Conversation

These lists are stored on Github. In this blog post, I show how you can use Git-Python and Matplotlib to explore the "Avastel all infected IPs 7d blocklist" and extract some insights. (2/6)
1
The main findings are the following: - There are ~70K distinct IP addresses in the list at a given time; - 800,000 malicious IP addresses have been flagged in 8 months; - 10.3% of the IPs have been included in the list for > 1 month; (3/6)
1
- The top 3 autonomous systems whose IP addresses are the most frequently flagged as proxies or used by bots are 1) Korea Telecom, 2) AS Coloam and 3) Chinanet; (4/6)
1