutes121
4AS216289 SIRCROSAR-NET- GB3 days, 8 hours, 24 minutes62
5AS16509 AMAZON-02- US3 days, 12 hours, 16 minutes61
6AS135901 MAYCHUNHO-AS-VN Phuong Dong technology solution company limited- VN4 days, 7 hours, 32 minutes60
7AS216309 EVILEMPIRE-AS- GB21 days, 12 hours, 36 minutes58
8AS200593 PROSPERO-AS- RU1 month, 1 days, 19 hours, 43 minutes49
9AS13335 CLOUDFLARENET- US3 days, 11 hours, 17 minutes48
10AS9829 BSNL-NIB National Internet Backbone- IN9 hours, 40 minutes47
11AS49943 ITRESHENIYA-AS- RU26 days, 3 hours, 9 minutes43
12AS131486 JDCOM Beijing Jingdong 360 Degree E-commerce Co., Ltd.- CN0 minute39
13AS47541 VKONTAKTE-SPB-AS vk.com- RU3 days, 20 hours, 12 minutes39
14AS36459 GITHUB- US27 days, 20 hours, 33 minutes38
15AS49581 FERDINANDZINK- DE9 days, 4 hours, 16 minutes38

Takedown Statistics


URLhaus is sending out abuse reports to hosting providers, hosting malware distribution sites. The following chart shows the number of active malware distribution sites and the number of unique abuse reports sent per day.


The following table shows the top 15 hosting providers with the fastest abuse desks. To generated these statistics, URLhaus measures the time between when URLhaus sent the abuse complaint to the hosting provider and when the reported content goes offline. Please consider that the accuracy is +/- 1 hour.

RankASN GoodCountryOnlineOfflineAverage Reaction Time
1AS13022 STREAMS_GMBH- None015 minutes
2AS133983 SBB-AS-IN Shivraj Broadband Internet Pvt Ltd- None035 minutes
3AS60458 ASN-XTUDIONET- ES016 minutes
4AS197746 HYPERHOSTING Georgios Vardikos trading as HYPERHOSTING- None016 minutes
5AS140159 LNKIOFPL-AS Linkio Fibernet Pvt Ltd- None016 minutes
6AS34137 PJSC Rostelecom Blagoveschensk- None016 minutes
7AS52564 Biazi Telecom- None016 minutes
8AS7020 QDATA-AS- None017 minutes
9AS47376 WGB-LLC- IR017 minutes
10AS263948 NEW LIFE TELECOM- None017 minutes
11AS134013 MASSSOHN-AS-IN Mass Computer- None017 minutes
12AS197684 ASHOSTUA- None027 minutes
13AS134929 ORANGECITY-AS ORANGE CITY INTERNET SERVICES PVT. LTD.- None017 minutes
14AS13124 A1BG_RSD- BG057 minutes
15AS55441 TTSLMEIS-AS-AP TTSL-ISP DIVISION- None017 minutes

The following table shows the top 15 hosting providers with the slowest abuse desks. To generated these statistics, URLhaus measures the time between when URLhaus sent the abuse complaint to the hosting provider and when the reported content goes offline. Please consider that the accuracy is +/- 1 hour.

RankASN PoorCountryOnlineOfflineAverage Reaction Time
1AS56385 NTKTV-AS- None014 years, 5 months, 15 days, 11 hours, 10 minutes
2AS8720 ASPAN-AS- None014 years, 5 months, 14 days, 6 hours, 12 minutes
3AS37677 SCPT- None014 years, 2 months, 23 days, 19 hours, 10 minutes
4AS36937 Neotel-AS- None014 years, 1 months, 29 days, 7 hours, 3 minutes
5AS197838 CHEELOO-AS- None013 years, 8 months, 1 days, 17 hours, 58 minutes
6AS263057 Connect Network- None013 years, 5 months, 14 days, 4 hours, 29 minutes
7AS4662 QTCN-ASN1 GCNet Reach & Range Inc.- None013 years, 1 months, 15 days, 18 hours, 40 minutes
8AS30782 TOYA Sp. z o.o.- None013 years, 1 months, 4 days, 20 hours, 34 minutes
9AS51622 IV-COM-AS- None012 years, 10 months, 17 days, 7 hours, 29 minutes
10AS35745 PROVECTOR-AS- None012 years, 10 months, 15 days, 16 hours, 47 minutes
11AS60822 WISP1- None012 years, 9 months, 15 days, 2 hours, 6 minutes
12AS9811 DRCSCNET Development & Research Center of State Council Net.- None222 years, 9 months, 5 days, 8 hours, 32 minutes
13AS10292 CWJ-1- None012 years, 7 months, 25 days, 16 hours, 36 minutes
14AS39513 ONECOM-AS- None012 years, 7 months, 2 days, 21 hours, 22 minutes
15AS57279 SAURONNET- None022 years, 6 months, 0 days, 11 hours, 56 minutes

The full list of average reaction time over all hosting providers (ASNs) can be found here:

If you are a hosting provider, network owner or national CERT, you can subscribe to the URLhaus feed for your ASN or country here: