<span id="hs_cos_wrapper_post_body" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="rich_text" ><p>Over the last couple of days there have been reports that "<a href="http://www.techeye.net/security/vietnams-domains-are-a-cyber-crime-haven">Vietnam is a haven of malware</a>" with "more than half of [the .vn domains] hosting malware" and that the ISP "1&amp;1" accounts for <a href="http://www.theregister.co.uk/2010/10/26/botnet_hosting_isps/">one in 10 botnet Command &amp; Control (C&amp;C) hosts</a>.</p> <!--more--><p>Now these are not the same complaint but they are similar and I thought it might be interesting to see what is in the ThreatSTOP database for both. The results are interesting.</p> <p>[ I got the 1&amp;1 address space from a lookup at <a href="http://bgp.he.net/AS8560#_prefixes">Hurricane Electric of AS 8560</a> and I took the Vietnam address space from <a href="http://www.maxmind.com/app/geolitecountry">MaxMind's GeoLite Country</a> database]</p> <p>In raw numbers 1&amp;1 pips Vietnam but the two are pretty similar. For recently active addresses (addresses that have been found to be bad since October 1), 1&amp;1 has 100 entries whereas Vietnam has 91. However the 1&amp;1 entries include 34 entries on the "parasites" list which is generally less bad than our other feeds whereas Vietnam has just one. On the other hand 1&amp;1 has 19 live C&amp;C hosts identified by ShadowServer plus one ZeuS C&amp;C host while Vietnam has just 4 identified by ShadowServer and one Zeus. 1&amp;1 also has a number of Phishing sites while Vietnam has none, which is somewhat surprising as Phishing sites typically morph into malware droppers and vice-versa and Vietnam we, are told, is a haven for malware infected websites.</p> <p>Just for comparison the large French ISP SFR-neuf-cegetel has 14 recently active IP addresses, including two ShadowServer C&amp;C hosts and no ZeuS ones, which suggests that yes in absolute terms both 1&amp;1 and Vietnam are indeed bad.</p> <p>A PDF with the raw output data is here: <a href="http://threatstop.files.wordpress.com/2010/10/vietnam_vs_1and1.pdf">Vietnam_vs_1and1</a></p> <p>PS Over the last 4 years that ThreatSTOP has been gathering data, ip addresses in the Vietnam list have 966 hits while 1&amp;1 has 1286. However I consider this data to be suspect since various IP address ranges have been reassigned in that time.</p></span>