Malware

Drive-by download

Drive-by download is malware that installs just because a visitor loaded a page, with no click on a download button. It exploits a browser or plugin flaw, or tricks the browser into saving a file.

How it is measured

Observe it in a sandbox: open the page in a throwaway browser and watch for file writes, new processes, or a download that begins without interaction. Network logs show the redirect chain, often through two or three hops to an exploit-hosting server.

On the site, the entry point is injected script or an iframe that points at the hop. Search the HTML for hidden frames and obfuscated script tags.

Worked example

A visitor to a local news site reports that Windows Defender flagged a file after reading an article. Looking at the page, a script in the sidebar ad slot requests `track.adnet-sync.top/l.js`, which redirects to a page that serves a `.js` file with `Content-Disposition: attachment`.

The ad network pulls the creative after the news site reports it. The site also adds a CSP that blocks any script host it did not list.

How it differs

A drive-by download is the delivery. An exploit kit is the toolbox that decides which browser hole to try. Malvertising is one route, where a bought ad carries the redirect. A normal download needs a click, while a drive-by needs only that the victim visits the page.

Common errors

Assuming users must click something. Patching the server but not the ad stack. Ignoring old browsers in your own office. Blocking one URL and missing the redirect chain. Testing on a fully patched modern browser and calling it safe.

In practice

Keep browsers and plugins updated on every machine that visits your site. Review third-party ad and widget scripts, and restrict hosts with a CSP. If a visitor reports a download from your page, capture the network trace before you touch anything.

See also

Exploit kit, Malvertising

Sources

Count this on a real site.

Watch my website