Custom Search

Saturday, May 25, 2013

Suspected Bot List [2013-05-24]

detection period: 2013-05-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 437

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE194.170.149.22Arab Emirates
AL82.114.70.102Albania
AM46.162.230.50Armenia
AO41.63.166.3Angola
BD180.211.179.30Bangladesh
BO200.119.200.131Bolivia
BR150.161.30.7Brazil
BR177.137.0.123Brazil
BY213.184.241.88Belarus
CI213.136.105.210Ivory Coast
CR190.10.122.121Costa Rica
CZ80.188.2.54Czech Republic
DE84.11.89.66Germany
ES212.49.136.26Spain
ES213.0.89.6Spain
ES217.16.255.159Spain
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IL82.102.158.5Israel
IN49.128.162.50India
IN111.93.108.194India
IN115.115.142.54India
IN117.218.129.170India
IN117.240.239.120India
IN118.94.179.98India
IN122.180.71.10India
IN122.180.96.110India
IN122.183.99.146India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IQ95.159.105.2Iraq
IQ109.224.20.138Iraq
IR82.99.246.10Iran
IR89.165.109.165Iran
IR194.33.126.10Iran
IR212.16.76.162Iran
IT93.88.37.10Italy
IT149.139.10.132Italy
JO87.236.232.231Jordan
JO109.107.132.172Jordan
KW62.150.12.46Kuwait
KW213.132.241.7Kuwait
LB212.36.193.188Lebanon
LB213.175.188.158Lebanon
MV202.21.182.26Republic of Maldives
MX148.204.14.253Mexico
MX148.208.224.251Mexico
MX177.224.19.159Mexico
MX177.224.245.64Mexico
MX177.228.74.25Mexico
MX177.228.75.63Mexico
MX187.162.207.98Mexico
MX189.194.170.198Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX201.132.167.105Mexico
MX201.159.106.90Mexico
NG41.223.65.101Nigeria
NI186.1.10.154Nicaragua
PA190.33.184.107Panama
PG180.150.252.66New Guinea
PH112.199.89.158Philippines
PH121.97.26.86Philippines
PH202.86.204.202Philippines
PK61.5.156.196Pakistan
PK111.68.104.132Pakistan
PK124.109.47.66Pakistan
PK202.69.40.170Pakistan
PK202.69.45.52Pakistan
RO89.120.75.51Romania
RO91.220.26.4Romania
RS178.149.63.175Serbia
RS178.149.182.28Serbia
RU81.24.85.98Russian Federation
SA94.77.199.148Saudi Arabia
SE46.246.28.47Sweden
SK93.184.71.66Slovakia
TN41.230.10.190Tunisia
TR82.222.189.43Turkey
TR193.255.143.63Turkey
TW36.226.0.6Taiwan
TW36.226.0.174Taiwan
TW36.226.0.232Taiwan
TW61.228.0.192Taiwan
TW180.218.233.132Taiwan
TW220.137.0.122Taiwan
UA91.212.124.153Ukraine
UA178.151.68.210Ukraine
UA178.151.86.1Ukraine
US50.192.170.241United States
US50.194.150.131United States
US66.190.188.60United States
US96.32.107.166United States
US108.163.195.37United States
US192.161.54.12United States
US192.211.58.108United States
US198.154.60.221United States
US199.193.66.161United States
US206.217.198.12United States
US209.239.112.104United States
VE190.93.44.76Venezuela
ZW41.57.125.190Zimbabwe
ZW41.57.127.4Zimbabwe

List from greylisting:

Botnet Statistics [2013-05-24]

detection period: 2013-05-24 00:00-23:59 UTC
total number of suspected botnet IPs: 9216
number of botnet IPs notified to network operators: 8790
number of spam blocked: 102589
recipient count of spam blocked: 3086617

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-HA1819
2CHINANET-HB1486
3UNICOM-HB1225
4CHINANET-HE921
5HINET-NET461
6UNICOM-HN243
7CHINANET-HA223
8CHINANET-GD219
9CTTNET123
10CRTC94

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China7107
2Taiwan483
3United States434
4Brazil100
5Russian Federation85
6India73
7Spain55
8Argentina48
9Germany45
10Iran44

Friday, May 24, 2013

Suspected Bot List [2013-05-23]

detection period: 2013-05-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 355

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE194.170.149.22Arab Emirates
AL82.114.70.102Albania
AM46.162.230.50Armenia
AO196.223.13.230Angola
BG212.73.156.197Bulgaria
BO200.119.200.131Bolivia
BO201.222.117.26Bolivia
BR150.161.30.7Brazil
BR177.137.0.123Brazil
BY213.184.241.88Belarus
CA198.50.166.144Canada
CI213.136.105.210Ivory Coast
CO190.0.60.238Colombia
DE84.11.89.66Germany
ES212.49.136.26Spain
ES213.0.89.6Spain
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
GT200.30.165.178Guatemala
HN190.107.140.77Honduras
IL82.102.158.5Israel
IN27.49.107.83India
IN59.96.66.2India
IN117.239.29.114India
IN117.240.239.120India
IN117.244.15.245India
IN118.94.179.98India
IN122.180.71.10India
IN122.180.96.110India
IN122.183.99.146India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IQ95.159.105.2Iraq
IQ109.224.20.138Iraq
IR89.165.109.165Iran
IR94.183.138.253Iran
IR212.16.76.162Iran
IT91.214.62.59Italy
IT149.139.10.132Italy
JO87.236.232.231Jordan
JO109.107.132.172Jordan
KW213.132.241.7Kuwait
KZ91.185.21.34Kazakhstan
LB212.36.193.188Lebanon
LB213.175.188.158Lebanon
MV202.21.182.26Republic of Maldives
MX148.204.14.253Mexico
MX177.224.19.159Mexico
MX177.228.74.25Mexico
MX177.228.75.63Mexico
MX187.162.207.98Mexico
MX187.247.92.77Mexico
MX189.194.170.198Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX200.57.144.81Mexico
MX201.132.167.105Mexico
MX201.159.106.90Mexico
MX201.164.163.184Mexico
NG41.223.65.101Nigeria
NI186.1.10.154Nicaragua
PG180.150.252.66New Guinea
PH121.97.26.86Philippines
PH202.86.204.202Philippines
PH202.124.193.11Philippines
PK61.5.156.196Pakistan
PK111.68.104.132Pakistan
PK124.109.47.66Pakistan
PK125.209.67.38Pakistan
PK202.69.40.170Pakistan
PK202.69.45.52Pakistan
PK202.142.158.122Pakistan
RO89.120.75.51Romania
RO91.220.26.4Romania
RS178.149.63.175Serbia
RS178.149.182.28Serbia
RU81.24.85.98Russian Federation
RU194.24.241.235Russian Federation
SA94.77.199.148Saudi Arabia
SA212.138.144.5Saudi Arabia
SV190.150.101.13El Salvador
TN41.230.10.190Tunisia
TR82.222.189.43Turkey
TR193.255.143.62Turkey
TW61.228.0.228Taiwan
UA91.212.124.153Ukraine
UA178.151.68.210Ukraine
UA178.151.86.1Ukraine
UNKNOWN190.52.205.5UNKNOWN
US50.194.150.131United States
US66.190.188.60United States
US108.163.195.37United States
US173.184.189.237United States
US192.161.54.12United States
US192.211.58.108United States
US198.154.60.221United States
US199.193.66.161United States
US207.157.71.132United States
US209.239.112.104United States
VE190.93.44.76Venezuela
ZW41.57.125.190Zimbabwe
ZW41.57.127.4Zimbabwe

List from greylisting: