Introduction

As security professionals we always are asked how large is the population of an infection. Conficker is no different from any other, and it seems that everyone wants to have some value to use for many different purposes. The press for impact, some vendors for FUD, and others to have a number to compare to other infections. The bottom line is that no one can give an exact number on any infection ever. If anyone ever states exact numbers, they either are controlling it, or are not being completely honest to themselves or others on the means of data collection. We can estimate a number based off of certain traffic types, but we make mistakes as often as anyone else. A lot of the malicious traffic can resemble other legitimate or malicious traffic which of course skews the numbers. On top of simple traffic analysis each threat provides its own unique mechanisms for tracking infection statistics. Each of these methods of course come with their own positives and negatives when discussing accuracy of the data. It is what that in mind that we wanted attempt to draw out some of the pro's and con's of our data collection methodology below.

So, it is with a lot of trepidation that we even show any values for conficker knowing that they will most likely be taken out of context and quoted by many.

Population Numbers

What the following tables show are the daily connections and unique IP's that have been connecting to our tracking systems. Many people equate one IP to one system, but that is not usually the case. If the system is behind a NAT gateway, it would represent dozens or hundreds of systems. If a system is mobile it could be reported several times in a single day under different IP's. And in today's world there are a very large number of mobile users which could inflate the number of connections and unique IP's that are tracked.

What does this really mean? The daily numbers should represent the potential maximum level of the infection, but in previous test cases usually prove to be much less than that maximum. So, take the range of 25% to 75% of the values that we display as the possible infection population and you will be close to the real value. And yes, this is a very large range, and you can see why we do not like to quote any numbers for infection populations, and why you will see very high and low numbers get quoted regularly depending on the purpose of the person making the quote.

One last note: we are publishing these numbers to give a better understanding of what we are tracking. We do not believe in shaming anyone related to these values, and is not our purpose in any way.

Data Details

These tables are updated daily from the tracking systems. They are updated only once a day.

Conficker A+B

These tables are specifically for the A+B infections.

Day        Date        Total HTTP Hits  Unique IP's  Unique ASN's  Unique GEO's
Sunday     2014-04-20      273,411,120      915,001        12,457           223
Saturday   2014-04-19      322,209,275    1,032,528        12,803           223
Friday     2014-04-18      342,517,513    1,078,817        13,276           224
Thursday   2014-04-17      359,976,294    1,188,883        13,697           224
Wednesday  2014-04-16      383,342,911    1,240,669        13,832           224
Tuesday    2014-04-15      390,469,406    1,248,561        13,892           223
Monday     2014-04-14      375,405,838    1,228,810        13,859           226
Sunday     2014-04-13      300,410,527      972,368        12,719           223
Saturday   2014-04-12      341,523,098    1,100,807        13,017           225
Friday     2014-04-11      372,029,952    1,241,774        13,804           229
Thursday   2014-04-10      394,069,079    1,268,212        13,901           227
Wednesday  2014-04-09      357,934,587    1,252,458        13,863           228
Tuesday    2014-04-08      394,811,879    1,286,289        13,971           227
Monday     2014-04-07      362,683,456    1,242,591        13,879           226
Sunday     2014-04-06      314,492,844      990,143        12,798           222
Saturday   2014-04-05      330,557,334    1,105,548        13,022           224
Friday     2014-04-04      377,215,472    1,255,590        13,875           227
Thursday   2014-04-03      389,369,042    1,287,409        14,002           224
Wednesday  2014-04-02      358,701,497    1,281,685        13,945           224
Tuesday    2014-04-01      371,356,782    1,300,860        13,945           224
Monday     2014-03-31      349,892,808    1,277,911        13,908           226
Sunday     2014-03-30      300,492,314    1,017,186        12,785           222
Saturday   2014-03-29      316,527,764    1,143,487        13,036           223
Friday     2014-03-28      368,691,705    1,278,886        13,895           223
Thursday   2014-03-27      361,277,840    1,305,328        14,037           226
Wednesday  2014-03-26      397,640,024    1,315,126        14,025           225
Tuesday    2014-03-25      402,816,586    1,318,965        13,999           224
Monday     2014-03-24      404,300,282    1,294,309        13,971           224
Sunday     2014-03-23      331,233,736    1,012,833        12,826           221
Saturday   2014-03-22      363,338,722    1,138,345        13,058           222

This chart shows the rate of IP's being seen over time.

90-Day

180-Day

Year

Conficker C

These tables are specifically for the C infections

Day        Date        Total HTTP Hits  Unique IP's  Unique ASN's  Unique GEO's
Sunday     2014-04-20                                                          
Saturday   2014-04-19                                                          
Friday     2014-04-18                                                          
Thursday   2014-04-17                                                          
Wednesday  2014-04-16                                                          
Tuesday    2014-04-15                                                          
Monday     2014-04-14                                                          
Sunday     2014-04-13                                                          
Saturday   2014-04-12                                                          
Friday     2014-04-11                                                          
Thursday   2014-04-10                                                          
Wednesday  2014-04-09                                                          
Tuesday    2014-04-08                                                          
Monday     2014-04-07                                                          
Sunday     2014-04-06                                                          
Saturday   2014-04-05                                                          
Friday     2014-04-04                                                          
Thursday   2014-04-03                                                          
Wednesday  2014-04-02                                                          
Tuesday    2014-04-01                                                          
Monday     2014-03-31                                                          
Sunday     2014-03-30                                                          
Saturday   2014-03-29                                                          
Friday     2014-03-28                                                          
Thursday   2014-03-27                                                          
Wednesday  2014-03-26                                                          
Tuesday    2014-03-25                                                          
Monday     2014-03-24                                                          
Sunday     2014-03-23                                                          
Saturday   2014-03-22                                                          

This chart shows the rate of IP's being seen over time. Because of the great difference between the daily totals and the hourly, we are using two Y-Axis values. The Y-Axis on the left is for the daily totals, while the one on the right s for both the hourly lines.

90-Day

180-Day

Year

Conficker A+B+C

This data set is the aggregate of all the conficker infections for today.

Day        Date        Total HTTP Hits  Unique IP's  Unique ASN's  Unique GEO's
Sunday     2014-04-20      273,411,120      915,001        12,457           223
Saturday   2014-04-19      322,209,275    1,032,528        12,803           223
Friday     2014-04-18      342,517,513    1,078,817        13,276           224
Thursday   2014-04-17      359,976,294    1,188,883        13,697           224
Wednesday  2014-04-16      383,342,911    1,240,669        13,832           224
Tuesday    2014-04-15      390,469,406    1,248,561        13,892           223
Monday     2014-04-14      375,405,838    1,228,810        13,859           226
Sunday     2014-04-13      300,410,527      972,368        12,719           223
Saturday   2014-04-12      341,523,098    1,100,807        13,017           225
Friday     2014-04-11      372,029,952    1,241,774        13,804           229
Thursday   2014-04-10      394,069,079    1,268,212        13,901           227
Wednesday  2014-04-09      357,934,587    1,252,458        13,863           228
Tuesday    2014-04-08      394,811,879    1,286,289        13,971           227
Monday     2014-04-07      362,683,456    1,242,591        13,879           226
Sunday     2014-04-06      314,492,844      990,143        12,798           222
Saturday   2014-04-05      330,557,334    1,105,548        13,022           224
Friday     2014-04-04      377,215,472    1,255,590        13,875           227
Thursday   2014-04-03      389,369,042    1,287,409        14,002           224
Wednesday  2014-04-02      358,701,497    1,281,685        13,945           224
Tuesday    2014-04-01      371,356,782    1,300,860        13,945           224
Monday     2014-03-31      349,892,808    1,277,911        13,908           226
Sunday     2014-03-30      300,492,314    1,017,186        12,785           222
Saturday   2014-03-29      316,527,764    1,143,487        13,036           223
Friday     2014-03-28      368,691,705    1,278,886        13,895           223
Thursday   2014-03-27      361,277,840    1,305,328        14,037           226
Wednesday  2014-03-26      397,640,024    1,315,126        14,025           225
Tuesday    2014-03-25      402,816,586    1,318,965        13,999           224
Monday     2014-03-24      404,300,282    1,294,309        13,971           224
Sunday     2014-03-23      331,233,736    1,012,833        12,826           221
Saturday   2014-03-22      363,338,722    1,138,345        13,058           222

90-Day

180-Day

Year

ASN Statistics

These charts represent how many ASN's are effected during the period of the graph.

90-Day

180-Day

Year

Country Statistics

These charts represent how many countries are effected during the period of the graph.

90-Day

180-Day

Year

HTTP Hit Statistics

These charts show how many daily hits from Conficker systems that we are seeing during the period of the graphs. While this is not really representative of an infection population, it does show the level of work that the Conficker Working Group must do daily in dealing with the level of events from Conficker.

90-Day

180-Day

Year