03/16/2010

More than 300 Botnet control and command servers on Belgian networks

The Source

These reports are based off of all the active and inactive Command and Control (C&C) points that we have tracked and are currently tracking. The columns are defined as follows:

  • Number - The total number of C&C's hosted within that geographical area
  • Closed - What percent of the C&C's that are now inactive
  • CC DDOS - The number of DDOS attacks issued from that C&C's within that geographical area
  • CC Scans - The number of scans into other networks the C&C's issues from that geographical area
  • CC CHosts - The number of successful compromises completed by that C&C's within that geographical area
  • TGT DDOS - The number of DDOS attacks that were targeted to this geographical area
  • TGT Scans - The number of scans that were targeted to this geographical area
  • TGT CHosts - The number of hosts compromised within this geographical area
GeoLoc Number Closed CC DDoS CC Scans CC CHosts TGT DDoS TGT Scans TGT CHosts URLs
US701257%348583229039612618287217136532022591017257064
NL194629%6079883859531199232497894494423647
DE150363%111513627502412780776321398476815341953393
CA136739%604228038530336205571239277109641809400
UK122037%1098673095636855231346662534711622445
SE121313%19045950482148352197536426750680
FR64237%695812150411841570219660546805175165
CN50384%32490242562609216652752972434248119698473198
HU4859%15161138579976215648920581
FI4663%2700740115123137619842
NO44810%18016704604994489817789
KR40980%869581275141636421345021112391176560
BE3757%1747413221298551444970381612202
JP32357%19843700618283130830482031843376058
TR25064%9614280585484673645835630368193

We should keep also in mind that China (CN) is a dictatorship so closing down a server is quite easy if they want to do it.

Japan has also a higher closing down percentage but that is because they have a CERT that is only doing that.

Belgium has a very low closing down percentage for botnet command and control servers.

The result is that we have DDOS attacks, infection scans and other malware traffic on our networks and going to other networks. As long as nobody sues you for damages, you can take it lightly, but the very low number of closed C&C may one day be used against you as neglicence.

10:54 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment