Custom Search

Sunday, May 29, 2011

Botnet Statistics [2011-05-28]

It turned out that I did not notice the SMTP server in my fake open relay died unexpectedly. That is why it had collected nothing for the past few days. I will see whether it can capture anything tomorrow.

detection period: 2011-05-28 00:00-23:59 UTC
total number of suspected botnet IPs: 1188
number of botnet IPs notified to network operators: 816
number of blocked spams: 0
recipient count of blocked spams: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD129
2BSNLNET36
3CRTC33
4CHINANET-JS31
5KORNET-KR29
6AR-TEAR7-LACNIC24
7PTCL16
8TELKOMNET12
9VNPT-VNNIC-VN11
10TATACOMM-IN11

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China357
2India95
3Russian Federation65
4Argentina47
5Brazil46
6South Korea44
7Indonesia37
8United States33
9Poland30
10Chile28

No comments:

Post a Comment