Custom Search

Saturday, July 3, 2010

Botnet Statistics for June 2010

We saw a substantial increase in number of detected bots in June (from 54K in May to 74K in June). Part of the reason might be that I added another detection system around the end of May. There are currently 3 systems running, though one of them is going to be taken offline before the coming August.

But I guess that another event, the public disclosure of a zero-day vulnerability in Microsoft XP by a Google researcher, also contributed to the increased bot counts. He posted his finding - the details of the vulnerability and proof-of-concept code - to a mailing list on June 10, 5 days after he had informed Microsoft of the vulnerability. Take a look at bot counts graphs in 5-day entroby at Shadowserver Foundation. You can see that around one third into June (about June 10), bot counts changed from a rapid declining trend to an increasing one. Though I detected more bots in June, they did not fall back to the previous level, as Microsoft haven't released an official patch for that vulnerability yet.

detection period: 2010-06-01 00:00 - 2010-06-30 23:59 UTC
total number of suspected botnet IPs: 74883
number of blocked spams: 4221977
recipient count of blocked spams: 100120734

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1India25243
2Taiwan16854
3China15323
4Brazil5029
5Argentina3187
6Russian Federation2059
7Thailand1032
8Ukraine617
9Mexico523
10Ethiopia522
11United States433
12Uruguay349
13Chile253
14Germany241
15Indonesia222
16South Korea188
17Japan184
18Colombia175
19Belarus152
20Algeria136
21Iran129
22Kazakhstan128
23France128
24Hong Kong122
25Egypt106

The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:

RankCountry# of blocked spams
1China1155932
2Taiwan792198
3Brazil459900
4India341508
5Malaysia235830
6Russian Federation154396
7United States133067
8Thailand112624
9Indonesia99006
10Argentina95129
11Colombia78206
12Ukraine39531
13Chile36692
14South Korea31964
15Czech Republic30782
16Poland28600
17France27340
18Viet Nam21405
19Pakistan19818
20Saudi Arabia18992
21United Kingdom16810
22Germany16643
23Philippines16404
24Czechoslovakia16397
25Italy16167

The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:

RankCountryrecipient count of blocked spams
1China25151146
2Taiwan18736442
3Brazil12591055
4India10674543
5Malaysia3889006
6Russian Federation3787016
7Thailand3315279
8Argentina2665985
9Indonesia2321815
10United States2275565
11Colombia2257047
12Chile994345
13Ukraine944411
14South Korea684327
15Czech Republic663982
16Poland653731
17France571959
18Pakistan518745
19Viet Nam474920
20Israel454841
21Germany407747
22Saudi Arabia391472
23Philippines371239
24Czechoslovakia340832
25Egypt314877

The top 25 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BSNLNET19044
2HINET-NET15959
3CHINANET-GD6556
4AR-TEAR7-LACNIC2514
5RITELE2494
6TATACOMM-IN1722
7RCOM1366
8002.558.134/0001-581061
9ALLIANCEBROADBAND1038
10002.558.157/0001-62965
11HATHWAY-NET954
12UNICOM-SD872
13002.449.992/0001-64770
14TFN-NET752
15000.065.376/0002-65566
16ETHIONET522
17TRUENET503
18040.432.544/0001-47453
19UNKNOWN419
20CHINANET-JX419
21MX-GICS-LACNIC397
22PACENET379
23CHINANET-HN379
24UNICOM-SX348
25UY-ANTA-LACNIC346

The top 25 networks (as found in WHOIS), ordered by number of blocked spams are:

RankNetwork# of blocked spams
1HINET-NET767006
2BSNLNET167134
3TMIDC-MY161931
4CHINANET-GD135206
5RCOM79720
6UNICOM-SD75802
7000.065.376/0002-6571827
8002.558.157/0001-6270370
9076.535.764/0326-9065668
10UNICOM-HE63849
11CHINANET-ZJ-WZ59413
12UNICOM-LN59132
13EASTGATE56519
14033.530.486/0001-2952594
15CHINANET-JS49588
16TRUENET36972
17AR-TEAR7-LACNIC34422
18UNICOM-HA34097
19CHINANET-SN33178
20CO-ACSA-LACNIC32474
21CHINANET-YN32422
22CHINANET-JX31290
23TELKOMNET30095
24UNICOM-BJ26894
25RITELE25876

The top 25 networks (as found in WHOIS), ordered by recipient count of blocked spams are:

RankNetworkrecipient count of blocked spams
1HINET-NET18280588
2BSNLNET5356235
3TMIDC-MY2590896
4RCOM2476588
5000.065.376/0002-652290256
6UNICOM-SD2219380
7002.558.157/0001-621929150
8076.535.764/0326-901683896
9CHINANET-GD1599502
10UNICOM-HE1476424
11UNICOM-LN1443126
12033.530.486/0001-291314899
13TRUENET1258953
14CHINANET-JS1228402
15AR-TEAR7-LACNIC1152185
16CHINANET-ZJ-WZ947416
17CHINANET-JX934147
18EASTGATE903802
19CO-ACSA-LACNIC899673
20CHINANET-SN892316
21CHINANET-YN855533
22TELKOMNET804760
23UNICOM-HA796317
24001.402.946/0001-47787367
25CHINANET-CQ644624

No comments:

Post a Comment