Custom Search

Tuesday, December 12, 2017

Botnet Statistics [2017-12-11]

detection period: 2017-12-11 00:00-23:59 UTC
total number of suspected botnet IPs: 313
number of botnet IPs notified to network operators: 244
number of spam blocked: 57173
recipient count of spam blocked: 1380124

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1MSFT57
2CHINANET-HB34
3CHINANET-GD25
4WASU21
5Baidu18
6CHINANET-ZJ-HZ17
7CHINANET-JS16
8VNPT-VNNIC-VN11
9HOSTWINDS-17-610
10CHINANET-ZJ5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China158
2United States72
3Viet Nam17
4Brazil9
5Spain5
6Czech Republic5
7Italy4
8Germany4
9India3
10Slovakia2

Suspected Bot List [2017-12-11]

detection period: 2017-12-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 69

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
CZ185.82.212.95Czech Republic
KG31.135.255.209Kyrgyzstan
RU95.68.240.209Russian Federation
US23.129.64.101United States
US23.129.64.102United States
ZA196.46.23.122South Africa

List from greylisting:

Monday, December 11, 2017

Botnet Statistics [2017-12-10]

detection period: 2017-12-10 00:00-23:59 UTC
total number of suspected botnet IPs: 281
number of botnet IPs notified to network operators: 272
number of spam blocked: 72004
recipient count of spam blocked: 1579249

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD34
2CHINANET-HB29
3VNPT-VNNIC-VN24
4CHINANET-ZJ-HZ18
5Baidu18
6CHINANET-JS16
7UNICOM-GD8
8CHINANET-ZJ8
9FPT-VN7
10WASU4

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China158
2Viet Nam44
3Brazil16
4United States7
5Germany5
6Russian Federation4
7Czech Republic4
8Netherlands3
9South Korea3
10Spain3