Hot Take [Updated 29/12/2018] Browser extension comparison: Malwares and Phishings

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Comparison between browser extensions

Test 29/12
Q&A - [Updated 29/12/2018] Browser extension comparison: Malwares and Phishings


Test 24/11
Q&A - [Updated 24/11/2018] Browser extension comparison: Malwares and Phishings


Test 12/11
Q&A - [Updated 12/11/2018] Browser extension comparison: Malwares and Phishings


Test 7/11
Q&A - [Updated 7/11/2018] Browser extension comparison: Malwares and Phishings


Test 6/9
Q&A - [Updated 3/9/2018] Browser extension comparison: Malwares and Phishings


Test 3/9
Q&A - [Updated 3/9/2018] Browser extension comparison: Malwares and Phishings


Test 2/9
Q&A - [Updated 25/7/2018] Browser extension comparison: Malwares and Phishings


Test, quick 1/9
Q&A - [Updated 25/7/2018] Browser extension comparison: Malwares and Phishings


Fun test 25/7/2018
Q&A - [Updated 24/7/2018] Browser extension comparison: Malwares and Phishings


Updated 24/7/2018 (most comprehensive, as possible)
Q&A - [Updated 24/7/2018] Browser extension comparison: Malwares and Phishings


Updated 19/7/2018
Q&A - [Updated 10/7/2018] Browser extension comparison: Malwares and Phishings


Updated 18/7/2018
Q&A - [Updated 10/7/2018] Browser extension comparison: Malwares and Phishings


Updated 10/7/2018
Q&A - [Updated 10/7/2018] Browser extension comparison: Malwares and Phishings


Updated 7/6/2018
Q&A - [Updated 7/6/2018] Browser extension comparison: Malwares and Phishings


Updated 3/6/2018
Q&A - [Updated 3/6/18] Browser extension comparison: Malwares and Phishings


Updated 25/4/2018
Poll - [Updated 25/4/18] Browser extension comparison: Malwares and Phishings


Update: 23/3/2018
Poll - [Updated 23/3/18] Browser extension comparison: Malwares and Phishings



Browser: Google Chrome 65 x64
Malware and phishing links: 10 malc0de, 10 vxvault, 10 openphish, 10 verified phishtank, 10 unverified phishtank
Total: 50 links
Extensions: recently downloaded from Chrome Web Store
- Google Safe Browsing (built-in chrome's protection)
- AdGuard AdBlocker: default settings, uses Google Safe Browsing (delayed) and their own database
- Avira browser safety: default settings
- Norton Safe Web: default settings
- Bitdefender Trafficlight: default settings, it rarely blocks any malware links, just old ones
- Avast Online Security: default settings, only has phishing protection, expected to score 0 against malwares
- Netcraft Extension: default settings, only has phishing protection, expected to score 0 against malwares
- uBlock Origin with some additional filters

NOTE: the result can vary from day-to-day. Tomorrow with different links, the result can be very different. All are live links but they can be dead a few minutes after the test. No duplication

Results:
result.png


Winner: Google Safe Browsing
 
Last edited:

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Hello Evjl's Rain,

I am curious, I know that in your tests the VX Vault list is better than the default Ublock Origin malware lists (Malvertising filter list by Disconnect, Malware Domain List, Malware Domains, and Spam404), but how would you rank those default Ublock Origin malware lists from best to worst?

Thank you,
-John Jr
makware domain list ~ malware domain >>> disconnect = spam404 ~ 0
they are basically useless. In 2 years of using my browser with them enabled, I rarely saw any block
while I could see many with other filters
vxvault list is just a failsafe when you accidentally click on a new malware links which are missed by other extensions
 
Last edited:

goodjohnjr

Level 5
Verified
Jul 11, 2018
231
makware domain list ~ malware domain >>> disconnect = spam404 ~ 0
they are basically useless. In 2 years of using my nrowser with them enabled, I rarely saw any block
while I could see many with other filters
vxvault list is just a failsafe when you accidentally click on a new malware links which are missed by other extensions


That was fast, thank you very much Evjl's Rain.

-John Jr
 

Moonhorse

Level 38
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,728
Have done recently some real life phishing tests, just explain how good netcraft is for basic user.

heres example with one url;

Firefox fail:firefoxfail.png

opera fail:
operafail.png
chrome fail:
chrome fail.png
AVG free fail:
avgfail.png


Netcraft blocks url:
netcraftdid.png

I know firefox, opera, etc clones use google safe browsing but sometimes their database is updated late comparing to google chrome

edit:vtjeez.png

Avira extension maybe will block it aswell
 

Attachments

  • firefoxfail.png
    firefoxfail.png
    346.2 KB · Views: 477
Last edited by a moderator:

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
for phishing, no comparison, netcraft wins

avast/AVG has weak phishing protection because they explained to me clearly that they only add frequently visited phishing, not the latest phishing links to reduce the size of the update
the advice me to install avast online security for better phishing protection and it did. Avast online security is a quite powerful anti-phishing extension, but not as good as netcraft

any browser other chrome has 30min delay database of google safe browsing. There is an option in google chrome, which reports malicious sites in realtime and blocks them. In saw some phishing missed but 10s later without refreshing the page, they were blocked. Many people disable it due to privacy concern
 

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,158
Have done recently some real life phishing tests, just explain how good netcraft is for basic user.

heres example with one url;

Firefox fail:View attachment 196411

opera fail:
View attachment 196412
chrome fail:
View attachment 196413
AVG free fail:
View attachment 196414


Netcraft blocks url:
View attachment 196415

I know firefox, opera, etc clones use google safe browsing but sometimes their database is updated late comparing to google chrome

edit:View attachment 196416

Avira extension maybe will block it aswell
Malwarebytes extension blocks the site. ESET IS also blocks it

Interestingly, uBO with the followings did not block the site

https://hosts-file.net/psh.txt
https://openphish.com/feed.txt
 
Last edited:

Moonhorse

Level 38
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,728

Ink

Administrator
Verified
Jan 8, 2011
22,490
If you're going to test Netcraft and Avira extensions, don't forget Windows Defender Browser Protection by Microsoft, to compare with Google SafeBrowsing.

Have done recently some real life phishing tests, just explain how good netcraft is for basic user.

Netcraft blocks url:
View attachment 196415
Blocked by WD SmartScreen & WDBP for Chrome.

1535042220737.png
 

Mahesh Sudula

Level 17
Verified
Top Poster
Well-known
Sep 3, 2017
825
The AV engines in the VT either scan through Cloud or the Av's blacklisted lists for sure..
How ever real time detections may differ to some extent ..KAspersky & NOrton use heuristic analysis(proactive approach) to spot a phished URL which may not reflect in the VT..
Net craft is a anti phishing champ since years..That's for sure!
 

Mahesh Sudula

Level 17
Verified
Top Poster
Well-known
Sep 3, 2017
825
And what about malware protection?
Furthermore, how is it different from BD Trafficlight?
As for as signatures concerned..it is from Bit defender including Cloud access
But not sure about its Behaviour blocker (Active Virus Control)..
as per my tests it is not as same as BD (Active Threat Control) ..
My open opinion on Ad aware... leave it..not at all recommended even as free _/\_
 
  • Like
Reactions: AtlBo and Moonhorse

imuade

Level 12
Verified
Top Poster
Well-known
Jul 29, 2018
566
As for as signatures concerned..it is from Bit defender including Cloud access
But not sure about its Behaviour blocker (Active Virus Control)..
as per my tests it is not as same as BD (Active Threat Control) ..
My open opinion on Ad aware... leave it..not at all recommended even as free _/\_
Thanks, but I was not talking about adaware antivirus+ vs Bitdefender Free AV, I was comparing adaware web companion with Bitdefender Trafficlight
 
  • Like
Reactions: Ink and AtlBo

TairikuOkami

Level 37
Verified
Top Poster
Content Creator
Well-known
May 13, 2017
2,685
Website states it blocks Adult websites, nothing about Malicious sites.
Adult websites host 5-10% of malicious content, that is not a big number, but every little bit helps, especially since it is default deny. The only downside is (except blocking adult content, rofl), that the better filter the more legitimate content is blocked as well, like image/video hosting.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top