URLhaus study exposes slow abuse-desk responses
Abuse.ch's URLhaus project finds most hosting providers take days to take down malware distribution sites, often tied to Emotet spam campaigns.
Abuse.ch's URLhaus project, launched in March 2018, collects and shares malware distribution URLs and automatically notifies hosting providers and network owners of abuse via Abuseix Abuse Contact DB. Analyzing nearly 39,000 abuse reports sent over several months, the project measured an average takedown reaction time of just over three days across hosting providers, with many providers taking over 10 days and some malware sites remaining active for more than three months. Only 16% of contacted providers reacted within 6 hours, and just 2% within one hour.
The report highlights that most of the malware distribution sites tracked by URLhaus are linked to Emotet (aka Heodo), a banking trojan/loader distributed via malicious spam campaigns using weaponized Office documents. Because Emotet spam runs are frequent and rapid, slow abuse-desk response times directly increase the window during which users can be infected. The article also documents numerous technical and procedural failures in abuse reporting—bounced emails, outdated RIR contact records, spam filters rejecting reports, and unhelpful auto-responses—that hinder effective and timely takedown of malicious infrastructure.
The piece is primarily an operational/process critique rather than a report of a specific attack, campaign, or novel technique. It advocates for hosting providers to adopt standardized abuse reporting formats like ARF/X-ARF, subscribe to URLhaus feeds, and maintain accurate abuse contact information to reduce response times. No specific threat actor, victim organization, or new malware variant is disclosed; the focus is on abuse-handling infrastructure and takedown latency across hosting providers and countries.
Mentioned in this report
Source reporting: https://abuse.ch/blog/measuring-reaction-time-of-abuse-desks
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free