Statistics

Most Delivery Payload

Heodo

Show
Average Takedown Time

11 days, 23 hours, 9 minutes

Show
Top Malware Hosting Network

AS4134 CHINANET-BACKBONE

Show

Number of submissions (past 30 days)


The chart below documented the number of submissions (unique malware URL) to URLhaus per day over a period of 30 days.


Top Reporters


It wouldn't be possible to operate URLhaus without the help of volunters who report malware URLs to URLhaus. The table below shows the top reporters and their Twitter handle.

RankReporterSubmissions
1@zbetcheckin77'893
2@Cryptolaemus139'810
3@Gandylyan123'529
4@spamhaus19'457
5@shotgunner10119'092
6@JRoosen16'477
7@JayTHL10'586
8@0xrb10'526
9@abuse_ch9'606
10@unixronin8'469
11@JAMESWT_MHT6'873
12@ps66uk4'872
13@cocaman4'115
14@p5yb34m3'907
15@oppimaniac3'671

Blacklist Comparison


URLhaus reports malware distribution sites to Spamhaus DBL, SURBL and Google Safe Browsing (GSB). In addition, several vendors of IT-security software are consuming URLhaus feeds to enrich their product(s). The statistics below measures the perfomance of several blacklist and DNS providers by counting the number of blacklisted domain names and compare them against each other.

Spamhaus DBL

SURBL

AdGuard DNS

Quad9 DNS

Disclaimer: The blacklist comparison does only consider active malware distribution sites tracked by URLhaus.

Most Delivered Payload


Malware URLs deliver all kind of different payloads. This chart shows the number of payload per malware family (signature) identified / crawled by URLhaus.

Top Tags


Most seen tag associated with malware URLs tracked by URLhaus.

Top Malware Hosting Networks


The chart below shows the top malware hosting network by ASN. Please consider that some of them just offer CDN or proxy services and are hence not hosting the malicious content it self rather than facilitate delivering the malicious payload to the user.

Top malware hosting networks in total (counting online and offline malware distribution sites):

RankASNCountryAverage Reaction TimeMalware URLs
1AS14061 DIGITALOCEAN-ASN - DigitalOcean, LLC- US5 days, 19 hours, 14 minutes30'374
2AS15169 GOOGLE - Google LLC- US7 days, 2 hours, 0 minutes12'780
3AS16276 OVH- FR13 days, 6 hours, 9 minutes9'097
4AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC- US1 month, 2 days, 1 hours, 4 minutes8'182
5AS13335 CLOUDFLARENET - Cloudflare, Inc.- US15 days, 23 hours, 46 minutes7'290
6AS4837 CHINA169-BACKBONE CHINA UNICOM China169 Backbone- CN7 days, 17 hours, 5 minutes6'292
7AS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CN15 days, 17 hours, 33 minutes5'667
8AS46606 UNIFIEDLAYER-AS-1 - Unified Layer- US25 days, 6 hours, 26 minutes4'954
9AS132525 CMNET-HEILONGJIANG-CN HeiLongJiang Mobile Communication Company Limited- CN1 day, 7 hours, 40 minutes3'675
10AS16509 AMAZON-02 - Amazon.com, Inc.- IE11 days, 21 hours, 5 minutes3'232
11AS54290 HOSTWINDS - Hostwinds LLC.- US11 days, 0 hours, 11 minutes2'968
12AS53667 PONYNET - FranTech Solutions- US20 days, 9 hours, 45 minutes2'887
13AS19679 DROPBOX - Dropbox, Inc.- NL3 days, 23 hours, 42 minutes2'851
14AS60144 THREE-W-INFRA-AS -- TRANSIT --- NL17 days, 6 hours, 40 minutes2'734
15AS36352 AS-COLOCROSSING - ColoCrossing- US7 days, 0 hours, 56 minutes2'597

Top malware hosting networks, hosting active malware content (counting online malware distribution sites only):

RankASNCountryAverage Reaction TimeMalware URLs
1AS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CN15 days, 17 hours, 33 minutes523
2AS4837 CHINA169-BACKBONE CHINA UNICOM China169 Backbone- CN7 days, 17 hours, 5 minutes197
3AS37963 CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.,Ltd.- CN1 month, 12 days, 12 hours, 6 minutes122
4AS46606 UNIFIEDLAYER-AS-1 - Unified Layer- US25 days, 6 hours, 26 minutes106
5AS9318 SKB-AS SK Broadband Co Ltd- KR2 months, 6 days, 13 hours, 7 minutes98
6AS4766 KIXS-AS-KR Korea Telecom- KR29 days, 21 hours, 48 minutes85
7AS54113 FASTLY - Fastly- NL24 days, 7 hours, 20 minutes68
8AS45090 CNNIC-TENCENT-NET-AP Shenzhen Tencent Computer Systems Company Limited- CN20 days, 2 hours, 51 minutes59
9AS48161 NG-AS Sos. Bucuresti - Ploiesti nr. 42-44- RO2 months, 8 days, 2 hours, 59 minutes57
10AS6877 AS6877- UA1 month, 22 days, 7 hours, 8 minutes57
11AS48090 PPTECHNOLOGY- NL6 days, 5 hours, 36 minutes57
12AS9808 CMNET-GD Guangdong Mobile Communication Co.Ltd.- CN21 days, 3 hours, 52 minutes48
13AS4812 CHINANET-SH-AP China Telecom (Group)- CN3 months, 7 days, 9 hours, 55 minutes48
14AS15169 GOOGLE - Google LLC- US7 days, 2 hours, 0 minutes40
15AS36352 AS-COLOCROSSING- US7 days, 0 hours, 56 minutes39

Takedown Statistics


URLhaus is sending out abuse reports to hosting providers, hosting malware distribution sites. The following chart shows the number of active malware distribution sites and the number of unique abuse reports sent per day.


The following table shows the top 15 hosting providers with the fastest abuse desks. To generated these statistics, URLhaus measures the time between when URLhaus sent the abuse complaint to the hosting provider and when the reported content goes offline. Please consider that the accuracy is +/- 1 hour.

RankASN GoodCountryOnlineOfflineAverage Reaction Time
1AS13022 - AT015 minutes
2AS22438 CLEAR-RATE-COMMUNICATIONS - Clear Rate Communications, Inc.- US017 minutes
3AS34243 WEBAGE- GB019 minutes
4AS8739 ICDSOFT- HK019 minutes
5AS8267 CYFRONET-AS Metropolitan Area Network Autonomous System- PL1111 minutes
6AS6789 CRELCOM-NET- UA0111 minutes
7AS16912 4-LESS-NETWORK - 4 Less Communications, Inc.- US0111 minutes
8AS263891 TURBONET INFO E TELECOM- BR0114 minutes
9AS56977 ASSTILAR- RU0115 minutes
10AS133699 ZIPTELIT-AS-IN Ziptel IT Solutions Pvt Ltd- IN0118 minutes
11AS29953 MORNCOMM - Cygnet Internet Services Inc- CA0118 minutes
12AS29083 DE-WORLDBONE-AS- DE0118 minutes
13AS20926 PULSATION-AS- FR0119 minutes
14AS12296 ADANET-- TR0120 minutes
15AS35266 EXN-AS- GB0220 minutes

The following table shows the top 15 hosting providers with the slowest abuse desks. To generated these statistics, URLhaus measures the time between when URLhaus sent the abuse complaint to the hosting provider and when the reported content goes offline. Please consider that the accuracy is +/- 1 hour.

RankASN PoorCountryOnlineOfflineAverage Reaction Time
1AS29713 ELIA-60 - Reliable Hosting Services- US0214 months, 25 days, 10 hours, 35 minutes
2AS58852 GZGD Guizhou provincial radio and television information Network Inc- CN0214 months, 17 days, 6 hours, 27 minutes
3AS35401 SUNLINK-AS Sunlink Telecom ISP, Tula, Russia- RU0114 months, 13 days, 3 hours, 56 minutes
4AS24165 PHOENIX-NET-TW PHOENIX CATV CO.,LTD- TW0114 months, 9 days, 6 hours, 12 minutes
5AS131259 QX-AS-AP QOXY PTE LTD- SG0513 months, 22 days, 4 hours, 46 minutes
6AS44234 GAYA-AS P.O.Hviezdoslava 23B- SK0313 months, 18 days, 2 hours, 48 minutes
7AS38099 KAKAO-AS-KR Kakao Corp- KR0213 months, 3 days, 17 hours, 17 minutes
8AS136958 UNICOM-GUANGZHOU-IDC China Unicom Guangdong IP network- CN0113 months, 2 days, 16 hours, 4 minutes
9AS37692 NetStack-AS- ZA0912 months, 18 days, 23 hours, 25 minutes
10AS63119 AS-63119 - netirons- US0512 months, 13 days, 11 hours, 35 minutes
11AS19332 Marcatel Com, S.A. de C.V.- MX0112 months, 7 days, 10 hours, 52 minutes
12AS16504 GRANITE - Granite Telecommunications LLC- US0112 months, 7 days, 3 hours, 2 minutes
13AS20321 Alternativa Gratis- AR0912 months, 5 days, 9 hours, 11 minutes
14AS21500 TNS-AS- UA0112 months, 5 days, 0 hours, 38 minutes
15AS14600 MXL-PROD - MX Logic, Inc.- US0112 months, 3 days, 20 hours, 31 minutes

The full list of average reaction time over all hosting providers (ASNs) can be found here:

If you are a hosting provider, network owner or national CERT, you can subscribe to the URLhaus feed for your ASN or country here: