Custom Search

Saturday, October 9, 2010

Botnet Statistics for September 2010

After some network and machine outages, I currently rent more than one vps to get some fault tolerance for my botnet detection system. Sometimes one of them will serve as my test server, and data collected on that server might not get included in the daily statistics. I include their data when calculating the monthly statistics, so the monthly number of blocked spams and recipient count might be more than the sum from daily statistcis. Just in case you ask.

detection period: 2010-09-01 00:00 - 2010-09-30 23:59 UTC
total number of suspected botnet IPs: 56714
number of blocked spams: 13056115
recipient count of blocked spams: 421289111

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1India17628
2Taiwan16951
3China7909
4Brazil2933
5Argentina2093
6Thailand1773
7Russian Federation1563
8United States1133
9Ukraine579
10Mexico375
11Ethiopia292
12Uruguay285
13South Korea232
14Belarus231
15France229
16Indonesia198
17Chile191
18Colombia187
19Germany167
20Algeria117
21Kazakhstan104
22Japan104
23Poland82
24Italy82
25Bulgaria71

The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:

RankCountry# of blocked spams
1China1970854
2United States1830078
3Taiwan1579124
4Brazil1331285
5Russian Federation746560
6India573092
7Colombia497750
8Thailand285832
9Germany266227
10South Korea216575
11Italy205606
12Poland204572
13Indonesia201191
14France187902
15Argentina130538
16Ukraine121000
17Mexico119281
18Philippines108120
19United Kingdom106935
20Romania97768
21Iran94265
22Peru80958
23Spain80935
24Australia77240
25South Africa72905

The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:

RankCountryrecipient count of blocked spams
1United States61392408
2China51348030
3Brazil46182326
4Taiwan43257451
5Russian Federation25815320
6India19862215
7Colombia17365717
8Thailand9864240
9Germany9288938
10South Korea7516506
11Italy7141024
12Indonesia6832511
13Poland6763972
14France6442797
15Argentina4443870
16Ukraine4200171
17Mexico4162841
18Philippines3771465
19United Kingdom3678922
20Romania3414965
21Iran3274869
22Peru2831273
23Spain2814125
24Australia2700151
25South Korea2552091

The top 25 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET16831
2BSNLNET13550
3CHINANET-GD4516
4AR-TEAR7-LACNIC1686
5TATACOMM-IN1378
6RCOM887
7002.558.134/0001-58819
8TRUENET640
9ALLIANCEBROADBAND579
10HATHWAY-NET538
11UNICOM-SD455
12002.449.992/0001-64443
13CAT-BB-NET440
14000.065.376/0002-65395
15TRUEBB-NET346
16PACENET325
17040.432.544/0001-47318
18UKRTELNET300
19076.535.764/0326-90297
20ETHIONET291
21UY-ANTA-LACNIC281
22MX-GICS-LACNIC208
23CHINANET-ZJ-WZ201
24CHINANET-JX175
25UNICOM-LN158

The top 25 networks (as found in WHOIS), ordered by number of blocked spams are:

RankNetwork# of blocked spams
1HINET-NET1359302
2CHINANET-ZJ-WZ623866
3000.065.376/0002-65284392
4OC3-NETWORKS2262771
5CO-ACSA-LACNIC224416
6CHINANET-GD194670
7003.420.926/0002-05191427
8RSCP-NET-4185453
9033.530.486/0001-29176683
10002.558.134/0001-58129425
11TFN-NET128084
12BSNLNET123993
13OC3-NETWORKS116767
14NETBLK-THEPLANET-BLK-16107150
15CO-CTSE-LACNIC104731
16RCOM103073
17CO-ETBE-LACNIC97223
18076.535.764/0326-9091059
19CAVTEL-BLK-888201
20BORANET-KR71132
21UNICOM-HE69569
22NETBLK-THEPLANET-BLK-1568796
23KORNET-KR68141
24CHINANET-JS64463
25002.558.157/0001-6263472

The top 25 networks (as found in WHOIS), ordered by recipient count of blocked spams are:

RankNetworkrecipient count of blocked spams
1HINET-NET37820293
2000.065.376/0002-659948893
3OC3-NETWORKS29887394
4CHINANET-ZJ-WZ9598055
5CO-ACSA-LACNIC7829798
6003.420.926/0002-056657708
7RSCP-NET-46487054
8033.530.486/0001-296122696
9002.558.134/0001-584517497
10BSNLNET4259928
11OC3-NETWORKS4086539
12NETBLK-THEPLANET-BLK-163749920
13CO-CTSE-LACNIC3652562
14RCOM3570340
15CO-ETBE-LACNIC3399316
16076.535.764/0326-903134618
17CHINANET-GD3081822
18TFN-NET2494178
19BORANET-KR2470775
20NETBLK-THEPLANET-BLK-152407314
21KORNET-KR2365899
22UNICOM-HE2332803
23SOFTLAYER-4-82217317
24002.558.157/0001-622208387
25OVH2192178

No comments:

Post a Comment