Custom Search

Monday, July 16, 2012

Botnet Statistics [2012-07-15]

I built another greylisting system yesterday. As data collected from its first day of operation was incomplete, I did not use them.

detection period: 2012-07-15 00:00-23:59 UTC
total number of suspected botnet IPs: 2430
number of botnet IPs notified to network operators: 2187
number of spam blocked: 130677
recipient count of spam blocked: 4113692

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD939
2UNICOM-GD598
3HINET-NET300
4003.420.926/0002-0516
5CHINANET-JS14
6002.558.157/0001-6213
7000.065.376/0002-6512
8TELEHOUSE10
9NETBLK-SOFTLAYER-RIPE-CUST-AR10282-RIPE8
10KORNET-KR8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1638
2Taiwan304
3Brazil88
4Russian Federation62
5United States36
6India21
7Netherlands20
8France18
9South Korea17
10Germany15

No comments:

Post a Comment