Custom Search

Wednesday, November 17, 2010

Botnet Statistics [2010-11-16]

To reduce the number of mail I have to send, I usually collect information about zombie computers within China in a single notification to CNCERT, National Computer network Emergency Response technical Team/Coordination Center of China.  And China has done a good job on botnet reduction for the past year, which leads to its absence from various reports on spam and botnets, like the "dirty dozen" by Sophos, the top 12 countries of spam source by M86 security, and the top 10 countries sending spam by ICSA Labs.  While China is still the all time number one for the Top Spam Server Countries of Project Honey Pot, it is now at number 17 of the last 30 days.

Since November 1 this year, I started to get failure notice for my notification to CNCERT, which seems to be caused by alias expansion to a mailbox exceeding its quota.   In the mean time, China started to move back up to number 14 on the Top Spam Server Countries of the last 7 days.  I might need to find another way soon to contact them before China returns to top 10 again.

detection period: 2010-11-16 00:00-23:59 UTC
total number of suspected botnet IPs: 3376
number of botnet IPs notified to network operators: 2993
number of blocked spams: 363063
recipient count of blocked spams: 12123150

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1351
2BSNLNET405
3AR-TEAR7-LACNIC63
4RCOM59
5CAT-BB-NET43
6TATACOMM-IN40
7002.558.134/0001-5837
8TRUENET33
9TRUEBB-NET33
10HATHWAY-NET32

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1361
2India590
3China295
4Brazil240
5Russian Federation146
6Thailand142
7Argentina118
8Ukraine53
9United States34
10South Korea34

No comments:

Post a Comment