Custom Search

Saturday, April 6, 2013

Botnet Statistics for March 2013

The number of infected computers detected went from 65K in February to 114K in March, an increase of 75%. It seems to me that bot herders have the upper hand now.

detection period: 2013-03-01 00:00 - 2013-03-31 23:59 UTC
total number of suspected botnet IPs: 114436
number of blocked spams: 2526693
recipient count of blocked spams: 91790675

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China46623
2Belarus18180
3Kazakhstan6141
4United States4304
5Ukraine4030
6Viet Nam3197
7Taiwan2508
8Russian Federation2113
9India1872
10Argentina1742
11Poland1726
12Spain1693
13Peru1322
14Colombia1249
15Mexico1060
16Iran1044
17Italy939
18Brazil896
19Germany871
20United Kingdom688
21Saudi Arabia681
22Romania664
23Chile632
24Turkey601
25Canada559

The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:

RankCountry# of blocked spams
1China424656
2United States378148
3Brazil313538
4Russian Federation185284
5United Kingdom85273
6South Korea76228
7India69159
8Taiwan61442
9France60860
10Ukraine60064
11Iran49243
12Spain47505
13Germany46499
14Indonesia43788
15Colombia40143
16Argentina39196
17Thailand35764
18Peru26969
19Poland26597
20Romania21003
21Mexico19807
22Netherlands18880
23Chile18419
24Kuwait17622
25Canada16287

The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:

RankCountryrecipient count of blocked spams
1China14248262
2United States14006973
3Brazil11608477
4Russian Federation6871532
5United Kingdom3027674
6South Korea2826552
7India2566409
8France2259341
9Taiwan2232037
10Ukraine2218316
11Iran1823643
12Spain1761114
13Indonesia1620599
14Germany1563631
15Colombia1490878
16Argentina1451724
17Thailand1324332
18Peru999740
19Poland986583
20Romania778505
21Mexico734420
22Netherlands701652
23Chile685713
24Kuwait651650
25Canada604027

The top 25 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BY-BELPAK-200912109649
2CHINANET-HB9552
3CHINANET-JS5721
4CRTC4649
5CHINANET-HE4182
6CHINANET-GD3405
7BY-BELPAK-201203303177
8CTTNET3005
9UNICOM-LN2287
10BY-BELPAK-200802132186
11VNPT-VNNIC-VN1963
12HINET-NET1936
13BY-BELPAK-201201061788
14KZ-KAZAKTELECOM-200809231536
15KZ-KAZAKTELECOM-200911261307
16UNICOM-SD1051
17CHINANET-FJ1016
18UNICOM-GD748
19UNICOM-HL725
20AR-TEAR7-LACNIC725
21UNICOM-HE604
22GWBN-WUHAN552
23UNICOM-NM533
24PE-TPSA-LACNIC529
25BSNLNET509

The top 25 networks (as found in WHOIS), ordered by number of blocked spams are:

RankNetwork# of blocked spams
1MSFT-EP85848
2HINET-NET52381
3002.558.157/0001-6248386
4003.420.926/0002-0547099
5UNICOM-LN44854
6KORNET-KR36744
7033.530.486/0001-2932500
8UNICOM-GD28510
9CHINANET-GD28046
10004.027.547/0001-3124763
11BHARTI-IN24588
12CMNET24285
13002.558.134/0001-5824166
14CO-ACSA-LACNIC22464
15HICHINA20726
16ES-ONO-2004041519941
17CHINANET-SH19256
18GBLX-11C18780
19JIAOJIANG-DONGGANG-LTD18523
20GULFNET-MOI17443
21CCS-DGI17217
22UNICOM-HE14519
23VAUGHAN-LIMITED-24684-LAN13402
24FR-OVH-2006092013265
25AR-IYTS-LACNIC13022

The top 25 networks (as found in WHOIS), ordered by recipient count of blocked spams are:

RankNetworkrecipient count of blocked spams
1MSFT-EP3188883
2HINET-NET1894649
3002.558.157/0001-621792222
4003.420.926/0002-051748333
5UNICOM-LN1662466
6KORNET-KR1363536
7033.530.486/0001-291201565
8CHINANET-GD1016762
9004.027.547/0001-31916021
10BHARTI-IN915593
11CMNET899295
12002.558.134/0001-58895372
13CO-ACSA-LACNIC837041
14HICHINA768611
15ES-ONO-20040415739266
16CHINANET-SH714041
17GBLX-11C697018
18JIAOJIANG-DONGGANG-LTD687221
19GULFNET-MOI645168
20CCS-DGI637671
21UNICOM-HE538106
22VAUGHAN-LIMITED-24684-LAN495488
23FR-OVH-20060920493198
24AR-IYTS-LACNIC483273
25IR-DCC-20010403469601

No comments:

Post a Comment