Custom Search

Tuesday, June 27, 2017

Botnet Statistics [2017-06-26]

detection period: 2017-06-26 00:00-23:59 UTC
total number of suspected botnet IPs: 753
number of botnet IPs notified to network operators: 668
number of spam blocked: 78304
recipient count of spam blocked: 1640555

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-ZJ114
2CMNET114
3WASU98
4CUBEMOTION34
5RU-ANDERS-2008102829
6CHINANET-GD18
7VNPT-VNNIC-VN16
8SERVERYOU-NET-LAX16
9PL-ARTNET-2012070413
10VIRTONO-NETWORKS-SRL11

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China419
2United States102
3Viet Nam41
4Russian Federation40
5India24
6Poland17
7Romania15
8Brazil10
9Taiwan8
10Thailand7

Suspected Bot List [2017-06-26]

detection period: 2017-06-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 120

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
IN1.186.128.5India
IN122.179.15.42India
IN171.48.48.175India
IN182.73.244.70India
IN202.56.255.50India
IN202.142.81.58India
IN203.115.99.218India
IN203.115.109.254India
MO116.193.10.34Macau
MO116.193.10.35Macau
MX189.207.180.18Mexico
PL91.185.189.179Poland
RU37.1.46.238Russian Federation
RU80.254.115.87Russian Federation
RU84.53.192.243Russian Federation
RU109.194.197.79Russian Federation
RU176.118.237.85Russian Federation
RU185.127.25.68Russian Federation
RU185.130.104.198Russian Federation
RU212.164.221.82Russian Federation
RU213.183.45.226Russian Federation
RU213.183.45.227Russian Federation
RU213.183.45.228Russian Federation
RU213.183.45.229Russian Federation
RU213.183.45.230Russian Federation
RU213.183.45.232Russian Federation
RU213.183.45.233Russian Federation
RU213.183.45.234Russian Federation
RU213.183.45.235Russian Federation
RU213.183.45.236Russian Federation
RU213.183.45.237Russian Federation
RU213.183.45.238Russian Federation
RU213.183.45.239Russian Federation
RU213.183.45.240Russian Federation
RU213.183.45.241Russian Federation
RU213.183.45.242Russian Federation
RU213.183.45.243Russian Federation
RU213.183.45.244Russian Federation
RU213.183.45.245Russian Federation
RU213.183.45.246Russian Federation
RU213.183.45.247Russian Federation
RU213.183.45.248Russian Federation
RU213.183.45.249Russian Federation
RU213.183.45.250Russian Federation
RU213.183.45.251Russian Federation
RU213.183.45.252Russian Federation
RU213.183.45.253Russian Federation
RU213.183.45.254Russian Federation
TH103.40.132.18Thailand
TH122.155.197.9Thailand
TH203.151.206.113Thailand
US50.2.13.2United States
US50.2.13.5United States
US50.2.13.7United States
US50.2.13.8United States
US50.2.13.10United States
US50.2.13.12United States
US50.2.13.14United States
US206.125.41.139United States
VE150.187.41.90Venezuela
ZA196.46.23.122South Africa

List from greylisting:

Monday, June 26, 2017

Botnet Statistics [2017-06-25]

detection period: 2017-06-25 00:00-23:59 UTC
total number of suspected botnet IPs: 577
number of botnet IPs notified to network operators: 539
number of spam blocked: 67821
recipient count of spam blocked: 980661

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET101
2WASU76
3UNICOM-ZJ66
4CHINANET-GD32
5VNPT-VNNIC-VN26
6CC-1521
7UK-RAPIDSWITCH-2007041813
8HOSTKEY-NET13
9CUBEMOTION13
10ALISOFT12

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China350
2United States50
3Viet Nam46
4United Kingdom17
5Taiwan13
6Netherlands13
7Brazil7
8Romania5
9Argentina5
10Russian Federation4