Custom Search

Wednesday, December 2, 2009

Botnet Statistics [2009-12-01]

HiNet in Taiwan got a surprising surge in botnet computers. My detection system logged more than 2000 botnet IPs from HiNet. Is this an outbreak of a new attack vector?

detection period: 2009-12-01 00:00-23:59 UTC
total number of suspected botnet IPs: 3723
number of botnet IPs notified to network operators: 3499

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET2112
2CHINANET-GD252
3BSNLNET101
4002.558.157/0001-6294
5AR-TEAR7-LACNIC78
6002.558.134/0001-5839
7UNICOM-SD31
8002.449.992/0001-6431
9AR-CASA10-LACNIC27
10AR-PRSA-LACNIC25

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan2127
2China558
3Brazil295
4India182
5Argentina143
6Russian Federation77
7United States44
8Colombia26
9Ukraine25
10Thailand21

No comments:

Post a Comment