Malware
Drive-by download
Drive-by download is malware that installs just because a visitor loaded a page, with no click on a download button. It exploits a browser or plugin flaw, or tricks the browser into saving a file.
How it is measured
Observe it in a sandbox: open the page in a throwaway browser and watch for file writes, new processes, or a download that begins without interaction. Network logs show the redirect chain, often through two or three hops to an exploit-hosting server.
On the site, the entry point is injected script or an iframe that points at the hop. Search the HTML for hidden frames and obfuscated script tags.
Worked example
A visitor to a local news site reports that Windows Defender flagged a file after reading an article. Looking at the page, a script in the sidebar ad slot requests `track.adnet-sync.top/l.js`, which redirects to a page that serves a `.js` file with `Content-Disposition: attachment`.
The ad network pulls the creative after the news site reports it. The site also adds a CSP that blocks any script host it did not list.
How it differs
A drive-by download is the delivery. An exploit kit is the toolbox that decides which browser hole to try. Malvertising is one route, where a bought ad carries the redirect. A normal download needs a click, while a drive-by needs only that the victim visits the page.
Common errors
Assuming users must click something. Patching the server but not the ad stack. Ignoring old browsers in your own office. Blocking one URL and missing the redirect chain. Testing on a fully patched modern browser and calling it safe.
In practice
Keep browsers and plugins updated on every machine that visits your site. Review third-party ad and widget scripts, and restrict hosts with a CSP. If a visitor reports a download from your page, capture the network trace before you touch anything.