<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Unveillance &#124; Data Leakage Intelligence &#38; Metrics</title>
	<atom:link href="http://www.unveillance.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.unveillance.com</link>
	<description></description>
	<lastBuildDate>Tue, 23 Aug 2011 16:43:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>Reports of Liberated Web Access in Libya</title>
		<link>http://www.unveillance.com/latest-news/reports-of-liberated-web-access-in-libya/</link>
		<comments>http://www.unveillance.com/latest-news/reports-of-liberated-web-access-in-libya/#comments</comments>
		<pubDate>Tue, 23 Aug 2011 02:57:19 +0000</pubDate>
		<dc:creator>oday</dc:creator>
				<category><![CDATA[Latest News]]></category>

		<guid isPermaLink="false">http://www.unveillance.com/?p=1051</guid>
		<description><![CDATA[Many sources are reporting that various amounts of additional web access has been restored in Libya following a sporadic blackout post Feb. 17, 2011. Taking a peak at our view of Malware Activity in the past week, there is quite a rampant and obvious increase evident in the graph below. In today&#8217;s times, to classify &#8230;]]></description>
			<content:encoded><![CDATA[<p>Many sources are reporting that various amounts of additional <a href="http://www.cnn.com/2011/TECH/web/08/22/libya.internet/index.html" target="_blank">web access has been restored</a> in Libya following a sporadic blackout post Feb. 17, 2011.</p>
<p>Taking a peak at our view of Malware Activity in the past week, there is quite a rampant and obvious increase evident in the graph below.</p>
<p><img src="/images/libya_past_week_total_events.png" /></p>
<p>In today&#8217;s times, to classify malware is not an exact science in that most modern malware is quite flexible and can change characteristics instantly following a C&#038;C-directed drop of a new binary.  Regardless, as best that can be classified by malware binary type the predominant type of malware emanating from Libya are <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Glossary.aspx#worm" target="_blank">Worm</a> and <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Glossary.aspx#virus" target="_blank">Virus</a> variants.</p>
<p><img src="/images/libya_past_week_type_counts.png" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.unveillance.com/latest-news/reports-of-liberated-web-access-in-libya/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Recent Malware Event Activity</title>
		<link>http://www.unveillance.com/latest-news/recent-malware-event-activity/</link>
		<comments>http://www.unveillance.com/latest-news/recent-malware-event-activity/#comments</comments>
		<pubDate>Mon, 13 Jun 2011 12:19:32 +0000</pubDate>
		<dc:creator>oday</dc:creator>
				<category><![CDATA[Latest News]]></category>

		<guid isPermaLink="false">http://www.unveillance.com/?p=1036</guid>
		<description><![CDATA[Over the past 31 days we have seen 4.4 billion events deriving from malware which breaks down to 142.5 million events per day. The graph above details event counts over the past 31 days, snapshotted hourly.]]></description>
			<content:encoded><![CDATA[<p><center><img src="/images/ma_x31.jpg" alt="ma_x31.jpg" /></center></p>
<p>Over the past 31 days we have seen 4.4 billion events deriving from malware which breaks down to 142.5 million events per day.  The graph above details event counts over the past 31 days, snapshotted hourly.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.unveillance.com/latest-news/recent-malware-event-activity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Syrian Malware Activity Slows to a Whisper</title>
		<link>http://www.unveillance.com/latest-news/syrian-malware-activity-slows-to-a-whisper/</link>
		<comments>http://www.unveillance.com/latest-news/syrian-malware-activity-slows-to-a-whisper/#comments</comments>
		<pubDate>Fri, 03 Jun 2011 16:05:29 +0000</pubDate>
		<dc:creator>oday</dc:creator>
				<category><![CDATA[Latest News]]></category>

		<guid isPermaLink="false">http://www.unveillance.com/?p=1004</guid>
		<description><![CDATA[Following the lead of a few other Middle Eastern and North African nations (including Egypt in late January 2011 and Libya in mid-February of 2011) in the wake of civil unrest, it has been reported that the public internet has been greatly reduced in Syria. Referring to malware activity that we track, it appears that &#8230;]]></description>
			<content:encoded><![CDATA[<p>Following the lead of a few other Middle Eastern and North African nations (including <a href="http://www.unveillance.com/latest-news/malware-activity-from-the-country-of-egypt/">Egypt</a> in late January 2011 and <a href="http://www.unveillance.com/latest-news/libyan-malware-activity-vanishes/">Libya</a> in mid-February of 2011) in the wake of civil unrest, it has been <a href="http://www.renesys.com/blog/2011/06/syrian-internet-shutdown.shtml" target="_blank">reported</a> that the public internet has been greatly reduced in Syria.  Referring to malware activity that we track, it appears that a dramatic change occurred just before 04:00 UTC time, evident in the graph below.</p>
<p><script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script><script type="text/javascript" src="/wp-content/highcharts/js/highcharts.js"></script><script type="text/javascript" src="/wp-content/highcharts/js/hc_theme.js"></script><br />
<a name="libya_rev">&nbsp;</a><script type="text/javascript">var chart;$(document).ready(function() {chart = new Highcharts.Chart({chart: {renderTo: 'obj_syria_net_cut',defaultSeriesType: 'line',marginBottom: 100},title: {text: 'Malware Activity from the Country of Syria',x: -20},subtitle: {text: 'In UTC Time',x: -20},xAxis: {categories: ['6/2 04:00','6/2 05:00','6/2 06:00','6/2 07:00','6/2 08:00','6/2 09:00','6/2 10:00','6/2 11:00','6/2 12:00','6/2 13:00','6/2 14:00','6/2 15:00','6/2 16:00','6/2 17:00','6/2 18:00','6/2 19:00','6/2 20:00','6/2 21:00','6/2 22:00','6/2 23:00','6/3 00:00','6/3 01:00','6/3 02:00','6/3 03:00','6/3 04:00','6/3 05:00','6/3 06:00','6/3 07:00','6/3 08:00','6/3 09:00','6/3 10:00','6/3 11:00','6/3 12:00','6/3 13:00','6/3 14:00','6/3 15:00'], labels: {rotation: -45, align: 'right', style: {font: 'normal 10px Verdana, sans-serif'}}},yAxis: {title: {text: ''}},legend: {enabled: true},plotOptions: {area: {fillColor: {linearGradient: [0, 0, 0, 300],stops: [[0, highchartsOptions.colors[0]],[1, 'rgba(2,0,0,0)']]},lineWidth: 2,marker: {enabled: false,states: {hover: {enabled: true,radius: 5}}},shadow: false,states: {hover: {lineWidth: 2}}}},tooltip: {formatter: function() {return '<b>'+ this.series.name +'</b><br/>Count: '+ this.y;}},series: [{type: 'area', animation: false, name: 'Unique Public Host Count', data: [82,74,161,192,263,454,517,593,689,495,619,538,486,475,480,436,520,509,548,456,360,242,148,92,40,10,11,6,5,5,3,3,3,4,3,3]}, {type: 'area', animation: false, name: 'Event Count', data: [2235,2346,4164,7224,10316,10543,15090,15148,14861,13778,12278,12053,12533,13514,12513,12428,13693,15418,15674,13310,9321,5598,4332,1715,483,90,103,177,119,132,56,34,33,24,9,19]}]});});</script></p>
<div id="obj_syria_net_cut" style="width: 880px; height: 400px; margin: 0 auto;"></div>
<p>Post the dramatic shift in overall malware activity there are still a handful of hosts beaconing out as part of the following AS listed below.</p>
<table border="0" width="100%" cellspacing="1" cellpadding="2">
<tr valign="top">
<td width="20%" align="center"><strong>AS</strong></td>
<td width="20%" align="center"><strong>BGP IPv4 Prefix</strong></td>
<td width="20%" align="center"><strong>AS Name</strong></td>
<td width="20%" align="center"><strong>City</strong></td>
<td width="10%" align="center"><strong>Infected Host Count</strong></td>
<td width="10%" align="center"><strong>Event Count</strong></td>
</tr>
<tr valign="top">
<td align="center">AS29386</td>
<td align="center">82.137.192.0/18</td>
<td align="center">STE-AS2 Syrian Telecommunications Establishment</td>
<td align="center">Damascus, SY</td>
<td align="center">3</td>
<td align="center">107</td>
</tr>
<tr valign="top">
<td align="center">AS29256</td>
<td align="center">178.253.64.0/19</td>
<td align="center">STE-AS Syrian Telecommunications Establishment</td>
<td align="center">-, SY</td>
<td align="center">1</td>
<td align="center">7</td>
</tr>
</table>
<p>You can follow updates of Syrian malware activity per hourly updates in our <a href="http://www.unveillance.com/latest-news/the-middle-east-and-north-africa/#syria">Middle East/North Africa blog</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.unveillance.com/latest-news/syrian-malware-activity-slows-to-a-whisper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Project Cyber Dawn: Libya &#8211; Released For Public Viewing</title>
		<link>http://www.unveillance.com/latest-news/project-cyber-dawn-libya-released-for-public-viewing/</link>
		<comments>http://www.unveillance.com/latest-news/project-cyber-dawn-libya-released-for-public-viewing/#comments</comments>
		<pubDate>Wed, 25 May 2011 18:09:59 +0000</pubDate>
		<dc:creator>oday</dc:creator>
				<category><![CDATA[Latest News]]></category>

		<guid isPermaLink="false">http://www.unveillance.com/?p=988</guid>
		<description><![CDATA[CSFI is officially releasing “Project Cyber Dawn Libya.” Project Cyber Dawn Libya is the result of a collaborative research effort of twenty-one individuals from the USA, Australia, Canada, Egypt, Italy, Tunisia and the UK. Project Cyber Dawn Libya collates, analyzes, and reports on raw data and its Interconnections that have been harvested from the public &#8230;]]></description>
			<content:encoded><![CDATA[<p><a title="Project Cyber Dawn: Libya (Public)" href="http://www.unveillance.com/wp-content/uploads/2011/05/Project_Cyber_Dawn_Public.pdf" target="_blank"><img class="alignleft size-full wp-image-989" title="Project Cyber Dawn: Libya (Public)" src="http://www.unveillance.com/wp-content/uploads/2011/05/libya.png" alt="" width="269" height="339" /></a>CSFI is officially releasing “Project Cyber Dawn  Libya.” Project Cyber Dawn Libya is the result of a collaborative  research effort of twenty-one individuals from the USA, Australia,  Canada, Egypt, Italy, Tunisia and the UK.</p>
<p>Project Cyber Dawn Libya collates, analyzes, and reports on raw data and  its Interconnections that have been harvested from the public domain.  Recent events are correlated with known historical data to provide an  in-depth view into Libyan Cyber Warfare capabilities and defenses.  Through this analysis, CSFI can help the international community to  understand not only Libya’s potential to influence the balance in  cyberspace, but also the physical repercussions of cyber-attacks  originating from, and directed towards Libya.</p>
<p>A public release copy of the report is downloadable by clicking the thumbnail to the left.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.unveillance.com/latest-news/project-cyber-dawn-libya-released-for-public-viewing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Global Botnet Distribution</title>
		<link>http://www.unveillance.com/latest-news/global-botnet-distribution/</link>
		<comments>http://www.unveillance.com/latest-news/global-botnet-distribution/#comments</comments>
		<pubDate>Fri, 25 Mar 2011 19:29:01 +0000</pubDate>
		<dc:creator>oday</dc:creator>
				<category><![CDATA[Latest News]]></category>

		<guid isPermaLink="false">http://www.unveillance.com/?p=898</guid>
		<description><![CDATA[Charlie Sheen would say that mass-infection or botnet-controlled malware is #winning. Malware has taken on many faces in recent years &#8211; from compromising hosts to predominantly send spam it has also evolved into identity theft, fraud, extortion and is now the cornerstone of the front lines of a widely-debated cyber war. The following graphic was &#8230;]]></description>
			<content:encoded><![CDATA[<p>Charlie Sheen would say that mass-infection or botnet-controlled malware is #winning.</p>
<p>Malware has taken on many faces in recent years &#8211; from compromising hosts to predominantly send spam it has also evolved into identity theft, fraud, extortion and is now the cornerstone of the front lines of a widely-debated cyber war.</p>
<p>The following graphic was generated earlier this afternoon (EDT) referencing the last 500,000 public hosts (roughly a single hour&#8217;s worth) emitting activity indicative of a compromised host per malware.  As expected North America and Europe are the most active during this time frame.</p>
<p><center><a href="http://www.unveillance.com/images/world_malware_activity.jpg" target="_blank"><img src="http://www.unveillance.com/wp-content/uploads/2011/03/world_malware_activity_1280.jpg" alt="" title="world_malware_activity_1280" width="640" /><span style="font-size: 10px;">Click for larger version</span></a></center></p>
<p>Base image credit to Nasa&#8217;s <a href="http://visibleearth.nasa.gov/view_rec.php?id=2430" target="_blank">Blue Marble</a> series.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.unveillance.com/latest-news/global-botnet-distribution/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Malware Activity Over the Duration of the 2011 Libyan Revolution</title>
		<link>http://www.unveillance.com/latest-news/malware-activity-over-the-duration-of-the-2011-libyan-revolution/</link>
		<comments>http://www.unveillance.com/latest-news/malware-activity-over-the-duration-of-the-2011-libyan-revolution/#comments</comments>
		<pubDate>Mon, 21 Mar 2011 02:36:13 +0000</pubDate>
		<dc:creator>oday</dc:creator>
				<category><![CDATA[Latest News]]></category>

		<guid isPermaLink="false">http://www.unveillance.com/?p=845</guid>
		<description><![CDATA[In the midst of the 2011 Libyan uprising coalition forces announced the launch of Operation Odyssey Dawn on Saturday (Mar. 19). The uprising began on or around Feb. 15 and in earnest on Feb. 17., picking up momentum in eastern Libya. Much like the uprising in Egypt, where the then standing Egyptian government attempted to &#8230;]]></description>
			<content:encoded><![CDATA[<p>In the midst of the <a href="http://en.wikipedia.org/wiki/2011_Libyan_uprising" target="_blank">2011 Libyan uprising</a> coalition forces announced the <a href="http://www.defense.gov/news/newsarticle.aspx?id=63225" target="_blank">launch of Operation Odyssey Dawn</a> on Saturday (Mar. 19).</p>
<p>The uprising began on or around Feb. 15 and in earnest on Feb. 17., picking up momentum in eastern Libya.  Much like the uprising in Egypt, where the then standing Egyptian government attempted to use a <a href="http://www.unveillance.com/latest-news/malware-activity-from-the-country-of-egypt/" target="_blank">complete shutdown on the Egyptian internet</a> as a ploy to slow the growing revolution, the Libyan government appeared to be using the same playbook and <a href="http://www.unveillance.com/latest-news/libyan-malware-activity-vanishes/" target="_blank">reportedly began to shutdown portions of the Libyan internet</a>.</p>
<p>Below is graph beginning on Feb. 17, 2011 of hourly counts of both unique public hosts and total events deriving from sinkholed malware.  While during the first couple weeks of the uprising the malware activity was average with the advent of a few periods of total silence lasting only a few hours at a time.  Starting on Mar. 3 the overall malware activity become very erratic and predominantly from hosts that appear to be centered in or around Tripoli.</p>
<p><script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script><script type="text/javascript" src="/wp-content/highcharts/js/highcharts.js"></script><script type="text/javascript" src="/wp-content/highcharts/js/hc_theme.js"></script><br />
<a name="libya_rev">&nbsp;</a><script type="text/javascript">var chart;$(document).ready(function() {chart = new Highcharts.Chart({chart: {renderTo: 'obj_libya_rev',defaultSeriesType: 'line',marginBottom: 100},title: {text: 'Libyan Malware Activity',x: -20},subtitle: {text: 'Feb. 17, 2011 - Mar. 20, 2011',x: -20},xAxis: {labels: {enabled: false}},yAxis: {title: {text: ''}},legend: {enabled: true},plotOptions: {area: {fillColor: {linearGradient: [0, 0, 0, 300],stops: [[0, highchartsOptions.colors[0]],[1, 'rgba(2,0,0,0)']]},lineWidth: 2,marker: {enabled: false,states: {hover: {enabled: true,radius: 5}}},shadow: false,states: {hover: {lineWidth: 2}}}},tooltip: {formatter: function() {return '<b>'+ this.series.name +'</b><br/>Count: '+ this.y;}},series: [{type: 'area', animation: false, name: 'Unique Public Host Count', data: [55,89,138,176,156,178,189,182,171,187,142,128,148,137,153,148,157,139,100,84,57,48,43,37,41,45,60,78,70,84,121,144,149,144,139,126,144,147,137,132,109,100,74,0,0,0,0,0,0,50,74,87,98,113,116,119,118,108,98,104,104,109,96,92,77,0,0,0,19,0,0,0,0,57,77,86,102,97,100,89,87,84,70,69,86,69,66,64,62,58,48,41,39,33,32,36,49,49,60,71,69,70,61,67,56,61,66,72,65,75,74,67,55,44,43,36,39,34,43,55,66,64,70,72,83,83,72,72,66,75,76,74,71,71,70,56,51,39,29,26,30,32,44,58,57,64,69,87,84,83,78,85,100,95,99,87,87,73,68,60,49,40,36,28,36,46,47,57,66,81,81,89,90,77,73,89,92,96,91,97,93,78,81,67,45,39,31,28,31,31,36,48,47,72,67,78,78,78,76,83,94,90,90,91,90,78,69,54,45,38,30,28,28,27,37,44,55,61,75,85,88,84,84,84,91,100,118,102,117,110,82,65,57,39,32,108,104,111,104,114,128,122,120,119,127,128,107,80,57,52,40,36,40,55,59,86,91,98,119,142,135,146,134,136,146,140,145,141,129,114,105,88,70,49,39,38,45,55,76,69,95,95,105,114,112,124,119,137,153,151,149,153,138,133,112,83,65,46,43,39,43,56,70,80,93,108,112,114,123,129,117,139,137,139,150,138,122,109,86,67,61,48,38,48,53,67,98,112,134,134,139,140,143,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,39,0,0,0,0,0,0,14,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,45,0,0,0,0,0,18,0,0,0,10,0,0,0,0,0,0,27,0,0,0,0,0,0,0,0,0,35,0,0,0,0,0,0,0,18,0,0,0,22,0,10,39,0,0,0,0,9,1,1,1,1,1,1,1,1,1,1,1,4,1,1,1,20,1,4,0,1,1,1,0,1,1,1,1,1,1,1,1,1,1,1,1,9,1,1,1,1,1,1,1,2,2,2,18,2,2,3,2,2,26,2,22,2,2,2,2,8,2,2,3,2,2,15,1,8,2,2,2,11,2,3,3,12,3,3,3,3,3,3,8,3,6,3,3,4,3,3,3,4,18,3,3,3,3,3,3,3,3,3,3,18,3,3,3,3,3,3,3,3,3,3,3,18,3,3,2,2,2,2,2,28,32,2,2,2,2,2,2,2,2,2,3,3,3,7,3,10,33,3,3,21,27,4,3,3,3,37,3,3,6,3,3,3,9,9,3,4,3,9,4,3,4,9,22,3,3,3,3,3,3,3,3,3,3,3,8,3,3,5,5,5,4,5,5,28,5,5,3,4,3,3,4,3,3,3,3,3,3,3,3,3,5,3,4,5,5,5,5,5,12,5,3,3,4,4,3,3,3,3,3,3,3,3,3,3,3,3,4,5,6,5,6,6,6,4,4,21,22,3,8,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,4,6,4,4,4,3,3,5,2,2,2,4,2,2,2,8,2,3,2,16,3,4,3,3,4,2,17,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,4]}, {type: 'area', animation: false, name: 'Event Count', data: [105,164,261,325,300,355,372,367,354,355,285,252,302,299,308,284,299,272,215,178,117,87,83,64,70,78,101,136,124,157,194,256,306,290,269,238,277,279,253,240,190,193,140,0,0,0,0,0,0,73,114,143,173,197,205,214,202,179,174,176,178,181,163,158,132,0,0,0,31,0,0,0,0,96,132,151,188,178,188,164,162,147,121,124,154,122,118,106,101,98,85,72,67,57,57,63,83,81,107,119,113,120,104,109,91,103,116,119,109,129,124,108,88,68,69,59,60,52,67,85,95,97,106,118,129,129,120,117,103,116,118,112,111,115,112,91,82,60,45,36,41,45,65,92,90,109,114,140,133,134,129,152,169,155,164,147,140,121,114,97,74,58,49,37,47,66,70,83,103,132,136,138,135,120,112,133,141,141,141,162,150,128,129,103,66,53,41,37,40,41,47,69,74,106,99,119,119,121,128,137,159,145,145,142,149,126,101,82,67,54,43,39,38,36,50,59,77,91,114,135,137,130,134,140,152,163,186,160,195,194,152,122,99,66,51,177,185,212,204,228,248,235,231,220,233,237,207,134,95,84,67,58,66,84,98,130,151,170,189,225,228,264,234,228,250,247,269,267,231,216,204,154,127,89,65,65,82,90,129,121,176,196,206,213,224,228,218,250,303,309,304,295,276,227,190,138,107,78,72,64,72,96,125,148,165,196,200,214,222,235,218,257,264,259,288,280,255,227,160,135,117,91,54,72,89,115,195,222,249,249,258,263,254,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,47,0,0,0,0,0,0,14,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,69,0,0,0,0,0,18,0,0,0,11,0,0,0,0,0,0,44,0,0,0,0,0,0,0,0,0,44,0,0,0,0,0,0,0,24,0,0,0,23,0,10,56,0,0,0,0,10,2,2,2,2,2,2,2,2,2,2,2,5,2,2,2,37,2,5,0,2,2,2,0,2,2,2,2,2,2,2,2,2,2,2,2,11,2,2,2,2,2,2,2,5,5,5,21,5,5,6,5,5,50,5,41,5,5,5,5,11,4,4,5,4,4,18,2,9,4,4,4,14,4,6,6,15,6,6,6,6,6,6,11,7,10,7,7,8,7,7,7,8,26,7,7,7,7,7,7,7,7,7,7,29,7,7,7,7,6,6,6,6,6,6,6,29,6,6,4,4,4,4,4,45,52,4,4,4,4,4,4,5,5,5,7,7,7,10,7,16,58,7,7,37,49,8,11,9,9,68,9,9,12,9,9,9,14,14,8,9,8,16,11,9,12,18,39,9,9,9,9,9,9,9,9,9,9,9,15,10,9,12,15,13,12,15,15,53,15,15,9,10,9,9,10,9,9,9,9,9,9,9,9,9,11,9,12,15,15,15,15,15,23,13,9,9,12,12,9,9,9,9,9,9,9,9,9,9,9,9,12,15,16,15,18,18,18,11,11,39,46,8,13,8,8,8,8,8,8,8,8,8,8,8,8,8,8,9,9,9,9,9,12,14,12,12,12,9,9,9,6,6,6,8,6,6,6,12,6,7,6,33,8,9,8,9,10,6,27,9,9,9,9,9,9,9,9,9,9,9,9,9,9,9,9,9,9,9,9,9,8,8,9]}]});});</script></p>
<div id="obj_libya_rev" style="width: 880px; height: 400px; margin: 0 auto;"></div>
<p><br clear="all"><br />
We have also been generating IPv4 Prefix origins of the malware coming out of Libya.  Below is a table summarizing all Prefix activity since Feb. 17.</p>
<table border="0" width="100%" cellspacing="1" cellpadding="2">
<tr valign="top">
<td width="20%" align="center"><strong>AS</strong></td>
<td width="20%" align="center"><strong>BGP IPv4 Prefix</strong></td>
<td width="20%" align="center"><strong>AS Name</strong></td>
<td width="20%" align="center"><strong>City</strong></td>
<td width="20%" align="center"><strong>Infected Host Count</strong></td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.208.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">11,315</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.0.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">7,442</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.192.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Benghazi, LY</td>
<td align="center">1,707</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.1.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">7,502</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">62.240.32.0/19</td>
<td align="center">GPTC-AS</td>
<td align="center">-, LY</td>
<td align="center">1,214</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">11,716</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">62.68.32.0/19</td>
<td align="center">GPTC-AS</td>
<td align="center">Benghazi, LY</td>
<td align="center">844</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/14</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">2,030</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.2.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">3,718</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.128.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Zawia, LY</td>
<td align="center">2,605</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Benghazi, LY</td>
<td align="center">590</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.3.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">1,559</td>
</tr>
</table>
<p><br clear="all"><br />
Finally, we created a desktop capture of all the Prefix activity of malware starting on Feb. 17 through Mar. 20.  Periodically within the video we expand each city&#8217;s consolidated labels to reveal all the Prefix details.  When the timeline is started shortly after the beginning of the movie you can see the Prefix activity roll in and out with each passing day (more easily seen if choosing to view higher resolution versions of the video in full screen).</p>
<p><center></p>
<p><object width="500" height="306"><param name="movie" value="http://www.youtube.com/v/w6NzAxZzg6k?version=3"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/w6NzAxZzg6k?version=3" type="application/x-shockwave-flash" width="500" height="306" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p></center></p>
]]></content:encoded>
			<wfw:commentRss>http://www.unveillance.com/latest-news/malware-activity-over-the-duration-of-the-2011-libyan-revolution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Middle East and North Africa</title>
		<link>http://www.unveillance.com/latest-news/the-middle-east-and-north-africa/</link>
		<comments>http://www.unveillance.com/latest-news/the-middle-east-and-north-africa/#comments</comments>
		<pubDate>Mon, 21 Feb 2011 06:04:56 +0000</pubDate>
		<dc:creator>oday</dc:creator>
				<category><![CDATA[Latest News]]></category>

		<guid isPermaLink="false">http://www.unveillance.com/?p=715</guid>
		<description><![CDATA[With recent civil unrest in several countries spanning the Middle East and North Africa a few nation states have cut internet access for their respective countries. The graphs below will update approximately every hour detailing malware activity by unique host counts and total events from each country. We have found that when the malware activity &#8230;]]></description>
			<content:encoded><![CDATA[<p>With recent civil unrest in several countries spanning the Middle East and North Africa a few nation states have cut internet access for their respective countries.  The graphs below will update approximately every hour detailing malware activity by unique host counts and total events from each country.  We have found that when the malware activity vanishes it&#8217;s indicative of the internet being cut.</p>
<p>Graphs no longer available.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.unveillance.com/latest-news/the-middle-east-and-north-africa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Detection and Practical Prevention</title>
		<link>http://www.unveillance.com/latest-news/malware-detection-and-practical-prevention/</link>
		<comments>http://www.unveillance.com/latest-news/malware-detection-and-practical-prevention/#comments</comments>
		<pubDate>Sat, 19 Feb 2011 11:53:01 +0000</pubDate>
		<dc:creator>oday</dc:creator>
				<category><![CDATA[Latest News]]></category>

		<guid isPermaLink="false">http://www.unveillance.com/?p=642</guid>
		<description><![CDATA[Defending your Enterprise&#8217;s network against modern threat and the tactics of virtual thieves has become a daunting task to place on the shoulders of any security team. Frankly speaking, it has become an unfair and unbalanced match in that the advantage is solely in the hands of the bad guys. Some articles and papers about &#8230;]]></description>
			<content:encoded><![CDATA[<p>Defending your Enterprise&#8217;s network against modern threat and the tactics of virtual thieves has become a daunting task to place on the shoulders of any security team.  Frankly speaking, it has become an unfair and unbalanced match in that the advantage is solely in the hands of the bad guys.</p>
<p>Some articles and papers about malware growth and trends:<br />
&#8220;Report: Malware Growth At An All-Time High&#8221;<br />
<a href="http://netcentricsecurity.com/articles/2011/02/08/report-malware-growth.aspx" target="_blank">http://netcentricsecurity.com/articles/2011/02/08/report-malware-growth.aspx</a></p>
<p>&#8220;Growing sophistication of botnets, pervasive devices and social networking, and threats to physical systems will demand increased vigilance in 2011.&#8221;<br />
<a href="http://www.gtisc.gatech.edu/pdf/cyberThreatReport2011.pdf" target="_blank">http://www.gtisc.gatech.edu/pdf/cyberThreatReport2011.pdf</a></p>
<p>&#8220;Hacktivism, cyber war and social engineering tactics expected to be among the most widely-used methods for spreading encrypted and dynamic malware.&#8221;<br />
<a href="http://press.pandasecurity.com/usa/news/pandalabs-predicts-security-trends-for-2011/" target="_blank">http://press.pandasecurity.com/usa/news/pandalabs-predicts-security-trends-for-2011/</a></p>
<p>&#8220;2010 saw not only continued sophistication on the part of cybercriminals but also a tightening of the organizational structures in which they operate. Turf wars between cybercriminal organizations will continue to develop in what has literally turned into a fully operational underground economy.&#8221;<br />
<a href="http://www.websense.com/content/threat-report-2010-highlights.aspx" target="_blank">http://www.websense.com/content/threat-report-2010-highlights.aspx</a></p>
<p>Doom and gloom aside, all hope is not lost.  We do not believe that things are so dark now that it requires a complete restart of modern preventive practices and policies, but a re-thinking and re-education of how you detect and measure security effectiveness within the Enterprise.  Tens of thousands of very bright and talented people have created all of the technology deployed and used in today&#8217;s Enterprise networks.  But, what is all of this technology in a nutshell?  It&#8217;s automation.</p>
<p>Effective automation requires relevant and correlated intelligence translated into optimized configuration parameters for all deployed components of a given Enterprise network security infrastructure.  We can help enlighten security teams with issue detection and trends that ultimately provides a more optimized approach to incident response while simultaneously greatly improving and automating security infrastructure issue focus and configuration in near-realtime.</p>
<p>As an example of how we use derivative trending data from security event data, we have recently posted metrics for the industry index, encompassing the Fortune 2000+.  You can access the trending information in our <a href="http://www.unveillance.com/trends/">Trending Section</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.unveillance.com/latest-news/malware-detection-and-practical-prevention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Libyan Malware Activity Vanishes</title>
		<link>http://www.unveillance.com/latest-news/libyan-malware-activity-vanishes/</link>
		<comments>http://www.unveillance.com/latest-news/libyan-malware-activity-vanishes/#comments</comments>
		<pubDate>Fri, 18 Feb 2011 16:04:54 +0000</pubDate>
		<dc:creator>oday</dc:creator>
				<category><![CDATA[Latest News]]></category>

		<guid isPermaLink="false">http://www.unveillance.com/?p=691</guid>
		<description><![CDATA[As the situation in Libya grows more unstable and violence escalates it has been reported that Libya has cut their internet much like how Egypt did three weeks ago. From our perspective of tracking malicious malware, we detected a total stoppage in activity starting several hours ago. var chart;$(document).ready(function() {chart = new Highcharts.Chart({chart: {renderTo: 'libya_activity',defaultSeriesType: &#8230;]]></description>
			<content:encoded><![CDATA[<p>As the situation in Libya grows more unstable and <a href="http://www.pcworld.com/businesscenter/article/220177/as_violence_escalates_libya_cuts_off_the_internet.html" target="_blank">violence escalates</a> it has been reported that Libya has cut their internet much like how <a href="http://www.unveillance.com/latest-news/malware-activity-from-the-country-of-egypt/">Egypt did three weeks ago</a>.</p>
<p>From our perspective of tracking malicious malware, we detected a total stoppage in activity starting several hours ago.</p>
<p><script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script><br />
<script type="text/javascript" src="/wp-content/highcharts/js/highcharts.js"></script></p>
<p><script type="text/javascript">
var chart;$(document).ready(function() {chart = new Highcharts.Chart({chart: {renderTo: 'libya_activity',defaultSeriesType: 'areaspline',marginBottom: 100},title: {text: 'Malware Activity from the Country of Libya',x: -20},subtitle: {text: 'In UTC Time',x: -20},xAxis: {categories: ['2/18 00:00','2/18 01:00','2/18 02:00','2/18 03:00','2/18 04:00','2/18 05:00','2/18 06:00','2/18 07:00','2/18 08:00','2/18 09:00','2/18 10:00','2/18 11:00','2/18 12:00','2/18 13:00','2/18 14:00','2/18 15:00','2/18 16:00','2/18 17:00','2/18 18:00','2/18 19:00','2/18 20:00','2/18 21:00','2/18 22:00','2/18 23:00','2/19 00:00','2/19 01:00','2/19 02:00','2/19 03:00','2/19 04:00','2/19 05:00'], labels: {rotation: -45, align: 'right', style: {font: 'normal 10px Verdana, sans-serif'}}},yAxis: {title: {text: ''},plotLines: [{value: 0,width: 1,color: '#808080'}]},plotOptions: {areaspline: {fillOpacity: 0.2}},tooltip: {formatter: function() {return '<b>'+ this.series.name +'</b><br/>'+this.x +': '+ this.y;}},series: [{name: 'Unique Host Count',data: [100,84,57,48,43,37,41,45,60,78,70,84,121,144,149,144,139,126,144,147,137,132,109,100,74,0,0,0,0,0]}, {name: 'Event Count',data: [215,178,117,87,83,64,70,78,101,136,124,157,194,256,306,290,269,238,277,279,253,240,190,193,140,0,0,0,0,0]}]});});
</script> </p>
<div id="libya_activity" style="width: 880px; height: 400px; margin: 0 auto;"></div>
<p><strong>Update, Feb. 19 (06:30 ET):</strong> Malware is flowing out of Libya as of a few hours ago.</p>
<p><script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script><br />
<script type="text/javascript" src="/wp-content/highcharts/js/highcharts.js"></script></p>
<p><script type="text/javascript">
var chart;$(document).ready(function() {chart = new Highcharts.Chart({chart: {renderTo: 'libya_activity2',defaultSeriesType: 'areaspline',marginBottom: 100},title: {text: 'Malware Activity from the Country of Libya (Update #2)',x: -20},subtitle: {text: 'In UTC Time',x: -20},xAxis: {categories: ['2/18 04:00','2/18 05:00','2/18 06:00','2/18 07:00','2/18 08:00','2/18 09:00','2/18 10:00','2/18 11:00','2/18 12:00','2/18 13:00','2/18 14:00','2/18 15:00','2/18 16:00','2/18 17:00','2/18 18:00','2/18 19:00','2/18 20:00','2/18 21:00','2/18 22:00','2/18 23:00','2/19 00:00','2/19 01:00','2/19 02:00','2/19 03:00','2/19 04:00','2/19 05:00','2/19 06:00','2/19 07:00','2/19 08:00','2/19 09:00','2/19 10:00','2/19 11:00'], labels: {rotation: -45, align: 'right', style: {font: 'normal 10px Verdana, sans-serif'}}},yAxis: {title: {text: ''},plotLines: [{value: 0,width: 1,color: '#808080'}]},plotOptions: {areaspline: {fillOpacity: 0.2}},tooltip: {formatter: function() {return '<b>'+ this.series.name +'</b><br/>'+this.x +': '+ this.y;}},series: [{name: 'Unique Host Count',data: [43,37,41,45,60,78,70,84,121,144,149,144,139,126,144,147,137,132,109,100,74,0,0,0,0,0,0,50,74,87,98,113]}, {name: 'Event Count',data: [83,64,70,78,101,136,124,157,194,256,306,290,269,238,277,279,253,240,190,193,140,0,0,0,0,0,0,73,114,143,173,197]}]});});
</script> </p>
<div id="libya_activity2" style="width: 880px; height: 400px; margin: 0 auto;"></div>
<p><strong>Update, Feb. 19 (18:30 ET):</strong> Malware coming out of Libya has become very erratic so I thought it best to just create a graph that will update itself approximately every hour showing the last 36 hours per update cycle.</p>
<p><script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script><br />
<script type="text/javascript" src="/wp-content/highcharts/js/highcharts.js"></script></p>
<p><script type="text/javascript">
var chart;$(document).ready(function() {chart = new Highcharts.Chart({chart: {renderTo: 'libya_activity_rolling',defaultSeriesType: 'areaspline',marginBottom: 100},title: {text: 'Malware Activity from the Country of Libya (Last Updated: 6/14 13:00 UTC)',x: -20},subtitle: {text: 'In UTC Time',x: -20},xAxis: {categories: ['6/13 01:00','6/13 02:00','6/13 03:00','6/13 04:00','6/13 05:00','6/13 06:00','6/13 07:00','6/13 08:00','6/13 09:00','6/13 10:00','6/13 11:00','6/13 12:00','6/13 13:00','6/13 14:00','6/13 15:00','6/13 16:00','6/13 17:00','6/13 18:00','6/13 19:00','6/13 20:00','6/13 21:00','6/13 22:00','6/13 23:00','6/14 00:00','6/14 01:00','6/14 02:00','6/14 03:00','6/14 04:00','6/14 05:00','6/14 06:00','6/14 07:00','6/14 08:00','6/14 09:00','6/14 10:00','6/14 11:00','6/14 13:00'], labels: {rotation: -45, align: 'right', style: {font: 'normal 10px Verdana, sans-serif'}}},yAxis: {title: {text: ''},plotLines: [{value: 0,width: 1,color: '#808080'}]},plotOptions: {areaspline: {fillOpacity: 0.2}},tooltip: {formatter: function() {return '<b>'+ this.series.name +'</b><br/>'+this.x +': '+ this.y;}},series: [{name: 'Unique Host Count',data: [2,2,2,2,2,2,2,2,2,3,2,3,2,2,2,2,2,2,2,2,2,2,2,2,2,2,2,2,2,2,2,2,2,3,2,2]}, {name: 'Event Count',data: [148,262,258,267,267,263,328,343,389,477,547,537,333,260,265,252,259,264,262,262,259,254,256,266,255,248,248,252,251,265,334,367,563,608,469,350]}]});});
</script> </p>
<div id="libya_activity_rolling" style="width: 880px; height: 400px; margin: 0 auto;"></div>
<p><strong>Update, March 3 (17:00 ET):</strong> Malware vanishes again, indicative of a complete or partial &#8216;net shutdown.  <a href="http://twitter.com/#!/NicRobertsonCNN/status/43438546958303232" target="_blank">Reports out of Tripoli</a> that &#8216;net and land lines down.  As always, our <a href="http://www.unveillance.com/latest-news/the-middle-east-and-north-africa/#libya">near-realtime graph</a> is always updating, tracking any dramatic changes in actiivty.</p>
<p><a name="malware_prefixes">&nbsp;</a><br />
<strong>Update, March 4 (23:00 ET):</strong> Since the latest apparent Libyan internet shutdown from two days ago, there has been a small amount of malware activity.  The prefixes are listed below.</p>
<table border="0" width="100%" cellspacing="1" cellpadding="2">
<tr valign="top">
<td width="20%" align="center"><strong>AS</strong></td>
<td width="20%" align="center"><strong>BGP IPv4 Prefix</strong></td>
<td width="20%" align="center"><strong>AS Name</strong></td>
<td width="20%" align="center"><strong>City</strong></td>
<td width="20%" align="center"><strong>Infected Host Count</strong></td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.208.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">-, LY</td>
<td align="center">16</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.0.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Misratah, LY</td>
<td align="center">7</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.1.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">8</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">14</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.192.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Benghazi, LY</td>
<td align="center">8</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/14</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">4</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">3</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.128.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Zawia, LY</td>
<td align="center">4</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.3.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">2</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">62.68.32.0/19</td>
<td align="center">GPTC-AS</td>
<td align="center">-, LY</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.2.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">1</td>
</tr>
</table>
<p><a name="malware_prefixes2">&nbsp;</a><br />
<strong>Update, March 5 (13:00 ET):</strong> Compared to the limited &#8216;net activity coming out of Libya, the largest spike of malware activity occurred within the last hour.</p>
<table border="0" width="100%" cellspacing="1" cellpadding="2">
<tr valign="top">
<td width="20%" align="center"><strong>AS</strong></td>
<td width="20%" align="center"><strong>BGP IPv4 Prefix</strong></td>
<td width="20%" align="center"><strong>AS Name</strong></td>
<td width="20%" align="center"><strong>City</strong></td>
<td width="20%" align="center"><strong>Infected Host Count</strong></td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.0.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Misratah, LY</td>
<td align="center">10</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.2.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">20</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.208.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">16</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.192.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Benghazi, LY</td>
<td align="center">6</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/14</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">5</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.128.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Zawia, LY</td>
<td align="center">7</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.1.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">4</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Benghazi, LY</td>
<td align="center">1</td>
</tr>
</table>
<p><a name="malware_prefixes3">&nbsp;</a><br />
<strong>Update, March 6 (06:00 ET):</strong> Sporadic network activity over the last 12 hours continues to make it&#8217;s way out of Libya by way of interactive malware. </p>
<table border="0" width="100%" cellspacing="1" cellpadding="2">
<tr valign="top">
<td width="20%" align="center"><strong>AS</strong></td>
<td width="20%" align="center"><strong>BGP IPv4 Prefix</strong></td>
<td width="20%" align="center"><strong>AS Name</strong></td>
<td width="20%" align="center"><strong>City</strong></td>
<td width="20%" align="center"><strong>Infected Host Count</strong></td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.0.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Misratah, LY</td>
<td align="center">32</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">28</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.2.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">2</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.208.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">35</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.192.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Benghazi, LY</td>
<td align="center">13</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/14</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">11</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.128.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Zawia, LY</td>
<td align="center">12</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.1.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">11</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Benghazi, LY</td>
<td align="center">2</td>
</tr>
</table>
<p><a name="malware_prefixes4">&nbsp;</a><br />
<strong>Update, March 7 (12:30 ET):</strong> Quick update of malware activity by AS over the past 24 hours. </p>
<table border="0" width="100%" cellspacing="1" cellpadding="2">
<tr valign="top">
<td width="20%" align="center"><strong>AS</strong></td>
<td width="20%" align="center"><strong>BGP IPv4 Prefix</strong></td>
<td width="20%" align="center"><strong>AS Name</strong></td>
<td width="20%" align="center"><strong>City</strong></td>
<td width="20%" align="center"><strong>Infected Host Count</strong></td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">37</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.192.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Benghazi, LY</td>
<td align="center">6</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.0.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Misratah, LY</td>
<td align="center">25</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.1.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">32</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/14</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">3</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.208.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">43</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.2.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">7</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.128.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Zawia, LY</td>
<td align="center">7</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.3.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">3</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">4</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">62.240.32.0/19</td>
<td align="center">GPTC-AS</td>
<td align="center">Sebha, LY</td>
<td align="center">5</td>
</tr>
</table>
<p><a name="malware_prefixes5">&nbsp;</a><br />
<strong>Update, March 18 (14:00 EDT):</strong> Follow-up update as the activity from Libya is still abnormal (activity over the past 24 hours).</p>
<table border="0" width="100%" cellspacing="1" cellpadding="2">
<tr valign="top">
<td width="20%" align="center"><strong>AS</strong></td>
<td width="20%" align="center"><strong>BGP IPv4 Prefix</strong></td>
<td width="20%" align="center"><strong>AS Name</strong></td>
<td width="20%" align="center"><strong>City</strong></td>
<td width="20%" align="center"><strong>Infected Host Count</strong></td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.208.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">45</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">62.68.32.0/19</td>
<td align="center">GPTC-AS</td>
<td align="center">-, LY</td>
<td align="center">9</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/14</td>
<td align="center">GPTC-AS</td>
<td align="center">-, LY</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.0.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">1</td>
</tr>
</table>
<p><a name="malware_prefixes6">&nbsp;</a><br />
<strong>Update, March 20 (00:00 EDT):</strong> Malware activity from Libya over the past 24 hours is predominantly concentrated within the 41.208.64.0/18 IPv4 Prefix.</p>
<table border="0" width="100%" cellspacing="1" cellpadding="2">
<tr valign="top">
<td width="20%" align="center"><strong>AS</strong></td>
<td width="20%" align="center"><strong>BGP IPv4 Prefix</strong></td>
<td width="20%" align="center"><strong>AS Name</strong></td>
<td width="20%" align="center"><strong>City</strong></td>
<td width="20%" align="center"><strong>Infected Host Count</strong></td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.208.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">207</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.1.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">6</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.0.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Misratah, LY</td>
<td align="center">3</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">62.240.32.0/19</td>
<td align="center">GPTC-AS</td>
<td align="center">-, LY</td>
<td align="center">10</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">7</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">62.68.32.0/19</td>
<td align="center">GPTC-AS</td>
<td align="center">-, LY</td>
<td align="center">7</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.128.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Zawia, LY</td>
<td align="center">2</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.3.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">3</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/14</td>
<td align="center">GPTC-AS</td>
<td align="center">-, LY</td>
<td align="center">2</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.2.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">1</td>
</tr>
</table>
<p><a name="malware_prefixes7">&nbsp;</a><br />
<strong>Update, March 21 (10:00 EDT):</strong> The 41.208.64.0/18 IPv4 Prefix continues emanate the majority of the malware activity.</p>
<table border="0" width="100%" cellspacing="1" cellpadding="2">
<tr valign="top">
<td width="20%" align="center"><strong>AS</strong></td>
<td width="20%" align="center"><strong>BGP IPv4 Prefix</strong></td>
<td width="20%" align="center"><strong>AS Name</strong></td>
<td width="20%" align="center"><strong>City</strong></td>
<td width="20%" align="center"><strong>Infected Host Count</strong></td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.208.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">-, LY</td>
<td align="center">159</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">12</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.1.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">3</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.0.0/14</td>
<td align="center">GPTC-AS</td>
<td align="center">-, LY</td>
<td align="center">7</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.252.64.0/18</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">2</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">62.240.32.0/19</td>
<td align="center">GPTC-AS</td>
<td align="center">-, LY</td>
<td align="center">4</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.2.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS21003</td>
<td align="center">41.254.3.0/24</td>
<td align="center">GPTC-AS</td>
<td align="center">Tripoli, LY</td>
<td align="center">1</td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.unveillance.com/latest-news/libyan-malware-activity-vanishes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Activity in Algeria Decreasing?</title>
		<link>http://www.unveillance.com/latest-news/malware-activity-in-algeria-decreasing/</link>
		<comments>http://www.unveillance.com/latest-news/malware-activity-in-algeria-decreasing/#comments</comments>
		<pubDate>Sun, 13 Feb 2011 10:48:44 +0000</pubDate>
		<dc:creator>oday</dc:creator>
				<category><![CDATA[Latest News]]></category>

		<guid isPermaLink="false">http://www.unveillance.com/?p=664</guid>
		<description><![CDATA[Conflicting reports about the internet in Algeria being cut or limited have been surfacing in the past several hours. Compare the malware activity for both Algeria and Egypt during times of civil unrest. var chart;$(document).ready(function() {chart = new Highcharts.Chart({chart: {renderTo: 'algeria_activity',defaultSeriesType: 'areaspline',marginBottom: 100},title: {text: 'Malware Activity from the Country of Algeria',x: -20},subtitle: {text: 'In UTC &#8230;]]></description>
			<content:encoded><![CDATA[<p>Conflicting reports about the internet in Algeria being cut or limited have been surfacing in the past several hours. Compare the malware activity for both Algeria and Egypt during times of civil unrest.</p>
<p><script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script><br />
<script type="text/javascript" src="/wp-content/highcharts/js/highcharts.js"></script></p>
<p><script type="text/javascript">
var chart;$(document).ready(function() {chart = new Highcharts.Chart({chart: {renderTo: 'algeria_activity',defaultSeriesType: 'areaspline',marginBottom: 100},title: {text: 'Malware Activity from the Country of Algeria',x: -20},subtitle: {text: 'In UTC Time',x: -20},xAxis: {categories: ['2/11 09:00','2/11 11:00','2/11 13:00','2/11 15:00','2/11 17:00','2/11 19:00','2/11 21:00','2/11 23:00','2/12 01:00','2/12 03:00','2/12 05:00','2/12 07:00','2/12 09:00','2/12 11:00','2/12 13:00','2/12 15:00','2/12 17:00','2/12 19:00','2/12 21:00','2/12 23:00','2/13 01:00','2/13 03:00','2/13 05:00','2/13 07:00','2/13 09:00','2/13 11:00','2/13 13:00','2/13 15:00','2/13 17:00','2/13 19:00','2/13 21:00','2/13 23:00','2/14 01:00','2/14 03:00','2/14 05:00'], labels: {rotation: -45, align: 'right', style: {font: 'normal 10px Verdana, sans-serif'}}},yAxis: {title: {text: ''},plotLines: [{value: 0,width: 1,color: '#808080'}]},plotOptions: {areaspline: {fillOpacity: 0.2}},tooltip: {formatter: function() {return '<b>'+ this.series.name +'</b><br/>'+this.x +': '+ this.y;}},series: [{name: 'Unique Host Count',data: [172,240,254,275,303,325,257,161,89,45,48,59,174,238,279,252,265,311,234,128,68,49,48,101,248,303,314,311,312,319,290,154,79,57,54]}, {name: 'Event Count',data: [287,422,447,494,547,573,482,315,161,81,93,99,287,428,497,451,494,563,448,248,125,85,81,170,456,563,554,624,598,580,609,328,146,105,104]}]});});
</script> </p>
<div id="algeria_activity" style="width: 880px; height: 400px; margin: 0 auto;"></div>
<p><script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script><br />
<script type="text/javascript" src="/wp-content/highcharts/js/highcharts.js"></script></p>
<p><script type="text/javascript">
var chart;$(document).ready(function() {chart = new Highcharts.Chart({chart: {renderTo: 'e2_malware_activity',defaultSeriesType: 'areaspline',marginBottom: 100},title: {text: 'Malware Activity from the Country of Egypt',x: -20},subtitle: {text: 'In UTC Time',x: -20},xAxis: {categories: ['1/27 02:00','1/27 03:00','1/27 04:00','1/27 05:00','1/27 06:00','1/27 07:00','1/27 08:00','1/27 09:00','1/27 10:00','1/27 11:00','1/27 12:00','1/27 13:00','1/27 14:00','1/27 15:00','1/27 16:00','1/27 17:00','1/27 18:00','1/27 19:00','1/27 20:00','1/27 21:00','1/27 22:00','1/27 23:00','1/28 00:00','1/28 01:00','1/28 02:00','1/28 03:00','1/28 04:00','1/28 05:00','1/28 06:00','1/28 07:00','1/28 08:00','1/28 09:00','1/28 10:00','1/28 11:00','1/28 12:00','1/28 13:00','1/28 14:00','1/28 15:00','1/28 16:00','1/28 17:00','1/28 18:00','1/28 19:00','1/28 20:00','1/28 21:00','1/28 22:00','1/28 23:00','1/29 00:00','1/29 01:00','1/29 02:00'], labels: {rotation: -45, align: 'right', style: {font: 'normal 10px Verdana, sans-serif'}}},yAxis: {title: {text: ''},plotLines: [{value: 0,width: 1,color: '#808080'}]},plotOptions: {areaspline: {fillOpacity: 0.2}},tooltip: {formatter: function() {return '<b>'+ this.series.name +'</b><br/>'+this.x +': '+ this.y;}},series: [{name: 'Unique Host Count',data: [1338,1093,1022,1122,1444,1898,2535,3242,3653,4083,4386,4339,4409,4496,4694,4754,4770,4851,4628,4398,3430,31,76,58,38,27,30,38,46,56,75,32,28,30,36,40,30,36,48,38,30,41,38,16,22,30,26,20,9]}, {name: 'Event Count',data: [2567,2031,1871,2035,2435,3346,4610,5808,6761,7401,8151,8083,8070,8364,8518,8697,8521,8683,8451,8314,8839,52,187,135,87,65,62,86,122,139,210,52,43,52,60,66,51,63,79,60,57,77,55,33,25,56,42,33,13]}]});});
</script> </p>
<div id="e2_malware_activity" style="width: 880px; height: 400px; margin: 0 auto;"></div>
<p>Below is a quick summary of the AS activity, per malware, seen as active in the past couple of days in Algeria.</p>
<phpcode>
<p><script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script><br />
<script type="text/javascript" src="/wp-content/highcharts/js/highcharts.js"></script></p>
<p><script> 
var chart;$(document).ready(function() {chart = new Highcharts.Chart({chart: {renderTo: 'bar_cont',defaultSeriesType: 'column',marginBottom: 100},title: {text: 'Algeria\'s Malware Activity by AS',x: -20},subtitle: {text: 'Infected Host Counts Since Late Feb. 11',x: -20},xAxis: {categories: ['AS36947', 'AS33774', 'AS3208', 'AS36879', 'AS36989', 'AS36891', 'AS36918', 'AS21391', 'AS3202'], labels: {align: 'center', style: {font: 'normal 12px Verdana, sans-serif'}}},yAxis: {title: {text: ''},plotLines: [{value: 0,width: 1,color: '#808080'}]},legend: {enabled: false},tooltip: {formatter: function() {return '<b>Infected Host Count</b><br/>'+this.x+': '+ this.y;}},series: [{name: '',data: [4748, 767, 10, 7, 5, 3, 2, 2, 1]}]});});
</script> </p>
<div id="bar_cont" style="width: 880px; height: 400px; margin: 0 auto"></div>
<table border="0" width="100%" cellspacing="1" cellpadding="2">
<tr valign="top">
<td width="25%" align="center"><strong>AS</strong></td>
<td width="25%" align="center"><strong>BGP IPv4 Prefix</strong></td>
<td width="25%" align="center"><strong>AS Name</strong></td>
<td width="25%" align="center"><strong>Infected Host Count</strong></td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.96.0.0/17</td>
<td align="center">FAWRI-AS</td>
<td align="center">355</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.97.64.0/18</td>
<td align="center">FAWRI-AS</td>
<td align="center">93</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.97.128.0/17</td>
<td align="center">FAWRI-AS</td>
<td align="center">518</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.98.0.0/17</td>
<td align="center">FAWRI-AS</td>
<td align="center">129</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.98.128.0/18</td>
<td align="center">FAWRI-AS</td>
<td align="center">107</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.98.192.0/18</td>
<td align="center">FAWRI-AS</td>
<td align="center">96</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.99.0.0/17</td>
<td align="center">FAWRI-AS</td>
<td align="center">498</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.100.64.0/18</td>
<td align="center">FAWRI-AS</td>
<td align="center">102</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.100.128.0/17</td>
<td align="center">FAWRI-AS</td>
<td align="center">335</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.101.0.0/17</td>
<td align="center">FAWRI-AS</td>
<td align="center">37</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.102.64.0/18</td>
<td align="center">FAWRI-AS</td>
<td align="center">50</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.102.128.0/17</td>
<td align="center">FAWRI-AS</td>
<td align="center">458</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.103.0.0/16</td>
<td align="center">FAWRI-AS</td>
<td align="center">136</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.104.0.0/16</td>
<td align="center">FAWRI-AS</td>
<td align="center">353</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.105.0.0/16</td>
<td align="center">FAWRI-AS</td>
<td align="center">268</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.106.0.0/16</td>
<td align="center">FAWRI-AS</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.107.0.0/17</td>
<td align="center">FAWRI-AS</td>
<td align="center">429</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.110.0.0/16</td>
<td align="center">FAWRI-AS</td>
<td align="center">71</td>
</tr>
<tr valign="top">
<td align="center">AS36879</td>
<td align="center">41.191.252.0/22</td>
<td align="center">SLC1-AS</td>
<td align="center">2</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.200.0.0/17</td>
<td align="center">FAWRI-AS</td>
<td align="center">225</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">41.200.5.0/24</td>
<td align="center">DJAWEB</td>
<td align="center">3</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.200.128.0/17</td>
<td align="center">FAWRI-AS</td>
<td align="center">327</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">41.201.0.0/19</td>
<td align="center">DJAWEB</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">41.201.32.0/19</td>
<td align="center">DJAWEB</td>
<td align="center">98</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">41.201.48.0/20</td>
<td align="center">DJAWEB</td>
<td align="center">85</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">41.201.64.0/19</td>
<td align="center">DJAWEB</td>
<td align="center">86</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">41.201.80.0/20</td>
<td align="center">DJAWEB</td>
<td align="center">56</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">41.201.96.0/20</td>
<td align="center">DJAWEB</td>
<td align="center">77</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.201.112.0/20</td>
<td align="center">FAWRI-AS</td>
<td align="center">71</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">41.201.168.0/21</td>
<td align="center">DJAWEB</td>
<td align="center">46</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">41.201.176.0/20</td>
<td align="center">DJAWEB</td>
<td align="center">91</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.201.192.0/21</td>
<td align="center">FAWRI-AS</td>
<td align="center">41</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">41.201.200.0/21</td>
<td align="center">DJAWEB</td>
<td align="center">31</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">41.201.208.0/20</td>
<td align="center">DJAWEB</td>
<td align="center">69</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">41.201.224.0/21</td>
<td align="center">DJAWEB</td>
<td align="center">10</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.201.232.0/21</td>
<td align="center">FAWRI-AS</td>
<td align="center">40</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">41.201.240.0/20</td>
<td align="center">DJAWEB</td>
<td align="center">64</td>
</tr>
<tr valign="top">
<td align="center">AS36989</td>
<td align="center">41.210.122.0/24</td>
<td align="center">ANWARNET</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS36989</td>
<td align="center">41.210.123.0/24</td>
<td align="center">ANWARNET</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS36989</td>
<td align="center">41.210.124.0/24</td>
<td align="center">ANWARNET</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS36989</td>
<td align="center">41.210.125.0/24</td>
<td align="center">ANWARNET</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS36989</td>
<td align="center">41.210.126.0/24</td>
<td align="center">ANWARNET</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS36947</td>
<td align="center">41.221.16.0/20</td>
<td align="center">FAWRI-AS</td>
<td align="center">8</td>
</tr>
<tr valign="top">
<td align="center">AS21391</td>
<td align="center">80.246.0.0/20</td>
<td align="center">TDA-AS</td>
<td align="center">2</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">80.249.64.0/20</td>
<td align="center">DJAWEB</td>
<td align="center">4</td>
</tr>
<tr valign="top">
<td align="center">AS3208</td>
<td align="center">193.194.69.0/24</td>
<td align="center">ARN</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS3202</td>
<td align="center">193.194.64.0/19</td>
<td align="center">St. Andrews University (SuperJANET SMDS)</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS3208</td>
<td align="center">193.194.80.0/24</td>
<td align="center">ARN</td>
<td align="center">2</td>
</tr>
<tr valign="top">
<td align="center">AS3208</td>
<td align="center">193.194.82.0/24</td>
<td align="center">ARN</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS3208</td>
<td align="center">193.194.84.0/24</td>
<td align="center">ARN</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS3208</td>
<td align="center">193.194.85.0/24</td>
<td align="center">ARN</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS3208</td>
<td align="center">193.194.87.0/24</td>
<td align="center">ARN</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS3208</td>
<td align="center">193.194.88.0/24</td>
<td align="center">ARN</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS3208</td>
<td align="center">193.194.92.0/24</td>
<td align="center">ARN</td>
<td align="center">2</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">196.20.64.0/18</td>
<td align="center">DJAWEB</td>
<td align="center">44</td>
</tr>
<tr valign="top">
<td align="center">AS33774</td>
<td align="center">196.20.95.0/24</td>
<td align="center">DJAWEB</td>
<td align="center">2</td>
</tr>
<tr valign="top">
<td align="center">AS36918</td>
<td align="center">196.29.40.0/22</td>
<td align="center">Orascom-Telecom-Algerie</td>
<td align="center">2</td>
</tr>
<tr valign="top">
<td align="center">AS36891</td>
<td align="center">196.41.225.0/24</td>
<td align="center">ICOSNET-AS</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS36891</td>
<td align="center">196.41.226.0/24</td>
<td align="center">ICOSNET-AS</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS36891</td>
<td align="center">196.41.229.0/24</td>
<td align="center">ICOSNET-AS</td>
<td align="center">1</td>
</tr>
<tr valign="top">
<td align="center">AS36879</td>
<td align="center">196.46.248.0/22</td>
<td align="center">SLC1-AS</td>
<td align="center">3</td>
</tr>
<tr valign="top">
<td align="center">AS36879</td>
<td align="center">196.46.252.0/22</td>
<td align="center">SLC1-AS</td>
<td align="center">2</td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.unveillance.com/latest-news/malware-activity-in-algeria-decreasing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

