Custom Search

Tuesday, November 30, 2010

Botnet Statistics [2010-11-29]

I wrote about failure notices I got when sending notifications to CNCERT two weeks ago.  But then the problem disappeared before I had done anything about it.  I guess I was just lucky. 

I also send notifications about zombie computers in India to the CERT of India.  Unfortunately they began to reject my notifications two days ago.  I might not be so lucky this time...

detection period: 2010-11-29 00:00-23:59 UTC
total number of suspected botnet IPs: 2393
number of botnet IPs notified to network operators: 1949
number of blocked spams: 338506
recipient count of blocked spams: 11568541

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET462
2BSNLNET320
3RCOM59
4AR-TEAR7-LACNIC52
5000.065.376/0002-6536
6TATACOMM-IN35
7002.558.134/0001-5835
8TRUENET30
9KORNET-KR28
10CAT-BB-NET28

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1India492
2Taiwan477
3China268
4Brazil224
5Russian Federation152
6Thailand106
7Argentina102
8Ukraine60
9United States54
10South Korea48

No comments:

Post a Comment