Custom Search

Thursday, June 30, 2011

Botnet Statistics [2011-06-29]

No data of fake open relay today.

detection period: 2011-06-29 00:00-23:59 UTC
total number of suspected botnet IPs: 939
number of botnet IPs notified to network operators: 709
number of blocked spams: 0
recipient count of blocked spams: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BSNLNET86
2CHINANET-GD59
3UNICOM-BJ48
4CHINANET-JS43
5CRTC33
6KORNET-KR19
7RCOM18
8CHINANET-ZJ17
9VNPT-VNNIC-VN16
10MTNLISP15

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China330
2India154
3Brazil62
4Russian Federation42
5South Korea42
6United States36
7Ukraine23
8Viet Nam20
9Taiwan18
10Indonesia17

Wednesday, June 29, 2011

Botnet Statistics [2011-06-28]

No data of fake open relay today.

detection period: 2011-06-28 00:00-23:59 UTC
total number of suspected botnet IPs: 1345
number of botnet IPs notified to network operators: 957
number of blocked spams: 0
recipient count of blocked spams: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BSNLNET118
2CHINANET-GD101
3UNICOM-BJ75
4CHINANET-JS39
5VNPT-VNNIC-VN33
6KORNET-KR32
7CRTC31
8TELKOMNET18
9TATACOMM-IN18
10002.558.134/0001-5818

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China429
2India217
3Brazil84
4South Korea79
5Russian Federation60
6United States45
7Viet Nam43
8Indonesia38
9Taiwan20
10Pakistan17

Tuesday, June 28, 2011

Botnet Statistics [2011-06-27]

No data of fake open relay today.

detection period: 2011-06-27 00:00-23:59 UTC
total number of suspected botnet IPs: 1352
number of botnet IPs notified to network operators: 934
number of blocked spams: 0
recipient count of blocked spams: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD104
2BSNLNET71
3UNICOM-BJ56
4KORNET-KR48
5CHINANET-JS38
6VNPT-VNNIC-VN31
7CRTC29
8RCOM22
9000.065.376/0002-6521
10CHINANET-ZJ20

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China411
2India179
3South Korea97
4Brazil80
5Russian Federation54
6Viet Nam44
7United States40
8Ukraine35
9Indonesia28
10Pakistan21

Monday, June 27, 2011

Botnet Statistics [2011-06-26]

I can not connect to my fake open relay, so its data are not included today.

detection period: 2011-06-26 00:00-23:59 UTC
total number of suspected botnet IPs: 787
number of botnet IPs notified to network operators: 565
number of blocked spams: 0
recipient count of blocked spams: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD95
2UNICOM-BJ65
3CRTC23
4KORNET-KR20
5CHINANET-HB13
6CHINANET-ZJ12
7CHINANET-JS12
8CHINANET-SH10
9BSNLNET10
10UNICOM-SD8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China349
2Russian Federation43
3South Korea40
4United States31
5India27
6Brazil23
7Indonesia21
8Ukraine18
9Taiwan15
10Viet Nam12

Sunday, June 26, 2011

Botnet Statistics [2011-06-25]

detection period: 2011-06-25 00:00-23:59 UTC
total number of suspected botnet IPs: 1874
number of botnet IPs notified to network operators: 1302
number of blocked spams: 4762
recipient count of blocked spams: 124588

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET288
2BSNLNET105
3CHINANET-GD94
4KORNET-KR88
5UNICOM-BJ33
6UKRTELNET26
7BHARTI-IN26
8TATACOMM-IN23
9CHINANET-JS23
10VNPT-VNNIC-VN22

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China354
2Taiwan307
3India270
4South Korea146
5Russian Federation116
6Brazil67
7Ukraine66
8Viet Nam35
9Indonesia28
10Poland26

Saturday, June 25, 2011

Botnet Statistics [2011-06-24]

detection period: 2011-06-24 00:00-23:59 UTC
total number of suspected botnet IPs: 2023
number of botnet IPs notified to network operators: 1406
number of blocked spams: 66336
recipient count of blocked spams: 2309513

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET200
2CHINANET-GD109
3BSNLNET72
4CHINANET-JS60
5KORNET-KR36
6TELKOMNET34
7UNICOM-BJ29
8RCOM24
9UNICOM-SD23
10000.065.376/0002-6522

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China511
2Taiwan220
3India183
4Russian Federation135
5Brazil133
6South Korea78
7Indonesia69
8Ukraine59
9United States46
10Viet Nam30

Friday, June 24, 2011

Botnet Statistics [2011-06-23]

detection period: 2011-06-23 00:00-23:59 UTC
total number of suspected botnet IPs: 2171
number of botnet IPs notified to network operators: 1545
number of blocked spams: 86051
recipient count of blocked spams: 3003914

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET168
2CHINANET-GD121
3BSNLNET79
4VNPT-VNNIC-VN69
5TELKOMNET54
6CHINANET-JS42
7UNICOM-BJ36
8PTCL30
9BHARTI-IN28
10CTTNET25

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China514
2India226
3Taiwan186
4Russian Federation142
5Indonesia125
6Brazil122
7Viet Nam100
8United States59
9Ukraine57
10South Korea57

Thursday, June 23, 2011

Botnet Statistics [2011-06-22]

My fake open relay is back online.

detection period: 2011-06-22 00:00-23:59 UTC
total number of suspected botnet IPs: 1797
number of botnet IPs notified to network operators: 1158
number of blocked spams: 49135
recipient count of blocked spams: 1714734

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD112
2BSNLNET69
3UNICOM-BJ50
4HINET-NET47
5CHINANET-JS43
6TELKOMNET31
7PTCL31
8CTTNET28
9CHINANET-HB25
10VNPT-VNNIC-VN22

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China494
2India172
3Russian Federation124
4Brazil117
5Indonesia67
6Taiwan61
7South Korea59
8Ukraine56
9United States51
10Pakistan41

Wednesday, June 22, 2011

Botnet Statistics [2011-06-21]

No data from my fake open relay today.

detection period: 2011-06-21 00:00-23:59 UTC
total number of suspected botnet IPs: 1504
number of botnet IPs notified to network operators: 971
number of blocked spams: 0
recipient count of blocked spams: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BSNLNET77
2CHINANET-GD76
3VNPT-VNNIC-VN68
4KORNET-KR40
5UNICOM-BJ36
6CHINANET-JS34
7PTCL31
8TELKOMNET28
9CRTC23
10BY-BELPAK-2009121021

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China303
2India185
3Russian Federation102
4Viet Nam95
5South Korea82
6Indonesia66
7Brazil64
8Ukraine44
9Pakistan39
10United States28

Tuesday, June 21, 2011

Botnet Statistics [2011-06-20]

Something happened to my fake open relay yesterday, so there is no data collected from it today.

detection period: 2011-06-20 00:00-23:59 UTC
total number of suspected botnet IPs: 1132
number of botnet IPs notified to network operators: 772
number of blocked spams: 0
recipient count of blocked spams: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD84
2BSNLNET76
3VNPT-VNNIC-VN41
4KORNET-KR36
5PTCL25
6UNICOM-BJ24
7TELKOMNET24
8CRTC22
9RCOM17
10UKRTELNET15

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China275
2India164
3Brazil77
4South Korea74
5Russian Federation65
6Viet Nam58
7Indonesia55
8Ukraine35
9Pakistan33
10United States27

Monday, June 20, 2011

Botnet Statistics [2011-06-19]

detection period: 2011-06-19 00:00-23:59 UTC
total number of suspected botnet IPs: 1851
number of botnet IPs notified to network operators: 1328
number of blocked spams: 25976
recipient count of blocked spams: 857288

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET232
2CHINANET-GD98
3BSNLNET54
4VNPT-VNNIC-VN42
5CHINANET-JS36
6KORNET-KR27
7TELKOMNET25
8CRTC25
9002.558.134/0001-5825
10000.065.376/0002-6524

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China453
2Taiwan249
3Brazil138
4India125
5Russian Federation101
6South Korea67
7Viet Nam62
8Ukraine54
9United States49
10Indonesia40

Sunday, June 19, 2011

Botnet Statistics [2011-06-18]

detection period: 2011-06-18 00:00-23:59 UTC
total number of suspected botnet IPs: 3548
number of botnet IPs notified to network operators: 2631
number of blocked spams: 33554
recipient count of blocked spams: 1094854

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BSNLNET593
2HINET-NET315
3CHINANET-GD122
4KORNET-KR92
5RCOM90
6TATACOMM-IN75
7UKRTELNET72
8000.065.376/0002-6548
9HATHWAY-NET46
10002.558.134/0001-5846

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1India979
2China418
3Taiwan357
4Brazil233
5Russian Federation215
6South Korea168
7Ukraine149
8Argentina90
9Viet Nam66
10Colombia45

Saturday, June 18, 2011

Botnet Statistics [2011-06-17]

detection period: 2011-06-17 00:00-23:59 UTC
total number of suspected botnet IPs: 3345
number of botnet IPs notified to network operators: 2589
number of blocked spams: 31752
recipient count of blocked spams: 1052857

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BSNLNET565
2HINET-NET293
3CHINANET-GD132
4UKRTELNET79
5RCOM76
6TATACOMM-IN74
7KORNET-KR62
8BY-BELPAK-2009121052
9HATHWAY-NET43
10002.558.134/0001-5843

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1India893
2China469
3Taiwan326
4Russian Federation259
5Brazil238
6Ukraine157
7South Korea91
8Argentina82
9Indonesia65
10Belarus60

Friday, June 17, 2011

Botnet Statistics [2011-06-16]

detection period: 2011-06-16 00:00-23:59 UTC
total number of suspected botnet IPs: 2813
number of botnet IPs notified to network operators: 2001
number of blocked spams: 81340
recipient count of blocked spams: 2824716

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BSNLNET262
2HINET-NET191
3CHINANET-GD128
4VNPT-VNNIC-VN60
5TELKOMNET59
6RCOM52
7002.558.134/0001-5846
8UKRTELNET43
9000.065.376/0002-6536
10TATACOMM-IN32

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China532
2India498
3Brazil226
4Taiwan207
5Russian Federation200
6Indonesia110
7Ukraine102
8Viet Nam99
9South Korea80
10Argentina66

Thursday, June 16, 2011

Botnet Statistics [2011-06-15]

detection period: 2011-06-15 00:00-23:59 UTC
total number of suspected botnet IPs: 2682
number of botnet IPs notified to network operators: 1811
number of blocked spams: 91916
recipient count of blocked spams: 3207803

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BSNLNET180
2HINET-NET169
3CHINANET-GD119
4VNPT-VNNIC-VN70
5PTCL66
6RCOM51
7TELKOMNET46
8TATACOMM-IN41
9002.558.134/0001-5838
10KORNET-KR35

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China480
2India407
3Brazil188
4Taiwan181
5Russian Federation170
6Viet Nam126
7Indonesia99
8Ukraine85
9Pakistan83
10South Korea79

Wednesday, June 15, 2011

Botnet Statistics [2011-06-14]

detection period: 2011-06-14 00:00-23:59 UTC
total number of suspected botnet IPs: 2820
number of botnet IPs notified to network operators: 1951
number of blocked spams: 94359
recipient count of blocked spams: 3280705

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BSNLNET239
2CHINANET-GD129
3HINET-NET99
4VNPT-VNNIC-VN67
5RCOM66
6KORNET-KR48
7UKRTELNET42
8TATACOMM-IN38
9000.065.376/0002-6535
10TELKOMNET33

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China570
2India491
3Russian Federation224
4Brazil200
5Taiwan123
6Viet Nam106
7Ukraine102
8South Korea94
9Indonesia74
10United States48

Tuesday, June 14, 2011

Botnet Statistics [2011-06-13]

detection period: 2011-06-13 00:00-23:59 UTC
total number of suspected botnet IPs: 2421
number of botnet IPs notified to network operators: 1758
number of blocked spams: 95028
recipient count of blocked spams: 3309594

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET164
2BSNLNET164
3CHINANET-GD124
4CHINANET-JS46
5RCOM43
6000.065.376/0002-6540
7CRTC38
8KORNET-KR37
9UNICOM-BJ34
10VNPT-VNNIC-VN31

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China584
2India342
3Brazil204
4Taiwan182
5Russian Federation152
6South Korea79
7Ukraine75
8Viet Nam61
9Argentina55
10United States44

Monday, June 13, 2011

Botnet Statistics [2011-06-12]

detection period: 2011-06-12 00:00-23:59 UTC
total number of suspected botnet IPs: 2255
number of botnet IPs notified to network operators: 1567
number of blocked spams: 94168
recipient count of blocked spams: 3280731

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET184
2BSNLNET101
3CHINANET-GD94
4VNPT-VNNIC-VN57
5CHINANET-JS48
6KORNET-KR37
7CRTC33
8CHINANET-SH31
9UKRTELNET28
10RCOM27

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China558
2Taiwan201
3India182
4Brazil160
5Russian Federation134
6South Korea102
7Viet Nam97
8Ukraine80
9Argentina62
10United States57

Sunday, June 12, 2011

Botnet Statistics [2011-06-11]

detection period: 2011-06-11 00:00-23:59 UTC
total number of suspected botnet IPs: 1749
number of botnet IPs notified to network operators: 1186
number of blocked spams: 23661
recipient count of blocked spams: 790406

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET119
2CHINANET-GD102
3CHINANET-JS45
4BSNLNET41
5KORNET-KR40
6CRTC30
7UNICOM-BJ26
8VNPT-VNNIC-VN23
9000.065.376/0002-6522
10UKRTELNET19

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China436
2Taiwan140
3Brazil121
4India116
5Russian Federation110
6South Korea86
7Ukraine56
8United States50
9Indonesia44
10Viet Nam40

Saturday, June 11, 2011

Botnet Statistics [2011-06-10]

detection period: 2011-06-10 00:00-23:59 UTC
total number of suspected botnet IPs: 1827
number of botnet IPs notified to network operators: 1184
number of blocked spams: 70864
recipient count of blocked spams: 2470497

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD90
2BSNLNET52
3CHINANET-JS40
4KORNET-KR37
5VNPT-VNNIC-VN33
6002.558.134/0001-5833
7CRTC30
8002.558.157/0001-6226
9UNICOM-BJ22
10RCOM22

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China450
2Brazil151
3India145
4Russian Federation124
5South Korea97
6Ukraine67
7Viet Nam61
8United States53
9Indonesia36
10Kazakhstan29

Friday, June 10, 2011

Botnet Statistics [2011-06-09]

detection period: 2011-06-09 00:00-23:59 UTC
total number of suspected botnet IPs: 1666
number of botnet IPs notified to network operators: 1108
number of blocked spams: 97063
recipient count of blocked spams: 3385514

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD110
2BSNLNET54
3CRTC43
4KORNET-KR32
5CHINANET-JS31
6000.065.376/0002-6527
7UKRTELNET24
8UNICOM-SD21
9002.558.157/0001-6221
10TELKOMNET20

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China478
2India146
3Brazil138
4Russian Federation116
5Ukraine74
6South Korea69
7United States54
8Indonesia46
9Viet Nam36
10Taiwan35

Thursday, June 9, 2011

Botnet Statistics [2011-06-08]

detection period: 2011-06-08 00:00-23:59 UTC
total number of suspected botnet IPs: 2105
number of botnet IPs notified to network operators: 1494
number of blocked spams: 96177
recipient count of blocked spams: 3257025

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD140
2HINET-NET104
3BSNLNET43
4KORNET-KR40
5CHINANET-JS40
6CRTC37
7UNICOM-BJ29
8CTTNET26
9CHINANET-SH25
10UNICOM-SD24

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China634
2Russian Federation166
3Brazil145
4India126
5Taiwan121
6South Korea88
7Ukraine76
8United States73
9Viet Nam42
10Indonesia36

Wednesday, June 8, 2011

Botnet Statistics [2011-06-07]

detection period: 2011-06-07 00:00-23:59 UTC
total number of suspected botnet IPs: 1981
number of botnet IPs notified to network operators: 1995
number of blocked spams: 95707
recipient count of blocked spams: 3274111

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET191
2CHINANET-GD127
3BSNLNET55
4KORNET-KR45
5CRTC39
6CHINANET-JS36
7CTTNET33
8VNPT-VNNIC-VN29
9002.558.134/0001-5820
10UNICOM-SD19

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China557
2Taiwan206
3Brazil134
4India127
5Russian Federation115
6South Korea81
7Ukraine65
8United States64
9Viet Nam46
10Indonesia40

Tuesday, June 7, 2011

Botnet Statistics [2011-06-06]

detection period: 2011-06-06 00:00-23:59 UTC
total number of suspected botnet IPs: 3425
number of botnet IPs notified to network operators: 2264
number of blocked spams: 38544
recipient count of blocked spams: 1157264

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET232
2BSNLNET138
3KORNET-KR137
4CHINANET-GD134
5VNPT-VNNIC-VN69
6UKRTELNET54
7BY-BELPAK-2009121046
8PTCL41
9CRTC39
10BHARTI-IN37

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China543
2Russian Federation322
3India311
4Taiwan263
5South Korea244
6Brazil200
7Ukraine165
8Viet Nam101
9United States68
10Argentina68

Monday, June 6, 2011

Botnet Statistics [2011-06-05]

detection period: 2011-06-05 00:00-23:59 UTC
total number of suspected botnet IPs: 2706
number of botnet IPs notified to network operators: 1929
number of blocked spams: 28652
recipient count of blocked spams: 802656

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET266
2BSNLNET148
3CHINANET-GD131
4KORNET-KR61
5UKRTELNET45
6RCOM38
7CHINANET-JS38
8CRTC36
9BY-BELPAK-2009121028
10CTTNET26

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China509
2India304
3Taiwan278
4Russian Federation266
5Brazil154
6Ukraine151
7South Korea113
8Argentina64
9United States59
10Kazakhstan48

Sunday, June 5, 2011

Botnet Statistics [2011-06-04]

detection period: 2011-06-04 00:00-23:59 UTC
total number of suspected botnet IPs: 2873
number of botnet IPs notified to network operators: 2176
number of blocked spams: 47837
recipient count of blocked spams: 1510319

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BSNLNET447
2HINET-NET273
3CHINANET-GD100
4RCOM78
5KORNET-KR71
6TATACOMM-IN64
7UKRTELNET44
8CHINANET-JS41
9CTTNET40
10002.558.134/0001-5836

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1India732
2China469
3Taiwan298
4Russian Federation223
5Brazil178
6Ukraine113
7South Korea104
8Argentina72
9Kazakhstan49
10United States45

Saturday, June 4, 2011

Botnet Statistics for May 2011

My way of counting numbers seems to screw the statistics somewhat.

I use both fake open relay and greylisting to detect botnets and compile their IP list. But only fake open relay has non-zero blocked spams. The reason: acting as open relay, it has to accept everything in its SMTP port. My greylisting never accept spam. It either rejects the mail temporarily, or if the sender retries, rejects the recipients permanently. I only count spam accepted as "blocked spam."

This might cause some discrepancies between different lists. If a certain country is mostly detected by greylisting, it might be high on the country list, but no so high on lists of both blocked spams and blocked recipients. I did not forsee this problem when I started incorporating greylisting into my statistics.

I do not intend to change my way of counting for the time being.

detection period: 2011-05-01 00:00 - 2011-05-31 23:59 UTC
total number of suspected botnet IPs: 46494
number of blocked spams: 2036931
recipient count of blocked spams: 63221233

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China15696
2Taiwan6309
3India4851
4Russian Federation2235
5Brazil1905
6South Korea1638
7Ukraine1073
8Indonesia988
9Viet Nam943
10Argentina774
11Pakistan625
12United States616
13Poland516
14Belarus439
15Colombia391
16Romania350
17Kazakhstan335
18Chile317
19Spain308
20Serbia296
21Philippines256
22Saudi Arabia253
23Germany220
24Peru216
25Morocco195

The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:

RankCountry# of blocked spams
1China556899
2Taiwan243573
3Brazil193970
4Russian Federation92351
5United States91660
6India86549
7France67563
8Colombia62517
9Indonesia34684
10Germany34366
11Thailand31767
12Mexico31042
13Ukraine30977
14Poland25883
15South Korea24982
16Iran23624
17Argentina23285
18Italy19292
19Philippines18619
20Kazakhstan16441
21Canada16370
22Singapore16190
23Chile16117
24Viet Nam12880
25Hong Kong12554

The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:

Botnet Statistics [2011-06-03]

detection period: 2011-06-03 00:00-23:59 UTC
total number of suspected botnet IPs: 3052
number of botnet IPs notified to network operators: 2265
number of blocked spams: 43335
recipient count of blocked spams: 1294022

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BSNLNET402
2HINET-NET309
3CHINANET-GD105
4KORNET-KR91
5RCOM57
6UKRTELNET55
7TATACOMM-IN53
8BY-BELPAK-2009121046
9AR-TEAR7-LACNIC45
10002.558.134/0001-5843

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1India680
2China479
3Taiwan328
4Russian Federation235
5Brazil209
6South Korea138
7Ukraine123
8Argentina85
9Belarus55
10United States44

Friday, June 3, 2011

Botnet Statistics [2011-06-02]

detection period: 2011-06-02 00:00-23:59 UTC
total number of suspected botnet IPs: 2810
number of botnet IPs notified to network operators: 2154
number of blocked spams: 42207
recipient count of blocked spams: 1282514

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BSNLNET509
2HINET-NET222
3CHINANET-GD117
4RCOM74
5TATACOMM-IN60
6UKRTELNET57
7KORNET-KR54
8HATHWAY-NET47
9002.558.134/0001-5839
10UNICOM-BJ38

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1India799
2China495
3Taiwan234
4Russian Federation211
5Brazil207
6Ukraine103
7South Korea93
8Argentina65
9Kazakhstan46
10Belarus41

Thursday, June 2, 2011

Botnet Statistics [2011-06-01]

detection period: 2011-06-01 00:00-23:59 UTC
total number of suspected botnet IPs: 3235
number of botnet IPs notified to network operators: 2375
number of blocked spams: 42396
recipient count of blocked spams: 1210242

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BSNLNET409
2HINET-NET290
3KORNET-KR125
4CHINANET-GD120
5RCOM82
6UKRTELNET55
7TATACOMM-IN52
8CRTC42
9002.558.134/0001-5841
10VNPT-VNNIC-VN37

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1India704
2China510
3Taiwan318
4Russian Federation271
5Brazil217
6South Korea196
7Ukraine139
8Argentina69
9Indonesia52
10United States51

Wednesday, June 1, 2011

Botnet Statistics [2011-05-31]

detection period: 2011-05-31 00:00-23:59 UTC
total number of suspected botnet IPs: 2958
number of botnet IPs notified to network operators: 2158
number of blocked spams: 46481
recipient count of blocked spams: 1378429

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BSNLNET382
2HINET-NET307
3CHINANET-GD124
4KORNET-KR108
5RCOM89
6TATACOMM-IN45
7AR-TEAR7-LACNIC43
8VNPT-VNNIC-VN40
9UKRTELNET40
10BY-BELPAK-2009121037

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1India674
2China443
3Taiwan319
4Russian Federation241
5Brazil193
6South Korea161
7Ukraine90
8Argentina79
9United States69
10Viet Nam59