URLhaus project takes down 100K malware sites
Abuse.ch's URLhaus project used community reporting to take down nearly 100,000 malware distribution sites in 10 months, most linked to Emotet.
This is a retrospective report from abuse.ch on its URLhaus project, launched in March 2018 to crowdsource identification and takedown of malware distribution URLs. Over the project's first 10 months, 265 contributing researchers submitted an average of 300 malicious URLs per day, resulting in nearly 100,000 takedowns, though 4,000-5,000 sites remain active at any given time. The article highlights persistent problems with hosting provider abuse-desk response times, noting an average takedown time of over 8 days globally and over a month for top Chinese hosting networks, with US and Chinese providers hosting two-thirds of the top malware hosting networks.
The report identifies Emotet (aka Heodo) as the dominant malware family behind the tracked distribution sites, spread via malspam campaigns using malicious macro-enabled Office documents that download and execute the payload from compromised websites. Some campaigns host the malicious document on a compromised site rather than attaching it directly to evade spam filters. Of roughly 380,000 malware samples collected by URLhaus over the period, Emotet/Heodo was the top payload identified. The piece is largely a project retrospective and community call-to-action, encouraging network owners, CERTs, and TLD operators to subscribe to URLhaus feeds and implement its blocklists (DNS RPZ, Snort/Suricata rules) rather than describing a new or active threat campaign.
Mentioned in this report
Source reporting: https://abuse.ch/blog/how-to-takedown-100000-malware-sites
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free