Most Prolific BotNet Command and Control Servers and Filters
Fri Nov 6 08:34:01 2009
10 Day Filter Set 30 Day Filter Set
| Priority 100 | TCP Ports 80 80 218 80 114 80 91 | Filter deny ip host 213.219.245.212 any log ! 464 infects 06/09/09 to 11/05/09 eastweb.ru | ISP hosting and colocation services |
| Clients 464 | russian federation |
Activity | Domain eastweb.ru |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 100 | TCP Ports 2081 9890 9890 66 2010 9890 216 | Filter deny ip host 66.252.13.214 any log ! 252 infects 05/10/09 to 11/03/09 louisianadynamics.com | ISP gigenet |
| Clients 252 | united states |
Activity | Domain louisianadynamics.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 72 | TCP Ports 65520 65520 85 65520 218 65520 69 | Filter deny ip host 221.5.74.39 any log ! 70 infects 06/25/09 to 08/17/09 cncnet.net | ISP china unicom guangdong province network |
| Clients 70 | china |
Activity | Domain cncnet.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 71 | TCP Ports 65520 65520 216 65520 85 65520 221 | Filter deny ip host 218.93.205.24 any log ! 69 infects 06/26/09 to 08/14/09 163data.com.cn | ISP chinanet jiangsu province network |
| Clients 69 | china |
Activity | Domain 163data.com.cn |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 65 | TCP Ports 3305 | Filter deny ip host 61.120.62.28 any log ! 63 infects 05/22/09 to 08/22/09 dion.ne.jp | ISP rabby_s inc |
| Clients 63 | japan |
Activity | Domain dion.ne.jp |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 62 | TCP Ports 65520 65520 91 65520 213 | Filter deny ip host 218.93.205.30 any log ! 60 infects 09/09/09 to 11/05/09 163data.com.cn | ISP chinanet jiangsu province network |
| Clients 60 | china |
Activity | Domain 163data.com.cn |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 48 | TCP Ports 3305 | Filter deny ip host 92.240.234.164 any log ! 47 infects 09/07/09 to 11/02/09 lightstorm.sk | ISP lightstorm communications s.r.o |
| Clients 47 | slovakia |
Activity | Domain lightstorm.sk |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 48 | TCP Ports 65520 65520 218 | Filter deny ip host 91.212.220.75 any log ! 47 infects 09/11/09 to 10/30/09 - | ISP group vertical ltd |
| Clients 47 | russian federation |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 35 | TCP Ports 65520 121 65520 69 | Filter deny ip host 114.80.101.21 any log ! 34 infects 05/30/09 to 06/25/09 online.sh.cn | ISP chinanet shanghai province network |
| Clients 34 | china |
Activity | Domain online.sh.cn |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 32 | TCP Ports 65520 65520 213 | Filter deny ip host 121.12.116.142 any log ! 31 infects 05/13/09 to 06/25/09 163data.com.cn | ISP chinanet guangdong province network |
| Clients 31 | china |
Activity | Domain 163data.com.cn |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 30 | TCP Ports 16667 | Filter deny ip host 66.252.13.212 any log ! 29 infects 05/22/09 to 11/03/09 louisianadynamics.com | ISP gigenet |
| Clients 29 | united states |
Activity | Domain louisianadynamics.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 22 | TCP Ports 7000 | Filter deny ip host 87.118.98.185 any log ! 22 infects 09/01/09 to 09/04/09 keymachine.de | ISP keyweb ag ip network |
| Clients 22 | germany |
Activity | Domain keymachine.de |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 21 | TCP Ports 8080 72 10324 10324 72 10324 83 | Filter deny ip host 67.43.236.66 any log ! 21 infects 06/09/09 to 10/02/09 - | ISP nader dara |
| Clients 21 | lebanon |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 18 | TCP Ports 6669 | Filter deny ip host 89.138.22.15 any log ! 18 infects 07/09/09 to 07/09/09 netvision.net.il | ISP bb-hfa |
| Clients 18 | israel |
Activity | Domain netvision.net.il |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 17 | TCP Ports 6900 | Filter deny ip host 78.155.216.238 any log ! 17 infects 09/29/09 to 09/30/09 - | ISP mostelecom-customer |
| Clients 17 | russian federation |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 15 | TCP Ports 10324 | Filter deny ip host 67.43.236.67 any log ! 15 infects 07/23/09 to 09/19/09 - | ISP nader dara |
| Clients 15 | lebanon |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 13 | TCP Ports 6669 | Filter deny ip host 190.12.5.5 any log ! 13 infects 07/11/09 to 07/12/09 corp-190-12-4-10-cue.puntonet.ec | ISP puntonet s.a |
| Clients 13 | ecuador |
Activity | Domain corp-190-12-4-10-cue.puntonet.ec |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 13 | TCP Ports 80 | Filter deny ip host 82.98.86.170 any log ! 13 infects 06/11/09 to 10/31/09 fhe3rz.net | ISP sedo domain parking |
| Clients 13 | germany |
Activity | Domain fhe3rz.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 11 | TCP Ports 8080 8080 67 | Filter deny ip host 72.10.172.211 any log ! 11 infects 06/20/09 to 10/16/09 gtcomm.net | ISP globotech communications |
| Clients 11 | canada |
Activity | Domain gtcomm.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 10 | TCP Ports 65520 65520 91 | Filter deny ip host 91.121.221.157 any log ! 10 infects 08/22/09 to 09/05/09 - | ISP fr-ovh |
| Clients 10 | france |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 10 | TCP Ports 5190 67 6556 5190 72 | Filter deny ip host 83.68.16.6 any log ! 10 infects 06/17/09 to 09/19/09 xs4all.nl | ISP xs4all internet bv |
| Clients 10 | netherlands |
Activity | Domain xs4all.nl |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 10 | TCP Ports 6556 194 | Filter deny ip host 194.109.11.65 any log ! 10 infects 06/21/09 to 10/04/09 xs4all.net | ISP xs4all ppp _30 router subnets |
| Clients 10 | netherlands |
Activity | Domain xs4all.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 8 | TCP Ports 3305 | Filter deny ip host 200.49.145.197 any log ! 8 infects 09/04/09 to 11/02/09 allytech.com | ISP allytech s.a |
| Clients 8 | argentina |
Activity | Domain allytech.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 8 | TCP Ports 65520 91 | Filter deny ip host 91.212.220.156 any log ! 8 infects 08/23/09 to 09/07/09 - | ISP group vertical ltd |
| Clients 8 | russian federation |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 7 | TCP Ports 3305 | Filter deny ip host 211.233.45.253 any log ! 7 infects 09/01/09 to 09/08/09 kidc.net | ISP korea internet data center inc |
| Clients 7 | korea_ republic of |
Activity | Domain kidc.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 5 | TCP Ports 3305 | Filter deny ip host 203.146.251.62 any log ! 5 infects 06/11/09 to 11/03/09 csloxinfo.net | ISP reassign to paidc idc suapha-idc customer |
| Clients 5 | thailand |
Activity | Domain csloxinfo.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 4 | TCP Ports 65520 65520 216 | Filter deny ip host 218.93.205.23 any log ! 4 infects 08/19/09 to 08/20/09 163data.com.cn | ISP chinanet jiangsu province network |
| Clients 4 | china |
Activity | Domain 163data.com.cn |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 3 | TCP Ports 6668 6667 | Filter deny ip host 91.121.83.177 any log ! 3 infects 08/22/09 to 08/22/09 gergosnet.com | ISP ovh sas |
| Clients 3 | france |
Activity | Domain gergosnet.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 2 | TCP Ports 65520 216 | Filter deny ip host 221.5.74.40 any log ! 2 infects 08/18/09 to 08/18/09 cncnet.net | ISP china unicom guangdong province network |
| Clients 2 | china |
Activity | Domain cncnet.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 2 | TCP Ports 13001 12351 | Filter deny ip host 122.160.232.194 any log ! 2 infects 09/13/09 to 10/30/09 122.airtelbroadband.in | ISP abts-dsl-del |
| Clients 2 | india |
Activity | Domain 122.airtelbroadband.in |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 2 | TCP Ports 2345 | Filter deny ip host 82.114.87.50 any log ! 2 infects 08/04/09 to 08/11/09 atk-ks.org | ISP yu-kujtesa |
| Clients 2 | serbia and montenegro |
Activity | Domain atk-ks.org |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 2 | TCP Ports 3305 | Filter deny ip host 210.166.223.51 any log ! 2 infects 07/12/09 to 08/03/09 hitachi-system.co.jp | ISP prox-communicator(prox system design inc.) |
| Clients 2 | japan |
Activity | Domain hitachi-system.co.jp |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 2 | TCP Ports 3305 | Filter deny ip host 217.18.77.190 any log ! 2 infects 08/03/09 to 08/03/09 axoft.nl | ISP qweb |
| Clients 2 | netherlands |
Activity | Domain axoft.nl |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 2 | TCP Ports 65520 | Filter deny ip host 193.104.94.11 any log ! 2 infects 11/05/09 to 11/05/09 ipaper.com | ISP block for pi assignments |
| Clients 2 | united kingdom |
Activity | Domain ipaper.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 2 | TCP Ports 2569 3938 | Filter deny ip host 89.149.227.51 any log ! 2 infects 10/16/09 to 10/17/09 internetserviceteam.com | ISP netdirekt e.k |
| Clients 2 | germany |
Activity | Domain internetserviceteam.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 3305 | Filter deny ip host 212.54.2.171 any log ! 1 infects 10/30/09 to 10/30/09 megabaud.fi | ISP elisa oyj |
| Clients 1 | finland |
Activity | Domain megabaud.fi |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 6669 | Filter deny ip host 93.156.203.49 any log ! 1 infects 07/16/09 to 07/16/09 cm-93-156-61-10.telecable.es | ISP telecable |
| Clients 1 | spain |
Activity | Domain cm-93-156-61-10.telecable.es |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 3305 | Filter deny ip host 62.128.152.250 any log ! 1 infects 08/03/09 to 08/03/09 calnea.com | ISP _ netbenefit dedicated servers sovereign house_ |
| Clients 1 | united kingdom |
Activity | Domain calnea.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 7575 | Filter deny ip host 218.10.16.78 any log ! 1 infects 07/01/09 to 07/01/09 - | ISP china unicom heilongjiang province network |
| Clients 1 | china |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 18067 | Filter deny ip host 123.164.66.62 any log ! 1 infects 06/30/09 to 06/30/09 163data.com.cn | ISP chinanet heilongjiang province network |
| Clients 1 | china |
Activity | Domain 163data.com.cn |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 6667 | Filter deny ip host 38.97.225.135 any log ! 1 infects 10/29/09 to 10/29/09 cogentco.com | ISP psinet inc |
| Clients 1 | united states |
Activity | Domain cogentco.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 3308 | Filter deny ip host 217.30.180.76 any log ! 1 infects 10/15/09 to 10/15/09 nebula.fi | ISP nebula oy. web hosting pri-dns and streaming |
| Clients 1 | finland |
Activity | Domain nebula.fi |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 5555 | Filter deny ip host 200.204.157.111 any log ! 1 infects 07/11/09 to 07/11/09 sterlingstudents.net | ISP comite gestor da internet no brasil |
| Clients 1 | brazil |
Activity | Domain sterlingstudents.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 80 216 | Filter deny ip host 97.74.144.31 any log ! 1 infects 10/14/09 to 10/14/09 jws.com | ISP godaddy.com inc |
| Clients 1 | united states |
Activity | Domain jws.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 1 | TCP Ports 80 | Filter deny ip host 194.67.57.20 any log ! 1 infects 09/03/09 to 09/03/09 mail.ru | ISP sovintel-msk-netbridge-ervices-net |
| Clients 1 | russian federation |
Activity | Domain mail.ru |
Chatter Example
|
BotClient Antivirus Diagnoses
|


russian federation
united states
china
japan
slovakia
germany
lebanon
israel
ecuador
canada
france
netherlands
argentina
korea_ republic of
thailand
india
serbia and montenegro
united kingdom
finland
spain
brazil