Custom Search

Saturday, March 12, 2011

Botnet Statistics for February 2011

Now I detect botnets with both fake open relays and greylisting. I could only detect about 14000 bots in February if greylisting is not used. After all, some spammers might have been driven out of business by my fake open relays, which have been operating for one and a half years now. But the numbers for blocked spams and recipients do not include the number from greylisting, as it gets much less spam mail than fake open relays.

detection period: 2011-02-01 00:00 - 2011-02-28 23:59 UTC
total number of suspected botnet IPs: 39902
number of blocked spams: 5971039
recipient count of blocked spams: 156118318

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China11731
2Taiwan5627
3India2838
4Brazil1995
5Viet Nam1698
6Indonesia1684
7Russian Federation1607
8South Korea1059
9Pakistan936
10Ukraine871
11Thailand732
12Belarus697
13Argentina481
14Colombia460
15Kazakhstan450
16United States409
17Peru338
18Poland310
19Germany283
20Romania277
21Saudi Arabia243
22Iran223
23Chile195
24Israel186
25France184

The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:

RankCountry# of blocked spams
1China1652622
2Brazil652219
3Taiwan356441
4India339544
5United States339027
6Russian Federation261236
7Colombia206402
8Indonesia177712
9Poland140927
10South Korea124034
11Thailand120969
12Ukraine88984
13Philippines88518
14France87309
15Germany68682
16Viet Nam66843
17Italy59903
18Spain58577
19Argentina55247
20Mexico50735
21Japan48374
22United Kingdom43967
23Netherlands37509
24Turkey37489
25European Union36650

The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:

RankCountryrecipient count of blocked spams
1China37991841
2Brazil17770374
3United States9953708
4Taiwan9131848
5India8755238
6Russian Federation6939250
7Colombia5573732
8Indonesia4735802
9Poland3522806
10South Korea3435207
11Thailand3277442
12Ukraine2608151
13Philippines2392940
14France2173634
15Germany1997437
16Italy1824146
17Viet Nam1701654
18Argentina1624490
19Spain1609469
20Mexico1528301
21United Kingdom1318905
22Japan1267370
23Canada1091878
24European Union1081394
25Turkey1075689

The top 25 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD5629
2HINET-NET5482
3UNICOM-BJ1978
4BSNLNET1258
5VNPT-VNNIC-VN1210
6PTCL825
7TELKOMNET756
8CRTC551
9BY-BELPAK-20091210545
10CTTNET516
11KORNET-KR510
12UNICOM-HA493
13002.558.134/0001-58439
14002.558.157/0001-62317
15UNICOM-HN303
16RCOM300
17UKRTELNET295
18TATACOMM-IN293
19000.065.376/0002-65290
20076.535.764/0326-90262
21CHINANET-JS251
22AR-TEAR7-LACNIC233
23TRUENET176
24CHINANET-HN166
25CHINANET-ZJ-WZ161

The top 25 networks (as found in WHOIS), ordered by number of blocked spams are:

RankNetwork# of blocked spams
1CHINANET-ZJ-WZ379624
2HINET-NET300195
3003.420.926/0002-05158123
4CHINANET-GD145683
5UNICOM-SD119948
6CO-ACSA-LACNIC111031
7033.530.486/0001-2999313
8CHINANET-JS92262
9RCOM80968
10KORNET-KR74897
11CHINANET-ZJ65399
12TELKOMNET64463
13BSNLNET58706
14VNPT-VNNIC-VN58033
15UNICOM-BJ57090
16BHARTI-IN51775
17INTER-SAT49664
18002.558.157/0001-6248431
19TATACOMM-IN45215
20UNICOM-HE44202
21076.535.764/0326-9042981
22004.027.547/0001-3140099
23FR-OVH-2006092035347
24GT-TESA-LACNIC33504
25VE-CSVE-LACNIC33398

The top 25 networks (as found in WHOIS), ordered by recipient count of blocked spams are:

RankNetworkrecipient count of blocked spams
1HINET-NET7710035
2CHINANET-ZJ-WZ5773410
3003.420.926/0002-054225707
4UNICOM-SD3303953
5CO-ACSA-LACNIC3058745
6CHINANET-GD2852395
7CHINANET-JS2774802
8033.530.486/0001-292678401
9RCOM2084967
10KORNET-KR1968991
11TELKOMNET1644661
12VNPT-VNNIC-VN1423392
13BSNLNET1419662
14BHARTI-IN1332968
15TATACOMM-IN1264869
16002.558.157/0001-621264549
17INTER-SAT1186846
18CHINANET-ZJ1175551
19076.535.764/0326-901146810
20UNICOM-HE1096710
21004.027.547/0001-311069112
22VE-CSVE-LACNIC957024
23000.065.376/0002-65892529
24OVH879711
25CO-ETBE-LACNIC874974

No comments:

Post a Comment