It’s quit interessting to see AS44997 (BTG12-AS BTG route block) at the top of the worst ISPs. For those of you which are reading my blog frequently: You now that ASN very-well from my previous posts. For all others: AS44997 was formerly known as UATelecom. The ISP is now known as Ural Industrial Company (Ural-NET) and is located in Russia. Different name but the same dirty business as before:
Ref: SBL70438
91.211.64.0/22 is listed on the Spamhaus Block List (SBL)
15-Feb-2009 21:53 GMT | SR04
Cybercrime & spam hosting hub; Ural Industrial Company Source: Spamhaus SBL70438
Another suspicious ISP is Leasweb, which is located in the Netherlands. When we look at Spamhaus SBL, we see more supicious activities in Leasweb’s Network:
The next ISP is Sistemnet Telekomunikasyon which is located in Turkey. I’ve already seen a lot of phishing sites, C&Cs and dropzones there. Shortly, It’s even worst than Ural-NET. Just take a look onto the SBLs concerning Sistemnet Telekomunikasyon:
If you want to see the whole statistic you can take a look on it on the ZeuS Tracker statistic page (link).
Improvements made to the ZeuS Tracker
Last but not least I have made some improvements to the ZeuS Tracker:
Country RSS feed available
I’ve received some requests from various CERTs concerning a country RSS Feed for new ZeuS hosts. So I’ve decided to create one. You can find it on the country page (eg. https://zeustracker.abuse.ch/monitor.php?country=HK). On the country page, just click on “Subscribe this country via RSS feed” and you will get informed about new ZeuS hosts in the specified country.
Browse ZeuS binaries
There is now a Browse ZeuS binaries function on the monitor page. With this function you can browse all ZeuS binaries which are stored in the ZeuS Tracker database (link).
Browse ZeuS configs
Additionally there is also a Browse ZeuS configs function on the monitor page. With this function you can browse all ZeuS configs which are stored in the ZeuS Tracker database (link).
0 Responses to “Some ZeuS statistics”