Custom Search

Saturday, March 27, 2010

Botnet Statistics [2010-03-26]

One of my 2 detection systems, which usually detects more bots than the other, has some problem today. I have not been able to connect to it so far. So the following data were calculated only from the log of the other one.

detection period: 2010-03-26 00:00-23:59 UTC
total number of suspected botnet IPs: 1653
number of botnet IPs notified to network operators: 1420
number of blocked spams: 87331
recipient count of blocked spams: 1315757

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1RITELE331
2BSNLNET256
3002.558.157/0001-6260
4AR-TEAR7-LACNIC53
5RCOM37
6TATACOMM-IN33
7HATHWAY-NET27
8UNICOM-SD26
9000.065.376/0002-6520
10076.535.764/0326-9019

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China625
2India395
3Brazil213
4Argentina89
5Russian Federation50
6Thailand23
7Colombia22
8United States21
9Indonesia21
10South Korea17

No comments:

Post a Comment