Published June 6, 2018 | Version v1
Journal article Open

Costly Freeware: A Systematic Analysis of Abuse in Download Portals

  • 1. IMDEA Software Institute


Freeware is proprietary software that can be used free of charge. A popular vector for distributing freeware are download
portals, i.e., websites that index, categorize, and host programs. Download portals can be abused to distribute potentially unwanted
programs (PUP) and malware. The abuse can be due to PUP and malware authors uploading their ware, by benign freeware
authors joining as affiliate publishers of PPI services and other affiliate programs, or by malicious download portal owners. In this
work, we perform a systematic study of abuse in download portals. We build a platform to crawl download portals and apply it to
download 191K Windows freeware installers from 20 download portals. We analyze the collected installers and execute them in a
sandbox to monitor their installation. We measure an overall ratio of PUP and malware between 8% (conservative estimate) and
26% (lax estimate). In 18 of the 20 download portals examined the amount of PUP and malware is below 9%. But, we also find
two download portals exclusively used to distribute PPI downloaders. Finally, we detail different abusive behaviors that authors of
undesirable programs use to distribute their programs through download portals.



Files (752.0 kB)

Name Size Download all
752.0 kB Preview Download

Additional details


ELASTEST – ElasTest: an elastic platform for testing complex distributed large software systems 731535
European Commission