We saw a substantial increase in number of detected bots in June (from 54K in May to 74K in June). Part of the reason might be that I added another detection system around the end of May. There are currently 3 systems running, though one of them is going to be taken offline before the coming August.
But I guess that another event,
the public disclosure of a zero-day vulnerability in Microsoft XP by a Google researcher, also contributed to the increased bot counts. He posted his finding - the details of the vulnerability and proof-of-concept code - to a mailing list on June 10, 5 days after he had informed Microsoft of the vulnerability. Take a look at
bot counts graphs in 5-day entroby at
Shadowserver Foundation. You can see that around one third into June (about June 10), bot counts changed from a rapid declining trend to an increasing one. Though I detected more bots in June, they did not fall back to the previous level, as Microsoft haven't released an official patch for that vulnerability yet.
detection period: 2010-06-01 00:00 - 2010-06-30 23:59 UTC
total number of suspected botnet IPs: 74883
number of blocked spams: 4221977
recipient count of blocked spams: 100120734
The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
Rank | Country | # of suspected botnet IPs |
1 | India | 25243 |
2 | Taiwan | 16854 |
3 | China | 15323 |
4 | Brazil | 5029 |
5 | Argentina | 3187 |
6 | Russian Federation | 2059 |
7 | Thailand | 1032 |
8 | Ukraine | 617 |
9 | Mexico | 523 |
10 | Ethiopia | 522 |
11 | United States | 433 |
12 | Uruguay | 349 |
13 | Chile | 253 |
14 | Germany | 241 |
15 | Indonesia | 222 |
16 | South Korea | 188 |
17 | Japan | 184 |
18 | Colombia | 175 |
19 | Belarus | 152 |
20 | Algeria | 136 |
21 | Iran | 129 |
22 | Kazakhstan | 128 |
23 | France | 128 |
24 | Hong Kong | 122 |
25 | Egypt | 106 |
The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:
Rank | Country | # of blocked spams |
1 | China | 1155932 |
2 | Taiwan | 792198 |
3 | Brazil | 459900 |
4 | India | 341508 |
5 | Malaysia | 235830 |
6 | Russian Federation | 154396 |
7 | United States | 133067 |
8 | Thailand | 112624 |
9 | Indonesia | 99006 |
10 | Argentina | 95129 |
11 | Colombia | 78206 |
12 | Ukraine | 39531 |
13 | Chile | 36692 |
14 | South Korea | 31964 |
15 | Czech Republic | 30782 |
16 | Poland | 28600 |
17 | France | 27340 |
18 | Viet Nam | 21405 |
19 | Pakistan | 19818 |
20 | Saudi Arabia | 18992 |
21 | United Kingdom | 16810 |
22 | Germany | 16643 |
23 | Philippines | 16404 |
24 | Czechoslovakia | 16397 |
25 | Italy | 16167 |
The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are: