On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

June 24th, 2008

200,000 sites spreading web malware, China's hosting the most

Posted by Dancho Danchev @ 3:16 pm

Categories: Black Hat, Botnets, Exploit code, Governments, Hackers, Passwords, People's Republic of China, Rootkits, Spyware and Adware, United States of America, Viruses and Worms

Tags: Security, Malware, Web Malware, Badware, Stopbadware.org, Google Safe Browsing, Dancho Danchev

Yesterday, the Stopbadware.org initiative released a report entitled “May 2008 Badware Websites Report” summarizingBadware sites May 2008 the findings out of analyzing over 200,000 sites spreading malware. With recent data for malicious sites provided by Google’s Safe Browsing diagnostic, Stopbadware.org also received responses from affected parties such as Google itself, The Planet, SoftLayer and iEurop. Here are more details on the methodology used, and who’s who in hosting the most badware sites for May, 2008 :

Using data from Google’s Safe Browsing initiative, StopBadware.org analyzed over 200,000 websites found to engage in badware behavior. The analysis found that over half of the sites were based on Chinese network blocks, with a small number of blocks accounting for most of the infected sites in that country. The U.S. accounted for 21% of infected sites, and these were spread across a wide range of networks. Compared to last year, the total number of sites was much higher, likely due both to increased scanning efforts by Google and to increased use of websites as a vector of malware infection. Several U.S.-based network blocks that were heavily infected last year, including that of web hosting company iPowerWeb, whose network block topped last year’s list, no longer host large numbers of infected sites.

What’s important to take into consideration when going through these stats, is that a great deal of networks hosting domain portfolios engaging in a countless number of malicious activities, would remain underreported due to the efforts them put into evading common detection approaches, the result of which is their current placement in the “Unknown” and “Other” categories. I was pleasantly surprised to see SoftLayer mentioned, in fact SoftLayer’s response to the research at the first place, as if we are to play a game of associations the first things that come to my mind when I see SoftLayer are The Russian Business Network, InterCage, Inc., Layered Technologies, Inc., Ukrtelegroup Ltd, Turkey Abdallah Internet Hizmetleri, and Hostfresh, ISPs providing infrastructure to malware command and control interfaces and malicious domains used in the majority of malware embedded attacks during the entire 2007, and early 2008.

The report makes an important point, namely, that compared to the previous year the total number of sites found to engage in badware activities was much bigger, mostly because of the increasing use of sites as infection vectors, but also because of Google’s increased scanning efforts.

Don’t forget that these are only the detected sites spreading malware, and with the ongoing efforts by malicious parties to implement evasive tactics in order to fool client side honeypots crawling their malicious sites, the number of malware spreading sites is much higher. For instance, for the past couple of weeks I’ve been analyzing malicious doorways which when properly analyzed redirect to over 10 to 20 different malware serving domains, and given most of them are also used as redirectors, analyzing a single malicious doorway ends up with a portfolio of over a 100 malicious domains. So what? Basically, the ongoing collaboration between blackhat search engine optimizers and malware authors, results in the malware authors getting empowered with know-how on cloaking their malicious doorways from search engine crawlers, and it’s these search engine crawlers who make it possible for client side honeypots to verify whether or not a site is malicious or not. The doorway would serve legitimate content to a potentially identified search engine’s crawler or even a client side honeypot, but would reveal it’s real ugliness to the average Internet user.

Anyway, what’s more disturbing at the bottom line - the fact that legitimate sites are starting to host most of the web malware these days, ruining the stereotype of “don’t visit unknown sites or you risk getting infected with something”, or the fact that we are not emphasizing on the average time it takes to shut down such a site at the first place, but are always curious where are they hosted geographically?

Consider going through the report, it’s well worth it.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 38 Talkback(s)
That is where we are headed.
My company uses proxy servers and white lists. The only sites allowed to be visited are the ones we use directly for business. And I just hope that none of these are infected.

It is sad the In... (Read the rest)
Posted by: bjbrock Posted on: 07/23/08 You are currently: a Guest | | Terms of Use
I say we just cut China's segment off...  BitTwiddler | 06/25/08
I agree, China has NOTHING I need or want.  No_Ax_to_Grind | 06/25/08
yes, but...  gdstark13 | 06/25/08
yes, but...is that a joke or what?  8string | 06/25/08
RE: yes, but...is that a joke or what?  gdstark13 | 06/25/08
If you think China has nothing you want . . .  dstreifling@... | 06/25/08
Firewall China Network Blocks  david.swift@... | 06/25/08
RE: Firewall....  bfilipiak@... | 06/25/08
List of IP addys for each country interesting  Hempman | 06/26/08
What attacks from China? People need to learn to read  wellofsouls | 06/27/08
Just a guess  Stan57 | 06/25/08
I am seeing a rampant uptick in spyware this week...  BitTwiddler | 06/25/08
Like roaches...  jasonp@... | 06/25/08
a solution  gdstark13 | 06/25/08
China also ranks #1 in software piracy  LBiege | 06/25/08
China is NOT #1 in software piracy  cool_techie | 06/25/08
90% in Bangladesh?  Tiquor | 06/25/08
Only percentage or per capita is fair  cool_techie | 06/25/08
Sofware makers CREATE the piracy!  newwestd | 06/25/08
Entitlement  radar_z | 06/25/08
Except  tracy anne | 06/26/08
Follow the money ...  terry flores | 06/25/08
RE: Follow the money...  bfilipiak@... | 06/25/08
RE: 200,000 sites spreading web malware, China's hosting the most  chaz15 | 06/25/08
wow  gdstark13 | 06/25/08
reply to wow  chaz15 | 06/25/08
RE: 200,000 sites spreading web malware, China's hosting the most  iamschatz | 06/25/08
A useless internet  pikeman666@... | 06/26/08
That is where we are headed.  bjbrock | 07/23/08
RE: 200,000 sites spreading web malware, Food for Registry!  vindersnodz@... | 06/26/08
RE: 200,000 sites spreading web malware, China's hosting the most  Andrew Taylor | 06/26/08
RE: 200,000 sites spreading web malware, China's hosting the most  epona | 06/28/08
RE: 200,000 sites spreading web malware, China's hosting the most  Common Sensei | 06/28/08
Bull in a China shop.  Common Sensei | 06/28/08
China give you malware to host?  wellofsouls | 07/02/08
Stop using Windows, and the Internet stops to be a threat for your computer  Thempleton | 07/14/08
Safe Surf Practices  rvgammill@... | 07/23/08
They need to be shut down...  bjbrock | 07/23/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc