Custom Search

Wednesday, January 18, 2012

Botnet Statistics for December 2011

I forgot to save some log files from Dec 18, 2011 to Jan 04, 2012, so this month's statistics is kind of incomplete. Mistakes do happen. After all, I am only human.

detection period: 2011-12-01 00:00 - 2011-12-31 23:59 UTC
total number of suspected botnet IPs: 29628
number of blocked spams: 1609196
recipient count of blocked spams: 55690089

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan6619
2China6216
3India2434
4Indonesia1476
5Viet Nam1262
6Russian Federation1108
7Brazil792
8South Korea770
9United States764
10Pakistan530
11Ukraine452
12Poland452
13Argentina396
14Romania371
15Belarus311
16Spain257
17Chile249
18Mexico229
19Serbia227
20Kazakhstan209
21Colombia207
22Germany202
23Saudi Arabia163
24European Union160
25Italy158

The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:

RankCountry# of blocked spams
1China420426
2Brazil180973
3United States159506
4Taiwan68411
5Russian Federation64009
6France48081
7Indonesia46467
8India43579
9Germany39113
10Ukraine37006
11Canada32144
12Poland26639
13Thailand23328
14Czech Republic22464
15South Korea22278
16Hong Kong19588
17United Kingdom18291
18Viet Nam18263
19Chile15286
20European Union15157
21Iran14723
22Mexico14073
23Netherlands12816
24Italy11775
25Ecuador11342

The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:

RankCountryrecipient count of blocked spams
1China14404351
2Brazil6324544
3United States5573238
4Russian Federation2235844
5Taiwan2134412
6France1682933
7Indonesia1623755
8India1522083
9Germany1367085
10Ukraine1293330
11Canada1122564
12Poland930794
13Thailand815237
14Czech Republic786383
15South Korea778743
16Hong Kong685167
17United Kingdom639577
18Viet Nam637016
19Chile533122
20European Union529439
21Iran515128
22Mexico491993
23Netherlands448101
24Italy409747
25Ecuador396945

The top 25 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET6436
2CHINANET-GD1367
3CTTNET1355
4BSNLNET976
5VNPT-VNNIC-VN705
6PTCL443
7CRTC434
8TELKOMNET378
9KORNET-KR357
10CHINANET-JS356
11CHINANET-FJ336
12RCOM232
13BY-BELPAK-20091210232
14UNICOM-BJ210
15BHARTI-IN209
16AR-TEAR7-LACNIC179
17TATACOMM-IN157
18MTNLISP136
19RO-ARTELECOM-20070815126
20000.065.376/0002-65125
21CHINANET-ZJ-WZ124
22002.558.134/0001-58121
23CHINANET-SH107
24002.558.157/0001-62106
25VIETEL-VN104

The top 25 networks (as found in WHOIS), ordered by number of blocked spams are:

RankNetwork# of blocked spams
1HINET-NET59555
2CHINANET-JS39624
3033.530.486/0001-2938681
4000.065.376/0002-6536925
5CHINANET-ZJ35617
6003.420.926/0002-0534643
7CHINANET-GX31877
8CHINANET-GD25988
9OVH24529
10UNICOM-JL21222
11CHINANET-SN15930
12002.558.157/0001-6215418
13CHINANET-GS14822
14UNICOM-LN14154
15CMNET13732
16CHINANET-ZJ-WZ13035
17UNICOM-SD12963
18SCTV-VN12813
19CHINANET-AH11382
20DACONET-CDT-NET10450
21TELKOMNET10164
22XOXO-BLK-149077
23MX-USCV4-LACNIC8876
24IWEB-BLK-077970
25VPLSNET7914

The top 25 networks (as found in WHOIS), ordered by recipient count of blocked spams are:

RankNetworkrecipient count of blocked spams
1HINET-NET1824237
2CHINANET-JS1386299
3033.530.486/0001-291353167
4000.065.376/0002-651291215
5003.420.926/0002-051209803
6CHINANET-ZJ1206943
7CHINANET-GX1114920
8CHINANET-GD909451
9OVH858542
10UNICOM-JL742699
11CHINANET-SN556433
12002.558.157/0001-62539259
13CHINANET-GS518764
14UNICOM-LN495418
15CMNET480854
16UNICOM-SD453265
17SCTV-VN447554
18CHINANET-AH397552
19DACONET-CDT-NET365992
20TELKOMNET355528
21XOXO-BLK-14317503
22MX-USCV4-LACNIC310501
23VPLSNET277465
24IWEB-BLK-07277459
25002.558.134/0001-58275022

No comments:

Post a Comment