ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Rise of the 'legit' malware sites

By | August 1, 2008, 12:51pm PDT

Summary: About 75 percent of all Web sites serving up malicious code are legitimate sites that have been hacked/compromised, according to a new report from WebSense. This number validates statistics from ScanSafe showing a dramatic rise in ‘good’ sites being being used as a conduit for drive-by malware downloads and other social engineering attacks. [ SEE: The key [...]

75% of malicious sites are ‘legit’About 75 percent of all Web sites serving up malicious code are legitimate sites that have been hacked/compromised, according to a new report from WebSense.

This number validates statistics from ScanSafe showing a dramatic rise in ‘good’ sites being being used as a conduit for drive-by malware downloads and other social engineering attacks.

[ SEE: The key to an open, transparent malware filtering system ]

Even more worrisome, the WebSense report (pdf) says that 60 percent of the top 100 most popular Web sites  have either hosted or been involved in malicious activity in the first half of 2008.

Some additional highlights:

  • 12 percent of Web sites infected with malicious code were created using Web malware exploitation kits, a decrease of 33 percent since December 2007. Websense researchers believe this decrease may be attributed to attackers launching more customized attacks to avoid
    signature detection by security measures.
  • 29 percent of malicious Web attacks included data-stealing code.
  • 46 percent of data-stealing attacks are conducted over the Web.
  • 87 percent of email messages are spam. this percentage remains the same as the second half of 2007.
  • 76.5 percent of all emails in circulation contained links to spam sites and/or malicious Web sites. this represents an 18 percent increase over the previous six-month period.
  • 85 percent of unwanted (spam or malicious) emails contain a link.
  • Pornography-related spam decreased by more than 70 percent and is no longer the most popular topic for spam. Shopping (20 percent), cosmetics (19 percent), and Medical (11 percent) represent the majority of today’s spam.
  • 9 percent of spam messages are phishing attacks, representing a 47 percent increase over  the last six months.

WebSense also provided confirmation of what we’ve been reporting here on Zero Day:

Top 10 Web Attack Vectors in 1st Half of 2008:

  1. Browser vulnerabilities
  2. Adobe Flash vulnerabilities.
  3. ActiveX vulnerabilities.
  4. sQL injection.
  5. Adobe Acrobat Reader vulnerabilities.
  6. Content management systems (CMS) vulnerabilities.
  7. Apple QuickTime vulnerabilities.
  8. Malicious Web 2.0 components (Facebook applications,  third-party widgets/gadgets, banner ads, etc.)
  9. RealPlayer vulnerabilities.
  10. DNS cache poisoning.

See additional reporting by from Brian Krebs at the Washington Post, Matt Hines at eWEEK and this Techmeme discussion.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
3
Comments

Join the conversation!

Just In

RE: Rise of the 'legit' malware sites
lovedong 12th Sep
I'm always waiting for this message every month... replica watches
0 Votes
+ -
Thanks For the Report...
dunn@... 5th Aug 2008
Not that it is news to our group but we have been saying the same thing to Management in hopes of purchasing a Web Filter Appliance (Specifically the IronPort S650) to work with our two current IronPort C350 MTA's.

But it always takes a consulting company to say the same things we have been saying for them to "buy in" to the concept.

I emailed your article to Management and am going to follow-up by emailing them the PDF of the report, after that they'll each have a full color double sided print of the report sitting on their desks. I don't give up easily as I am part of the Desktop Enterprise Management team and we have to create custom fixlet for Bigfix for most everything except Microsoft patches and we have been doing a lot of that lately.
0 Votes
+ -
I'm always waiting for this message every month... replica watches
0 Votes
+ -
RE: Rise of the 'legit' malware sites
klockheed 6th Aug 2008
A list of sites might be more useful.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix