Over 1 per cent of search results include malicious sites

Posted by   Virus Bulletin on   Feb 12, 2008

Google research paper confirms significant increase in number of malware-serving websites.

Recent reports of increasing numbers of websites serving malicious content have been confirmed in a paper published by researchers from Google.

The researchers report finding over three million URLs serving malware, as detected by at least one anti-virus program, with another three million showing suspicious behaviour. In most cases, the malware is loaded into the page via a piece of JavaScript code or via an iframe linking to an external site, with almost 10,000 sites found to be actually hosting the malware.

Though these numbers may seem insignificant among the billions of websites on the internet, more than 1% of all Google search results pages now contain at least one site serving malware, a figure which has quadrupled in the past nine months.

Not surprisingly, users who visit websites with adult content have a higher risk of running into malware. However, this does not mean that these are the only sites that pose a threat, as malware was found on every type of website, according to the Open Directory Project categorisation of websites. In fact, most malware-serving websites are genuine sites that have been compromised. This may be partly the fault of website administrators, as over 38% of malware-serving websites that run the Apache server software use an out-of-date version, with another 26% not reporting their version number. 40% of the PHP versions in use were also found to be out of date.

The researchers also looked into the global distribution of malicious websites. Of the sites serving malware, as well as of those actually hosting the malware, two thirds are located in China, with the United States and Russia taking second and third place in both categories. However, these figures vary greatly from country to country. For instance, for 96% of Chinese websites serving malware, the malware is also hosted in China.

The paper confirms a worrying trend of increasing numbers of genuine websites serving malware, and implies that the former 'safe browsing' strategy of visiting only trusted sites is fast becoming impossible to implement. Web users can protect themselves by ensuring they run reputable security software and keeping it updated, and web administrators must ensure they run up-to-date versions of server software and keep their sites clean.

A summary of findings can be found at Google's Online Security Blog here, while the original paper can be downloaded (in PDF format) here.

Posted on 12 February 2008 by Virus Bulletin

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

Firefox 59 to make it a lot harder to use data URIs in phishing attacks

Firefox developer Mozilla has announced that, as of version 59 of the browser, many kinds of data URIs, which provide a way to create "domainless web content", will not be rendered in the browser, thus making this trick - used in various phishing…

Standalone product test: FireEye Endpoint

Virus Bulletin ran a standalone test on FireEye's Endpoint Security solution.

VB2017 video: Consequences of bad security in health care

Jelena Milosevic, a nurse with a passion for IT security, is uniquely placed to witness poor security practices in the health care sector, and to fully understand the consequences. Today, we publish the recording of a presentation given by Jelena at…

Vulnerabilities play only a tiny role in the security risks that come with mobile phones

Both bad news (all devices were pwnd) and good news (pwning is increasingly difficult) came from the most recent mobile Pwn2Own competition. But the practical security risks that come with using mobile phones have little to do with vulnerabilities.

VB2017 paper: The (testing) world turned upside down

At VB2017 in Madrid, industry veteran and ESET Senior Research Fellow David Harley presented a paper on the state of security software testing. Today we publish David's paper in both HTML and PDF format.