Most Prolific BotNet Command and Control Servers and Filters
Tue May 15 08:30:44 2012
10 Day Filter Set 30 Day Filter Set
| Priority 100 | TCP Ports 80 80 83 | Filter deny ip host 213.155.14.161 any log ! 887 infects 01/04/12 to 05/14/12 - | ISP ossadchy - osadchiy yuriy |
| Clients 887 | ukraine |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 51 | TCP Ports 65520 | Filter deny ip host 83.133.119.197 any log ! 50 infects 01/06/12 to 05/12/12 greatnet.de | ISP lncde-greatnet-newmedia |
| Clients 50 | germany |
Activity | Domain greatnet.de |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 13 | TCP Ports 65520 | Filter deny ip host 114.112.255.81 any log ! 13 infects 02/20/12 to 05/11/12 - | ISP 22d no.1 building |
| Clients 13 | china |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 5 | TCP Ports 65520 | Filter deny ip host 94.63.149.150 any log ! 5 infects 01/06/12 to 01/09/12 ipv4ilink.net | ISP evolva telecom s.r.l |
| Clients 5 | romania |
Activity | Domain ipv4ilink.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 4 | TCP Ports 3921 | Filter deny ip host 182.72.4.108 any log ! 4 infects 04/30/12 to 04/30/12 - | ISP - |
| Clients 4 | - |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 4 | TCP Ports 6900 | Filter deny ip host 190.96.181.218 any log ! 4 infects 01/18/12 to 01/18/12 - | ISP telebucaramanga s.a. e.s.p |
| Clients 4 | colombia |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 2 | TCP Ports 3921 | Filter deny ip host 66.41.211.152 any log ! 2 infects 03/16/12 to 04/08/12 comcast.net | ISP comcast cable communications holdings inc |
| Clients 2 | united states |
Activity | Domain comcast.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 65520 | Filter deny ip host 91.226.212.159 any log ! 1 infects 02/07/12 to 02/07/12 nacksystem.net | ISP eu-zz |
| Clients 1 | united kingdom |
Activity | Domain nacksystem.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 65520 | Filter deny ip host 91.226.212.164 any log ! 1 infects 02/12/12 to 02/12/12 nacksystem.net | ISP eu-zz |
| Clients 1 | united kingdom |
Activity | Domain nacksystem.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 445 | Filter deny ip host 66.252.13.152 any log ! 1 infects 03/25/12 to 03/25/12 louisianadynamics.com | ISP gigenet |
| Clients 1 | united states |
Activity | Domain louisianadynamics.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 65520 91 | Filter deny ip host 94.63.147.131 any log ! 1 infects 02/06/12 to 02/06/12 ipv4ilink.net | ISP evolva telecom s.r.l |
| Clients 1 | romania |
Activity | Domain ipv4ilink.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 65520 | Filter deny ip host 91.217.82.147 any log ! 1 infects 05/11/12 to 05/11/12 nacksystem.net | ISP eu-zz |
| Clients 1 | united kingdom |
Activity | Domain nacksystem.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 80 | Filter deny ip host 69.22.162.40 any log ! 1 infects 04/25/12 to 04/25/12 nlayer.net | ISP nlayer communications inc |
| Clients 1 | united states |
Activity | Domain nlayer.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|


ukraine
germany
china
romania
-
colombia
united states
united kingdom