Custom Search

Monday, November 29, 2010

Botnet Statistics [2010-11-28]

I decommissioned one of my vpses yesterday, as its billing period will be up today.  So I have only two detection systems in operation for the time being.  I also got hold of some domains suitable for greylisting last week.  A lot of work need to be done before I can detect botnet computers with greylisting, but I have high hope for its detection capability.

detection period: 2010-11-28 00:00-23:59 UTC
total number of suspected botnet IPs: 2428
number of botnet IPs notified to network operators: 2013
number of blocked spams: 132822
recipient count of blocked spams: 4440382

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET529
2BSNLNET363
3AR-TEAR7-LACNIC76
4UKRTELNET52
5RCOM41
6002.558.134/0001-5840
7TRUENET36
8KORNET-KR35
9000.065.376/0002-6532
10TATACOMM-IN30

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan544
2India507
3China233
4Russian Federation181
5Brazil177
6Argentina135
7Thailand117
8Ukraine79
9South Korea53
10United States32

No comments:

Post a Comment