Volunteers Take Down 124K Malware Sites

Volunteers Take Down 124K Malware Sites CircleID reports that abuse.ch, a non-profit cybersecurity organization based in Switzerland kicked off a volunteer-based information sharing project called URLhaus in March 2018. URLhaus collects and shares URLs identified to be distributing malware. Since its start up, URLhaus has proven to be quite effective in taking down over 124,000 malware distribution sites.

Abussubmitted in average 300 malware sitese.ch’s URLhaus project allows anyone to sign up with a Twitter account to report malicious URLs. The system will download and analyze the site’s payload and try to identify it before submitting it to Anti-Virus vendors and blacklist providers such as Google Safe Browsing, Spamhaus DBL, and SURBL, according to the blog post.

CircleID reports that 265 security researchers located all over the world have identified and submitted on average 300 malware sites to URLhaus each day. The article said URLhaus succeeded beyond the infosec community; the project also managed to get the attention of many hosting providers which is not an easy task, especially for large hosting providers that have tens of thousands of customers and hence a significant amount hijacked websites in their network that are getting abused by cybercriminals to distribute malware.

The chart below produced by abuse.ch shows the number of active malware distribution sites tracked since the launch of URLhaus.

malware distribution sites tracked since the launch of URLhaus.

abuse.ch reports that the US or China hosts 2/3 of the top malware hosting networks. The overall average malicious site take-down time is 8 days, 10 hours, 24 minutes. The three top Chinese malware hosting networks have an average abuse desk reaction time of more than a month!

That’s more than enough time to infect thousands of devices every day.

 

Top malware hosting networks

The top malware hosting networks, hosting active malware content identified by abuse.ch as of January 2019.
RankASNCountryAverage Reaction TimeMalware URLs
1AS14061 DIGITALOCEAN-ASN - DigitalOcean, LLCUS6 days, 12 hours, 56 minutes307
2AS4134 CHINANET-BACKBONE No.31,Jin-rong StreetCN1 month, 9 days, 19 hours, 22 minutes256
3AS4837 CHINA169-BACKBONE CHINA UNICOM China169CN1 month, 23 days, 8 hours, 41 minutes163
4AS48815 CRITICALCASEIT21 hours, 58 minutes151
5AS46606 UNIFIEDLAYER-AS-1 - Unified LayerUS2 days, 11 hours, 54 minutes127
6AS53667 PONYNET - FranTech SolutionsUS13 days, 3 hours, 37 minutes105
7AS16276 OVHFR5 days, 22 hours, 6 minutes104
8AS60144 THREE-W-INFRA-AS -- TRANSIT --NL9 days, 10 hours, 37 minutes83
9AS13335 CLOUDFLARENET - Cloudflare, Inc.US13 days, 7 hours, 5 minutes67
10AS37963 CNNIC-ALIBABA-CN-NET-AP Hangzhou AlibabaCN1 month, 2 days, 0 hours, 1 minutes66
11AS8342 RTCOMM-ASRU10 days, 8 hours, 9 minutes63
12AS36352 AS-COLOCROSSING - ColoCrossingUS16 days, 9 hours, 57 minutes53
13AS3462 HINET Data Communication Business GroupTW17 days, 6 hours, 19 minutes51
14AS23650 CHINANET-JS-AS-AP CHINANET jiangsu provinceCN3 days, 11 hours, 50 minutes51
15AS3462 HINET Data Communication BusinessTW17 days, 6 hours, 19 minutes51

 

rb-

abuse.ch offers the URLhaus black list for free to help protect your networks and users from malware. You can get more details from abuse.ch here.

 

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Comments are closed.