Menu DaniWeb
Log In Sign Up
  • Read
  • Contribute
  • Meet
  1. Forums
  2. Hardware and Software
  3. Information Security
  4. News Stories
  5. News Story

Malware hosting trends exposed

16 Years Ago happygeek 1 Tallied Votes 659 Views Share

Using newly registered domains with a very short lifespan to host malware websites is so last year. It would appear that these days such things are far more likely to be hosted on much older compromised web sites instead. Could this be down to a decline in domain tasting?

The latest MessageLabs Intelligence report appears to think so, suggesting that the previously widespread practise of cancelling a new domain registration within a few days 'cooling off' period has been in decline recently. Indeed, the Internet Corporation for Assigned Names and Numbers stated as much in June. The MessageLabs analysis of those websites which had been established purely to deliver malware showed that those domains classified as young, registered within three months of being blocked for hosting malicious content, are now relatively small in number. Mainly because they are discovered and taken down within the first 38 days of registration in 90% of cases. When it came to older domains that had been registered for more than three months and then compromised for malware service, MessageLabs discovered that they have a much longer shelf life: 90% are taken down after 138 days. Overall, 80% of sites blocked for serving up malware are established legitimate sites which have been compromised.

"It is not surprising that with a small window of opportunity for younger domains, the attackers register domains much faster" Paul Wood, MessageLabs Intelligence Senior Analyst, Symantec says "suggesting that attackers are working very hard to set up new domains and compromise new websites. However, in an effort to keep up with the rapid turnover of domains, the bad guys are often serving up the same malware". Which is why it is of a greater benefit for the bad guys to compromise those existing sites rather than establish a specialised new domain for the purpose. "Fundamentally, using legitimate websites to spread malware reduces the labor for the cybercriminals and extends the lifetime of the malware" Wood explains, adding "moreover, by taking advantage of the Add Grace Period, a policy that allows scammers to register a domain at no cost and cancel after five days, ‘domain tasting’ and ‘domain kiting’ have become common practice for cybercriminals, allowing them to beat the system without ever paying for malware distribution."

The report also highlights a decrease in the global ratio of spam in email traffic from new and previously unknown bad sources in September, down 2.1% since August to 86.4% or 1 in every 1.2 emails sent. Year on year though, spam levels were up: 88.1% for Q3 2009 compared with 81.0% for Q3 2008. There was also bad news about botnets, which appear to be have well and truly recovered from the McColo takedown hiccup and are now responsible for sending a staggering 150 billion spam emails every day!

cybersecurity virus-malware web-server
About the Author
Member Avatar for happygeek
happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

A freelance technology journalist for 30 years, I have been a Contributing Editor at PC Pro (one of the best selling computer magazines in the UK) for most of them. As well as currently contributing to Forbes.com, The Times and Sunday Times via Raconteur…

Dani AI

Generated 10 Months Ago

Good catch by — the domain-tasting loophole was largely closed in 2009, and that policy change pushed many attackers to compromise existing, longer-lived sites instead of spinning up short-lived domains. For historical context, ICANN’s AGP (Add Grace Period) limits caused a dramatic drop in “domain tasting,” which helps explain why malicious operators started relying more on hacked legitimate sites. ()

Industry telemetry from that era (and follow-up research) shows a very large number of legitimately registered sites being abused to serve drive‑by exploits, hidden iframes and SEO spam. These compromises are often more persistent and harder to takedown than a single throwaway domain, because the malicious code is buried in content, templates or server configs. See contemporary incident reports and large-scale scans for examples. (darkreading.com)

Practical steps to triage and clean a suspected compromised site:

  • Check Google Search Console -> Security issues first to get Google’s sample URLs and guidance. Request a review only after you are sure the site is clean. ()
  • On the server, look for recent file changes and common obfuscation patterns. Quick, non-destructive checks:
    
    # list files changed in last 60 days (adjust path /var/www)
    find /var/www -type f -mtime -60 -ls

search for typical obfuscation/backdoor tokens

grep -R --line-number -E "eval\(|base64_decode\(|gzinflate\(|str_rot13\(" /var/www || true


- Restore clean core files from a verified backup, remove backdoors, rotate all passwords/keys, and patch vulnerable apps/plugins.

For prevention and recovery workflow, use layered controls: a reputable scanner/WAF, regular integrity checks, timely CMS and library patching, least-privilege file permissions, and proactive monitoring. Vendor guides and site scanners offer useful cleanup/playbook detail if you need step‑by‑step remediation. ([malcare.com](https://www.malcare.com/blog/is-my-website-hacked/?utm_source=openai))

Note: don’t rush a Google review until every backdoor is removed — incomplete cleanups cause repeat flags and longer recovery times. This thread’s observations remain a useful reminder that protecting the sites you already run is now often the most important line of defense. @Azmah’s appreciation reflects why those defensive steps matter.
Member Avatar for Azmah
Azmah 1 Junior Poster
14 Years Ago

Damn! That's crazy. I'm glad that there are people protecting us ^_^

Reply to this topic
Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.

Sign Up — It's Free!
Recommended Topics
  • Member Avatar issue in https based web service certificate 1
  • Member Avatar Please help, Rundll.exe/iexplore.exe virus 1
  • Member Avatar On certain websites get page can not be displayed 1
  • Member Avatar w32.virut.cf virus 17
  • Member Avatar Re: I keep getting redirected to random web pages... 17
  • Member Avatar Unknown Virus...??? 13
  • Member Avatar TrendMicro or Avant Problem! Please Help! 5
  • Member Avatar Please Help Me With Virus!!!! 32
  • Member Avatar smitfraud c 2
  • Member Avatar The Fannie Mae Virus That Nearly Was 2
  • Member Avatar Downloader.Tibs Have Taken Over.... 0
  • Member Avatar I suspect I have a bad infection 42
  • Member Avatar Trojan woe? 6
  • Member Avatar RunDLL Error on Start Up - Please Help 5
  • Member Avatar onclick.cn virus and HJT log 10
  • Member Avatar Internet explorer runs in the background and plays audio adverts 1
  • Member Avatar Infected Computer, Please help. 39
  • Member Avatar ieuser.exe running and opening w/o permission 58
  • Member Avatar Hijack This Log Please Help Me 7
  • Member Avatar Internet Explorer opens by itself 10
Not what you need?

Reach out to all the awesome people in our information security community by starting your own topic. We equally welcome both specific questions as well as open-ended discussions.

Start New Topic
Topics Feed
Reply to this Topic
Edit Preview

Share Post

Insert Code Block

  • Forums
  • Forum Index
  • Hardware & Software
  • Programming
  • Digital Media
  • Community Center
  • Recent
  • Recommended Topics
  • Newest Topics
  • Latest Topics
  • Latest Posts
  • Latest Comments
  • Top Tags
  • Tools
  • Writing
    • Start New Topic
    • Markdown Syntax
    • Newsletter Archive
  • Social
    • Top Members
    • Meet People
  • APIs
    • Connect API
    • Forum API Docs
    • Topics Feed
  • Resources
  • Community Rules
  • DaniWeb Premium
  • FAQ
  • About Us
  • Advertise
  • Contact Us
  • Legal
  • Terms of Service
  • Privacy Policy
© 2026 DaniWeb® LLC
© 2026 DaniWeb® LLC
  • FAQ
  • About Us
  • Advertise
  • Contact Us
  • Terms of Service
  • Privacy Policy