Custom Search

Wednesday, April 16, 2014

Suspected Bot List [2014-04-15]

detection period: 2014-04-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 92

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.17.36.83Argentina
BO190.129.12.162Bolivia
CO190.60.39.186Colombia
CZ80.188.121.251Czech Republic
HN190.107.140.77Honduras
ID27.131.4.6Indonesia
IN111.93.9.67India
IN117.239.241.147India
IN117.239.39.165India
IN122.160.239.46India
IN203.88.131.106India
IN203.90.114.228India
IN210.212.97.139India
IN223.226.28.86India
IN27.251.176.178India
IR91.98.36.84Iran
IT85.159.181.210Italy
IT95.227.34.226Italy
IT95.234.249.153Italy
MW105.234.255.2Malawi
MX187.240.114.239Mexico
MX201.158.203.50Mexico
NL93.174.95.82Netherlands
PH122.49.217.2Philippines
PH58.69.100.234Philippines
PK121.52.159.236Pakistan
RU5.19.221.219Russian Federation
SA94.77.199.148Saudi Arabia
SG116.251.217.213Singapore
TR193.255.143.62Turkey
TR193.255.143.63Turkey
TR195.226.221.155Turkey
TR195.244.39.195Turkey
US204.152.209.109United States
US204.195.104.31United States
US204.44.100.185United States
US209.58.205.18United States
US50.201.42.106United States
US69.64.48.57United States
US97.90.101.77United States
VE186.24.34.179Venezuela
VE190.111.122.3Venezuela
VE190.202.116.101Venezuela
ZA165.233.62.202South Africa
ZW41.220.28.138Zimbabwe

List from greylisting:

Botnet Statistics [2014-04-15]

detection period: 2014-04-15 00:00-23:59 UTC
total number of suspected botnet IPs: 1036
number of botnet IPs notified to network operators: 948
number of spam blocked: 58768
recipient count of spam blocked: 1907918

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD134
2CRTC75
3CHINANET-FJ38
4CHINANET-JS31
5CHINANET-SH22
6UNICOM-GD17
7HINET-NET13
8HICHINA12
9VNPT-VNNIC-VN11
10UNICOM-BJ11

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China495
2United States58
3Russian Federation48
4Brazil34
5Ukraine25
6Indonesia25
7India24
8Taiwan22
9Viet Nam19
10Italy18

Tuesday, April 15, 2014

Suspected Bot List [2014-04-14]

detection period: 2014-04-14 00:00-23:59 UTC
number of suspected bots' IPs listed here: 55

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.17.36.83Argentina
AR190.182.225.42Argentina
BD103.244.21.70Bangladesh
BO190.129.12.162Bolivia
BO190.129.58.252Bolivia
CO190.60.39.186Colombia
CZ80.188.121.251Czech Republic
EC186.42.225.189Ecuador
EG41.33.169.36Egypt
HN190.107.140.77Honduras
ID27.131.4.6Indonesia
IN111.93.9.67India
IN122.160.239.46India
IN202.62.67.250India
IN203.88.131.106India
IN203.90.114.228India
IN210.212.97.139India
IN223.226.28.86India
IN27.251.176.178India
IR91.98.36.84Iran
IT85.159.181.210Italy
IT95.227.34.226Italy
IT95.234.249.153Italy
IT95.253.67.148Italy
LV46.183.220.29Latvia
MW105.234.255.2Malawi
MX187.240.114.239Mexico
NL93.174.95.82Netherlands
PH122.49.217.2Philippines
PH58.69.100.234Philippines
PK121.52.159.236Pakistan
RS188.2.93.77Serbia
RU95.188.112.11Russian Federation
SA94.77.199.148Saudi Arabia
SG116.251.217.213Singapore
TR193.255.143.62Turkey
TR193.255.143.63Turkey
TR195.226.221.155Turkey
TR195.244.39.195Turkey
US204.152.209.109United States
US204.152.209.195United States
US204.195.104.31United States
US204.44.100.185United States
US209.58.205.18United States
US50.201.42.106United States
US69.64.48.57United States
US97.90.101.77United States
VE186.24.34.179Venezuela
VE190.111.122.3Venezuela
VE190.202.116.101Venezuela
VE201.209.187.170Venezuela
ZA165.233.62.202South Africa
ZW41.220.28.138Zimbabwe

List from greylisting: