Most Prolific BotNet Command and Control Servers and Filters
Sun Sep 7 08:32:45 2008
10 Day Filter Set 30 Day Filter Set
| Priority 100 | TCP Ports 65520 65520 190 65520 194 65520 67 65520 69 65520 208 65520 77 65520 72 65520 217 65520 24 65520 216 65520 122 65520 218 65520 75 | Filter deny ip host 210.245.211.011 any log ! 596 infects 06/28/08 to 08/30/08 romlox.net | ISP kingdom - internet access |
| Clients 596 | hong kong |
Activity | Domain romlox.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 100 | TCP Ports 7000 7000 85 7000 218 | Filter deny ip host 211.096.097.044 any log ! 551 infects 04/27/08 to 05/12/08 cnuninet.net | ISP china united telecommunications corporation |
| Clients 551 | china |
Activity | Domain cnuninet.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 100 | TCP Ports 80 80 210 | Filter deny ip host 194.054.090.246 any log ! 526 infects 05/29/08 to 08/30/08 monkey.hosting.ua | ISP hosting.ua datacentre allocation |
| Clients 526 | ukraine |
Activity | Domain monkey.hosting.ua |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 100 | TCP Ports 13001 12351 | Filter deny ip host 067.149.121.039 any log ! 378 infects 08/11/08 to 08/16/08 wideopenwest.com | ISP wideopenwest ohio |
| Clients 378 | united states |
Activity | Domain wideopenwest.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 100 | TCP Ports 443 443 85 | Filter deny ip host 217.170.244.002 any log ! 311 infects 03/11/08 to 07/20/08 - | ISP ndermarrja telekomunikuese ktdn-ads |
| Clients 311 | serbia and montenegro |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 100 | TCP Ports 9890 9890 194 9890 69 9890 210 9890 208 9890 149 | Filter deny ip host 069.042.216.090 any log ! 259 infects 03/31/08 to 08/13/08 awknet.com | ISP awknet communications llc |
| Clients 259 | united states |
Activity | Domain awknet.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 100 | TCP Ports 6667 6668 7000 3921 | Filter deny ip host 063.173.172.098 any log ! 231 infects 03/14/08 to 08/22/08 - | ISP splk_tele yemen |
| Clients 231 | yemen |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 100 | TCP Ports 7000 8885 | Filter deny ip host 222.177.011.165 any log ! 216 infects 05/12/08 to 06/06/08 - | ISP renhexiaoxue |
| Clients 216 | china |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 100 | TCP Ports 9890 9890 69 | Filter deny ip host 069.042.216.108 any log ! 210 infects 08/25/08 to 08/30/08 awknet.com | ISP awknet communications llc |
| Clients 210 | united states |
Activity | Domain awknet.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 100 | TCP Ports 12351 13001 | Filter deny ip host 024.192.170.232 any log ! 129 infects 08/09/08 to 08/11/08 wideopenwest.com | ISP wideopenwest michigan |
| Clients 129 | canada |
Activity | Domain wideopenwest.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 100 | TCP Ports 80 65520 211 65520 209 65520 210 80 211 65520 69 65520 217 80 64 65520 222 80 217 | Filter deny ip host 085.114.137.060 any log ! 127 infects 04/10/08 to 06/03/08 fastit.net | ISP fastit |
| Clients 127 | germany |
Activity | Domain fastit.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 100 | TCP Ports 13001 12351 | Filter deny ip host 190.174.067.119 any log ! 115 infects 08/01/08 to 08/02/08 - | ISP - |
| Clients 115 | - |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 100 | TCP Ports 13001 12351 | Filter deny ip host 069.247.147.113 any log ! 110 infects 06/27/08 to 07/04/08 comcast.net | ISP comcast cable communications inc |
| Clients 110 | united states |
Activity | Domain comcast.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 100 | TCP Ports 7000 | Filter deny ip host 209.250.232.240 any log ! 109 infects 05/19/08 to 06/10/08 justedge.net | ISP justedge networks inc |
| Clients 109 | united states |
Activity | Domain justedge.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 89 | TCP Ports 13001 12351 | Filter deny ip host 094.036.065.059 any log ! 86 infects 08/04/08 to 08/04/08 - | ISP - |
| Clients 86 | - |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 80 | TCP Ports 3838 9928 72 2938 2293 7382 7763 9283 3938 3240 75 8492 7382 72 2938 210 7575 | Filter deny ip host 072.010.172.218 any log ! 78 infects 03/14/08 to 08/24/08 webdesignpro.org | ISP globotech communications |
| Clients 78 | canada |
Activity | Domain webdesignpro.org |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 76 | TCP Ports 5001 | Filter deny ip host 064.085.160.111 any log ! 74 infects 05/30/08 to 08/14/08 corenetworks.net | ISP great lakes comnet inc |
| Clients 74 | united states |
Activity | Domain corenetworks.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 47 | TCP Ports 7000 | Filter deny ip host 210.217.196.011 any log ! 46 infects 05/10/08 to 05/12/08 innosoft.biz | ISP intertns-lline-giga |
| Clients 46 | korea_ republic of |
Activity | Domain innosoft.biz |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 44 | TCP Ports 7000 | Filter deny ip host 218.093.014.236 any log ! 43 infects 04/29/08 to 05/03/08 - | ISP jintan changshen elementary school |
| Clients 43 | china |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 42 | TCP Ports 13001 12351 | Filter deny ip host 122.131.133.019 any log ! 41 infects 08/07/08 to 08/07/08 mesh.ad.jp | ISP nec biglobe ltd |
| Clients 41 | japan |
Activity | Domain mesh.ad.jp |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 42 | TCP Ports 65520 80 65520 67 65520 217 65520 72 | Filter deny ip host 085.114.143.208 any log ! 41 infects 03/11/08 to 04/21/08 fastit.net | ISP fastit |
| Clients 41 | germany |
Activity | Domain fastit.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 31 | TCP Ports 13001 12351 | Filter deny ip host 118.236.160.101 any log ! 30 infects 08/06/08 to 08/06/08 - | ISP - |
| Clients 30 | - |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 24 | TCP Ports 3267 | Filter deny ip host 069.042.216.124 any log ! 24 infects 03/11/08 to 04/25/08 awknet.com | ISP awknet communications llc |
| Clients 24 | united states |
Activity | Domain awknet.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 18 | TCP Ports 5001 | Filter deny ip host 213.239.192.125 any log ! 18 infects 05/31/08 to 08/14/08 your-server.de | ISP hetzner-rz-nbg-net |
| Clients 18 | germany |
Activity | Domain your-server.de |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 18 | TCP Ports 10324 5190 1863 | Filter deny ip host 067.043.236.098 any log ! 18 infects 06/09/08 to 08/29/08 synflood.ws | ISP globotech communications |
| Clients 18 | canada |
Activity | Domain synflood.ws |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 17 | TCP Ports 13001 12351 | Filter deny ip host 118.236.126.084 any log ! 17 infects 08/05/08 to 08/05/08 - | ISP - |
| Clients 17 | - |
Activity | Domain - |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 16 | TCP Ports 2345 | Filter deny ip host 084.244.019.183 any log ! 16 infects 03/13/08 to 04/26/08 spray.net | ISP spray network services ab |
| Clients 16 | sweden |
Activity | Domain spray.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 13 | TCP Ports 6667 | Filter deny ip host 092.114.004.002 any log ! 13 infects 08/01/08 to 08/06/08 apexcovantage.com | ISP eu-zz |
| Clients 13 | united kingdom |
Activity | Domain apexcovantage.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 13 | TCP Ports 6556 6556 194 | Filter deny ip host 194.109.011.065 any log ! 13 infects 06/10/08 to 08/30/08 xs4all.net | ISP xs4all ppp _30 router subnets |
| Clients 13 | netherlands |
Activity | Domain xs4all.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 13 | TCP Ports 7000 7000 85 | Filter deny ip host 067.019.050.066 any log ! 13 infects 04/06/08 to 04/09/08 theplanet.com | ISP theplanet.com internet services inc |
| Clients 13 | united states |
Activity | Domain theplanet.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 12 | TCP Ports 8080 8080 72 1863 10324 | Filter deny ip host 067.043.236.066 any log ! 12 infects 04/12/08 to 08/30/08 synflood.ws | ISP globotech communications |
| Clients 12 | canada |
Activity | Domain synflood.ws |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 12 | TCP Ports 13001 | Filter deny ip host 190.075.104.096 any log ! 12 infects 08/03/08 to 08/03/08 cantv.net | ISP cantv servicios venezuela |
| Clients 12 | venezuela |
Activity | Domain cantv.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 11 | TCP Ports 2345 2345 66 | Filter deny ip host 084.244.005.183 any log ! 11 infects 05/15/08 to 06/12/08 brimob.org | ISP spray network services ab |
| Clients 11 | sweden |
Activity | Domain brimob.org |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 11 | TCP Ports 6667 6667 85 7000 6668 | Filter deny ip host 203.186.079.248 any log ! 11 infects 03/14/08 to 03/22/08 ctinets.com | ISP i t city international ltd - por mee factory bui |
| Clients 11 | hong kong |
Activity | Domain ctinets.com |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 10 | TCP Ports 8080 10324 8080 67 | Filter deny ip host 072.010.172.211 any log ! 10 infects 04/12/08 to 08/15/08 webdesignpro.org | ISP globotech communications |
| Clients 10 | canada |
Activity | Domain webdesignpro.org |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 10 | TCP Ports 13001 | Filter deny ip host 064.202.117.102 any log ! 10 infects 08/11/08 to 08/11/08 scnet.net | ISP hostforweb inc |
| Clients 10 | united states |
Activity | Domain scnet.net |
Chatter Example
|
BotClient Antivirus Diagnoses
|
| Priority 8 | TCP Ports 51115 51115 85 | Filter deny ip host 069.050.208.003 any log ! 8 infects 04/21/08 to 05/06/08 bulletads.com | ISP atjeu publishing llc |
| Clients 8 | united states |
Activity | Domain bulletads.com |
Chatter Example
|


hong kong
china
ukraine
united states
serbia and montenegro
yemen
canada
germany
-
korea_ republic of
japan
sweden
united kingdom
netherlands
venezuela