Malware Activity: Key Statistics
Quarter over Quarter comparison: April 1,2024 - June 30,2024

Each reporting period, we analyze URLs, domain names, and IP addresses reported for serving up or distributing malware. We use these and other metadata — domain and IP address registration data, ICANN registry and registrar monthly reports, routing data, attack type, and other indicators — to report key statistics for each reporting period.

We compare number of domains reported for hosting malware in TLDs for two consecutive quarters in the table below.

Complete lists of Top-level Domains, gTLD registrars and hosting networks (ASNs) where malware was reported for the quarter can be downloaded in CSV format from the Records page.

Measurement January to March 2024 April to June 2024 Change
in
Measurement
Total number of malware reports collected from feeds (per quarter) 1,639,485 1,753,910 114,425
Total number of malware records produced from malware reports 1,512,722 1,446,550 -66,172
Endpoint malware (targets user-attended devices) 31,506 71,539 40,033
Internet of Things (IoT) malware (targets sensors, wearables, appliances...) 41,002 96,706 55,704
Malicious IP address malware records (Traffic Injectors and Attackware) 1,068,623 1,117,224 48,601
Uncategorized malware (Verified as malware but not classified) 371,591 161,081 -210,510
Unique domain names reported for serving up malware 171,720 40,286 -131,434
Top-level Domains (TLDs) where we observed malware hosting 493 367 -126
Registrars that had gTLD domains under management reported for serving malware 986 472 -514
Hosting Networks (ASNs) where we observed malware hosting or distribution 15,817 15,458 -359
Unique IPv4 addresses reported as serving or distributing malware 1,085,481 1,153,409 67,928