Most abused TLDs in February 2010

The statistic for the top level domains used for hosting Phishing sites and malicious files in February 2010 are available: The most noticeable difference from January is that the usage of .ru domains increased by more than 64% in only one month, landing on the 3rd place in our top 15.

As can be seen in the table below, the .cn domains disappeared from our Phishing top, meaning that their amount is very much under 1% from the total amount of URLs in February.

However, the situation is completely different with Malware. Either because nobody bothered to disable the old faked domains or because there are a lot of compromised servers in China, the Malware files hosted in .cn domains has grown significantly from January, with over 73%.

Phishing Malware
# Top level domain % Deviation from
January 2010
in %
Top Level Domain % Deviation from
January 2010
in %
1 .com 46.20 -29.25 .com 36.25 -68.71
2 Others 11.27 100.00 .cn 24.66 73.83
3 .ru 9.92 64.75 IP Address 8.02 99.95
4 .org 6.24 31.23 Others 7.51 100.00
5 .net 5.27 -63.37 .net 7.30 28.60
6 IP Address 4.16 99.70 .kr 3.24 18.65
7 .kr 4.00 41.36 .org 2.91 -6.20
8 .cz 3.76 70.10 .info 2.42 -16.12
9 .uk 2.37 -2.67 .in 1.93 56.09
10 .fr 1.67 -7.60 .ru 1.85 -27.38
11 .pl 1.17 -251.63 .br 1.32 7.64
12 .info 1.12 17.61 .de 0.73 -5.14
13 .de 1.03 -39.51 .uk 0.70 16.87
14 .au 1.03 53.70 .it 0.67 1.26
15 .it 0.80 11.11 .pl 0.50 -25.00

Phishing Statistics for February 2010

Malware Statistics (TLDs) February 2010

Sorin Mustaca
Manager International Software Development