Custom Search

Monday, February 1, 2010

Botnet Statistics [2010-01-31]

Last week I read a paper titled "Spamming Chains: A New Way of Understanding Spammer Behavior" from CEAS 2009, and then realized that I should add number of blocked spams and recipient count of blocked spams to my daily statistics. So here they are.

detection period: 2010-01-31 00:00-23:59 UTC
total number of suspected botnet IPs: 3140
number of botnet IPs notified to network operators: 2876
number of blocked spams: 142094
recipient count of blocked spams: 4283754

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1338
2BSNLNET221
3TFN-NET149
4002.558.157/0001-6284
5UNICOM-SD64
6AR-TEAR7-LACNIC60
7CHINANET-JS43
8UNICOM-HA38
9CHINANET-GD38
10002.558.134/0001-5835

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1499
2China579
3India315
4Brazil255
5Argentina124
6Russian Federation55
7United States32
8Colombia21
9Thailand19
10Indonesia19

No comments:

Post a Comment