Webs.com Botnet Activities

Webs.com is a Web hoster how permit his users to create a personal, group, or small business website for free. Webs.com is also providing a free subdomain for each created account (ex : http://yourname.webs.com).

Since the start of our HoneyNet in February 2009 we have directly observe that some malware’s where located on Webs.com how participate actively to a bonnet construction and propagation.

Webs.com server, how is hosting the malware’s, has the IP 216.52.115.50. Since February 2009 to end August 2010, Webs.com botnet is composed of few different malware hoisters, has generate 2 978 events and 70 attackers have call the botnet files located on the hoster servers.

US, Germany and Colombia are the countries how are the most participating to the botnet activity in term of events. US and China are the countries how are hosting part of the botnet since more than 100 days.

August 2010 was the more active month in term of events, March 2010 the month with the most distinct attackers. February and April 2010 the months with the most detected hosters.
Since Jun 2010 we can see that the activity of the botnet is increasing drastically.
Interesting point the Webs.com, FileAve.com, the Kortech.cn and the Interfree.it botnets are linked together between some few hosters. Just check the available Afterglow visualization of the interaction between the botnets.