Home / News

Typosquatted Domain Names Pose Plenty of Risk But Surprisingly Little Malware

A recent study took an in-depth look at the scale and the risk of domain name typosquatting — the practice of registering mis-spellings of popular domain names in an attempt to profit from typing mistakes. "Applying every possible one-character typo to the domain names of Facebook, Google, Twitter, Microsoft, Apple and Sophos," Paul Ducklin, Sophos' Asia Pacific head of technology collected HTTP data and browser screenshots from 1502 web sites and 14,495 URLs.

Ducklin wrote: "We recently surveyed a batch of lost USB keys bought from a transit authority's Lost Property auction; we hoped that the infection rate would be about 10%, but found that 66% of the keys in our study were infected. So we naively assumed that typosquat sites would be similarly incautious (either by accident or design) about malware. But out of 14,495 URLs downloaded in browsing to the 1502 sites on our list, only one contained malware. That's just 0.01% by URL, and 0.07% by fully-qualified domain name."

In his report, Ducklin analyses the data revealing unexpected results and harmful aspects of the typosquatting ecosystem.

Related topics: Cybersquatting, Domain Names, Malware, Security

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

A more meaningful conclusion Eric Brunner-Williams  –  Dec 20, 2011 12:26 PM PDT

The study also found that DoubleClick (Google) had a revenue relation with 37% of the study sites. The distribution of its competitors in the PPC universe was discovered in the study site sample unfortunately not stated.

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

.IN.NET - New Internet Address for India, Launching June 17th

Radix Registry Passes 4 New gTLD Initial Evaluations

DomainsBot to Help Professionals Find .PRO Internet Addresses More Easily

INTA 2013: Gearing Up for Dallas

Hope is Not a Strategy: Neustar Releases 2012 Annual DDoS Attack and Impact Survey

.PW Crosses 50,000 Domain Registrations in 3 Weeks

The Ratings Are In: Measuring .ORG's Trust and Success in Numbers

How Neustar Technology Can Help Mitigate DDoS Attacks

dot Brand or dot What? Consumers Unaware of New TLDs, Including .Google, .Microsoft and .Nike

Zodiac Prepares for Chinese New gTLDs, Announces "Chinese Advisory Services" for New gTLD Applicants

.PW General Availability Opens With More Than 4000 Orders in 30 Minutes

CentralNic Powers First New Top-Level Domains Announced by ICANN

Invitation to a Seminar on "A New Beginning - Domain Name Market in China"

LogicBoxes Announces Vertical Integration Solutions for New gTLDs

.PW Registry Extends Landrush Till March 22, 2013

DCA Registry Services Participates in ICANN Africa Strategy Meeting, Addis Ababa

Network Solutions & Register.com, Web.com, become 100th and 101st Accredited Registrars for .PW

gTLD Update: No TLDH or Client Strings Affected

Public Interest Registry Releases Report Revealing Continued Growth of the .ORG Domain

.PW Landrush Goes Live

Sponsored Topics

Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
Neustar

DNS

Sponsored by
Neustar
dotMobi

Mobile

Sponsored by
dotMobi
Afilias

DNS Security

Sponsored by
Afilias