Feeds

Cameroon leapfrogs Hong Kong in malware hosting blocklist

One in three .cm domains booby-trapped, warns McAfee

Choosing a cloud hosting partner with confidence

Cameroon (.cm) web domains supplanted those in Hong Kong as most likely to harbour malware, with more than one in three (36.7 per cent) of domains registered in the West African country hosting viruses or malicious code.

The .cm used by Cameroon is a common typo for .com, a factor that security firm McAfee speculates may explain why cybercriminals have set up fake typo-squatting sites that lead to malicious downloads or spyware under the country's domain.

Meanwhile Hong Kong (.hk) websites have successfully managed to purge themselves of malware threats – droppings from the most risky domain last year, to a mid-table (34th) position next year. This year only 1.1 per cent of .hk sites pose a risk, compared to one in five .hk Web sites setting off warning bells in McAfee's equivalent report last year. McAfee credits "aggressive measures" from .hk’s domain managers in clamping down on dodgy registrations for the drop.

Hong Kong's newly-minted net sainthood contrasts with the position in the People’s Republic of China (.cn), which appears in second spot in McAfee's list of shame.

"This report underscores how quickly cybercriminals change tactics to lure in the most victims and avoid being caught," said Mike Gallagher, chief technology officer for McAfee Labs. "Last year, Hong Kong was the riskiest domain and this year it is dramatically safer.

"Cybercriminals target regions where registering sites is cheap and convenient, and pose the least risk of being caught."

McAfee's third annual Mapping the Mal Web report names Irish (.ie) sites as the safest in EMEA, with only Japanese (.jp) sites ranking lower in risk globally. British websites hold a relatively safe berth, appearing in 55th place on McAfee's list of shame.

Websites ending in ".com" came out as the second most risky domains in 2009, moving up from the ninth spot last year. By contrast, government (.gov) domains were the safest non-country domain.

McAfee analysed 27 million websites and 104 top-level domains using its SiteAdvisor and TrustedSource technology in compiling its report. SiteAdvisor tests websites for browser exploits, phishing, excessive pop-ups and malicious downloads, while TrustedSource offers a reputation system that tracks web traffic patterns, site behaviour, hosted content and more, to gauge site security risks.

The security firm reckons 5.8 per cent (or more than 1.5 million web sites) pose a security risk of one kind or another. ®

The top five riskiest country domains online for 2009, according to McAfee

  1. Cameroon (.cm)
  2. PR of China (.cn)
  3. Samoa (.ws)
  4. Phillipines (.ph)
  5. Former Soviet Union (.su)

Beginner's guide to SSL certificates

More from The Register

next story
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.