Menu DaniWeb
Log In Sign Up
  • Read
  • Contribute
  • Meet
  1. Home
  2. Hardware and Software Forum
  3. Information Security Forum
  4. News Stories
  5. News Story

Malware hosting trends exposed

15 Years Ago happygeek 1 Tallied Votes 643 Views Share

Using newly registered domains with a very short lifespan to host malware websites is so last year. It would appear that these days such things are far more likely to be hosted on much older compromised web sites instead. Could this be down to a decline in domain tasting?

The latest MessageLabs Intelligence report appears to think so, suggesting that the previously widespread practise of cancelling a new domain registration within a few days 'cooling off' period has been in decline recently. Indeed, the Internet Corporation for Assigned Names and Numbers stated as much in June. The MessageLabs analysis of those websites which had been established purely to deliver malware showed that those domains classified as young, registered within three months of being blocked for hosting malicious content, are now relatively small in number. Mainly because they are discovered and taken down within the first 38 days of registration in 90% of cases. When it came to older domains that had been registered for more than three months and then compromised for malware service, MessageLabs discovered that they have a much longer shelf life: 90% are taken down after 138 days. Overall, 80% of sites blocked for serving up malware are established legitimate sites which have been compromised.

"It is not surprising that with a small window of opportunity for younger domains, the attackers register domains much faster" Paul Wood, MessageLabs Intelligence Senior Analyst, Symantec says "suggesting that attackers are working very hard to set up new domains and compromise new websites. However, in an effort to keep up with the rapid turnover of domains, the bad guys are often serving up the same malware". Which is why it is of a greater benefit for the bad guys to compromise those existing sites rather than establish a specialised new domain for the purpose. "Fundamentally, using legitimate websites to spread malware reduces the labor for the cybercriminals and extends the lifetime of the malware" Wood explains, adding "moreover, by taking advantage of the Add Grace Period, a policy that allows scammers to register a domain at no cost and cancel after five days, ‘domain tasting’ and ‘domain kiting’ have become common practice for cybercriminals, allowing them to beat the system without ever paying for malware distribution."

The report also highlights a decrease in the global ratio of spam in email traffic from new and previously unknown bad sources in September, down 2.1% since August to 86.4% or 1 in every 1.2 emails sent. Year on year though, spam levels were up: 88.1% for Q3 2009 compared with 81.0% for Q3 2008. There was also bad news about botnets, which appear to be have well and truly recovered from the McColo takedown hiccup and are now responsible for sending a staggering 150 billion spam emails every day!

abuse cybersecurity virus-malware web-server windows-virus
About the Author
Member Avatar for happygeek
happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

A freelance technology journalist for 30 years, I have been a Contributing Editor at PC Pro (one of the best selling computer magazines in the UK) for most of them. As well as currently contributing to Forbes.com, The Times and Sunday Times via Raconteur…

Member Avatar for Azmah
Azmah 1 Junior Poster
13 Years Ago

Damn! That's crazy. I'm glad that there are people protecting us ^_^

Reply to this topic
Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.

Sign Up — It's Free!
Related Topics
  • Member Avatar Virus won't let me do anything. 4
  • Member Avatar How to destroy a botnet 0
  • Member Avatar IE opens in background 15
  • Member Avatar IE opening by itself 12
  • Member Avatar Desktop Wil Not Load, Everything Else Apparently Fine (HiJack Log) 1
  • Member Avatar HELP! Taskbar changes color, sound is disables and internet keeps crashing! 6
  • Member Avatar Aurora Trouble... please help I cant delet it 19
  • Member Avatar Internet Explorer keeps opening on its own 14
  • Member Avatar Please help a damsel in distress 2
  • Member Avatar Unable to boot Safe Mode 14
  • Member Avatar Need help cleaning PC 5
  • Member Avatar Firefox and Internet Explorer Redirect Virus 6
  • Member Avatar DNS Changer Trojan? 6
  • Member Avatar IE7 and Chrome redirect hijack 23
  • Member Avatar Internet Mystery 14
  • Member Avatar HELP!! Search links keep redirecting me to advertisements!!! 25
  • Member Avatar Infected Computer, Please help. 39
  • Member Avatar Web Browsers not working, Other programs are. 4
  • Member Avatar WARNING: 200,000 US-based WordPress web pages compromised by hijack injection attack 4
  • Member Avatar Firefox 3.6.8 Opening unrequested new browser windows 37
Not what you need?

Reach out to all the awesome people in our information security community by starting your own topic. We equally welcome both specific questions as well as open-ended discussions.

Start New Topic
Topics Feed
Reply to this Topic
Edit Preview

Share Post

Insert Code Block

  • Forums
  • Forum Index
  • Hardware/Software
    • Recommended Topics
  • Programming
    • Recommended Topics
  • Digital Media
    • Recommended Topics
  • Community Center
    • Recommended Topics
  • Latest Content
  • Newest Topics
  • Latest Topics
  • Latest Posts
  • Latest Comments
  • Top Tags
  • Topics Feed
  • Social
  • Top Members
  • Meet People
  • Community Functions
  • DaniWeb Premium
  • Newsletter Archive
  • Markdown Syntax
  • Community Rules
  • Developer APIs
  • Connect API
  • Forum API Docs
  • Tools
  • SEO Backlink Checker
  • Legal
  • Terms of Service
  • Privacy Policy
  • FAQ
  • About Us
  • Advertise
  • Contact Us
© 2025 DaniWeb® LLC