I regularly move the collected data (mail log) off my vpses, which only have limited storage space. Now all the old data (since last June) reside on my Windows PC at home. Unable to move them back to the vps (I have only 256Kbps upload bandwidth at home), I have to process them under UWIN , a UNIX emulation under Windows by AT&T, instead. A script taking minutes to run in the vps, now takes hours to complete under UWIN. I knew Windows was not a good fit for a UNIX environment, but I never thought the difference would be so huge.
detection period: 2009-06-08 07:37 - 2009-06-30 23:59 UTC
total number of suspected botnet IPs: 15240
number of blocked spams: 940245
recipient count of blocked spams: 13480394
The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
Rank | Country | # of suspected botnet IPs |
---|---|---|
1 | Taiwan | 14726 |
2 | China | 258 |
3 | Brazil | 54 |
4 | India | 46 |
5 | Russian Federation | 23 |
6 | United States | 22 |
7 | Indonesia | 8 |
8 | Bulgaria | 8 |
9 | Hong Kong | 7 |
10 | Germany | 6 |
11 | Colombia | 6 |
12 | Argentina | 6 |
13 | Pakistan | 5 |
14 | France | 5 |
15 | Egypt | 5 |
16 | Thailand | 4 |
17 | South Korea | 4 |
18 | Iran | 4 |
19 | Czech Republic | 4 |
20 | Philippines | 3 |
21 | Malaysia | 3 |
22 | United Kingdom | 3 |
23 | Spain | 3 |
24 | Ukraine | 2 |
25 | Mongolia | 2 |
The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:
Rank | Country | # of blocked spams |
---|---|---|
1 | Taiwan | 725865 |
2 | Malaysia | 152121 |
3 | China | 57677 |
4 | Brazil | 802 |
5 | United States | 618 |
6 | India | 411 |
7 | Russian Federation | 364 |
8 | Hong Kong | 342 |
9 | Indonesia | 278 |
10 | Ukraine | 208 |
11 | Argentina | 150 |
12 | Bangladesh | 144 |
13 | Colombia | 122 |
14 | Germany | 118 |
15 | Bulgaria | 112 |
16 | Czech Republic | 108 |
17 | United Kingdom | 71 |
18 | Czechoslovakia | 68 |
19 | Belgium | 64 |
20 | Italy | 61 |
21 | Thailand | 60 |
22 | Philippines | 60 |
23 | Pakistan | 52 |
24 | Egypt | 47 |
25 | Canada | 47 |
The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:
Rank | Country | recipient count of blocked spams |
---|---|---|
1 | Taiwan | 9985102 |
2 | Malaysia | 2433933 |
3 | China | 926359 |
4 | Brazil | 24033 |
5 | United States | 18039 |
6 | India | 12459 |
7 | Russian Federation | 10436 |
8 | Hong Kong | 10207 |
9 | Indonesia | 8240 |
10 | Ukraine | 6200 |
11 | Argentina | 4603 |
12 | Bangladesh | 4239 |
13 | Colombia | 3689 |
14 | Bulgaria | 3534 |
15 | Germany | 3357 |
16 | Czech Republic | 3230 |
17 | Czechoslovakia | 1997 |
18 | United Kingdom | 1971 |
19 | Thailand | 1846 |
20 | Belgium | 1813 |
21 | Italy | 1692 |
22 | Philippines | 1483 |
23 | Pakistan | 1410 |
24 | Canada | 1273 |
25 | Egypt | 1251 |
The top 25 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | APOL-NET | 8993 |
2 | HINET-NET | 4758 |
3 | TFN-NET | 964 |
4 | CHINANET-ZJ-WZ | 121 |
5 | UNICOM-GD | 22 |
6 | BSNLNET | 18 |
7 | 002.558.157/0001-62 | 14 |
8 | UNKNOWN | 12 |
9 | RCOM | 11 |
10 | UNICOM-HA | 10 |
11 | UNICOM-CN | 9 |
12 | UNICOM-SD | 8 |
13 | BTN-CIDR3 | 8 |
14 | UNICOM-HE | 7 |
15 | HGC | 6 |
16 | CHINANET-HB | 6 |
17 | 033.530.486/0001-29 | 5 |
18 | 000.065.376/0002-65 | 5 |
19 | TATACOMM-IN | 4 |
20 | SCARTEL | 4 |
21 | CHINANET-JS | 4 |
22 | CHINANET-GX | 4 |
23 | CHINANET-AH | 4 |
24 | AR-TEAR7-LACNIC | 4 |
25 | UNICOM-HL | 3 |
The top 25 networks (as found in WHOIS), ordered by number of blocked spams are:
Rank | Network | # of blocked spams |
---|---|---|
1 | HINET-NET | 548950 |
2 | APOL-NET | 131795 |
3 | TMIDC-MY | 85375 |
4 | EASTGATE | 66746 |
5 | CHINANET-ZJ-WZ | 54185 |
6 | TFN-NET | 44884 |
7 | UNICOM-HE | 366 |
8 | HGC | 340 |
9 | CHINANET-SH | 311 |
10 | UNICOM-HA | 307 |
11 | IPNET-ID | 207 |
12 | HANGZHOU-DACHENG-NETBAR | 195 |
13 | UNICOM-SD | 189 |
14 | CHINANET-HB | 179 |
15 | EDUNET1 | 174 |
16 | DXTNET | 166 |
17 | UNKNOWN | 150 |
18 | NETBLK-PRESCIENT01 | 148 |
19 | FIBRENET-BD | 144 |
20 | RCOM | 143 |
21 | CHINANET-YN | 125 |
22 | BTN-CIDR3 | 125 |
23 | NETBLK-THEPLANET-BLK-13 | 121 |
24 | 033.530.486/0001-29 | 117 |
25 | 001.947.194/0001-08 | 117 |
The top 25 networks (as found in WHOIS), ordered by recipient count of blocked spams are:
Rank | Network | recipient count of blocked spams |
---|---|---|
1 | HINET-NET | 8292464 |
2 | TMIDC-MY | 1365997 |
3 | EASTGATE | 1067936 |
4 | APOL-NET | 1067228 |
5 | CHINANET-ZJ-WZ | 825780 |
6 | TFN-NET | 618411 |
7 | UNICOM-HE | 10343 |
8 | HGC | 10161 |
9 | UNICOM-HA | 9290 |
10 | CHINANET-SH | 8722 |
11 | IPNET-ID | 6320 |
12 | HANGZHOU-DACHENG-NETBAR | 5978 |
13 | UNICOM-SD | 5424 |
14 | EDUNET1 | 5219 |
15 | CHINANET-HB | 5078 |
16 | DXTNET | 4623 |
17 | RCOM | 4414 |
18 | NETBLK-PRESCIENT01 | 4361 |
19 | UNKNOWN | 4297 |
20 | FIBRENET-BD | 4239 |
21 | 033.530.486/0001-29 | 3764 |
22 | CHINANET-YN | 3706 |
23 | NETBLK-THEPLANET-BLK-13 | 3604 |
24 | BTN-CIDR3 | 3459 |
25 | 001.947.194/0001-08 | 3331 |
No comments:
Post a Comment