

The reaction time measures how long it takes to remove malicious content following a specific report, and is an average time to remove the malware the full list shows that some reports take just two days and others up to 4 months. Even if malware is detected by Microsoft Defender, it is not "automatically taken down in OneDrive," Beaumont said. It is also common to see malware hosted on business Office 365 accounts that have been compromised.Īutomated blocking of suspicious files by the cloud providers is problematic not only because new variants are hard to detect, but also for privacy reasons.

The Microsoft sites hosting malware use OneDrive accounts that might have been created specifically for the purpose, or hijacked from legitimate users. Whatever they do with these reports filled out through the MSRC API, it is definitely not automated." MSRC is the Microsoft Security Response Center.īeaumont said that while "My experience is the Azure Storage items should disappear very quickly. The official Twitter account of abuse.ch, which runs URLhaus, said "for the record, the oldest active malware site with an age of 19 months is hosted on Sharepoint and serving GuLoader." It added: "I've seen an increase of 10 new malware sites hosted at MS over the weekend.

Malware hosted on OneDrive, reported to URLhaus
