Custom Search

Tuesday, September 30, 2014

Suspected Bot List [2014-09-29]

detection period: 2014-09-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 127

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.16.161.35Argentina
AR186.22.193.175Argentina
AR186.22.241.100Argentina
AR186.23.11.128Argentina
AR190.120.59.156Argentina
AR190.124.155.72Argentina
AU192.94.208.254Australia
BD203.76.147.70Bangladesh
BG78.128.22.134Bulgaria
CA64.39.165.52Canada
CL186.36.104.201Chile
CL190.120.169.196Chile
CL190.208.228.186Chile
CL190.209.183.181Chile
CO200.80.43.248Colombia
DE89.14.252.144Germany
EC181.112.33.69Ecuador
EC181.112.150.242Ecuador
EC186.47.232.178Ecuador
IN59.185.241.3India
IN106.197.33.10India
IN117.96.22.90India
IN117.218.50.134India
IN117.230.166.148India
IN117.249.218.48India
IN210.212.85.35India
IR91.98.147.62Iran
IR91.98.234.195Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT79.10.134.101Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
LK220.247.216.242Sri Lanka
MX201.161.130.76Mexico
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PL87.101.22.140Poland
PL95.160.12.231Poland
PL95.160.42.93Poland
PL95.160.68.142Poland
PL95.160.136.95Poland
PL95.160.177.29Poland
PT62.169.103.57Portugal
RU95.188.45.141Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
SE83.209.204.114Sweden
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US24.112.13.173United States
US24.112.18.252United States
US24.112.188.73United States
US24.154.236.162United States
US24.171.26.226United States
US24.183.164.80United States
US24.183.203.94United States
US24.207.213.64United States
US24.217.91.251United States
US24.217.156.57United States
US50.201.42.106United States
US65.184.46.166United States
US65.184.203.46United States
US65.185.104.25United States
US66.168.218.87United States
US66.190.171.102United States
US66.227.227.215United States
US68.114.255.8United States
US68.117.101.115United States
US68.184.61.35United States
US69.163.37.119United States
US71.8.124.217United States
US71.82.59.32United States
US71.83.75.47United States
US71.91.110.198United States
US71.95.211.121United States
US75.128.69.144United States
US75.130.192.33United States
US75.131.17.141United States
US75.135.3.237United States
US75.137.29.184United States
US75.137.69.178United States
US75.139.220.50United States
US75.141.103.25United States
US75.141.202.20United States
US96.39.187.235United States
US97.92.219.138United States
US97.92.221.89United States
US174.139.8.82United States
US204.116.60.250United States
UZ89.236.219.106Uzbekistan
VE186.24.43.3Venezuela
VE190.202.116.101Venezuela

List from greylisting:

Botnet Statistics [2014-09-29]

detection period: 2014-09-29 00:00-23:59 UTC
total number of suspected botnet IPs: 2778
number of botnet IPs notified to network operators: 2651
number of spam blocked: 162112
recipient count of spam blocked: 4515876

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1199
2CHINANET-JS225
3CHINANET-GD208
4CRTC81
5CHINANET-SN79
6CHINANET-LN68
7CHINANET-HB31
8CHINANET-HL30
9CHINANET-FJ30
10UNICOM-GD28

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1207
2China928
3United States163
4Brazil56
5Poland49
6Russian Federation36
7Germany34
8Indonesia22
9India18
10Ukraine17

Monday, September 29, 2014

Suspected Bot List [2014-09-28]

detection period: 2014-09-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 125

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AM178.78.184.66Armenia
AR181.16.178.73Argentina
AR181.177.16.75Argentina
AR186.22.83.14Argentina
AR186.22.104.45Argentina
AR186.22.109.44Argentina
AR186.22.193.175Argentina
AR186.23.40.87Argentina
AR186.23.89.47Argentina
AR190.6.214.160Argentina
AR190.11.121.53Argentina
AR190.13.115.240Argentina
AR190.106.82.139Argentina
AR190.115.124.30Argentina
AR190.221.104.213Argentina
AR200.50.186.43Argentina
BD203.76.147.70Bangladesh
CL181.73.75.223Chile
CL181.73.108.87Chile
CL181.74.240.93Chile
CL186.36.34.163Chile
CL186.36.118.184Chile
CL190.208.112.31Chile
CL190.209.57.20Chile
CL190.209.85.239Chile
CL190.209.141.29Chile
CO190.60.39.188Colombia
CO200.80.43.248Colombia
DE89.13.253.55Germany
EG62.117.58.109Egypt
ES87.111.171.16Spain
ES89.29.222.160Spain
IN59.93.122.243India
IN117.252.3.251India
IN117.254.182.167India
IN210.212.85.35India
IR91.98.147.62Iran
IR91.98.234.195Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT62.18.60.8Italy
IT62.18.141.73Italy
IT79.10.5.185Italy
IT79.47.24.99Italy
IT79.47.211.126Italy
IT82.61.124.179Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
LK220.247.216.242Sri Lanka
MX187.240.97.111Mexico
PE181.65.183.42Peru
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PL95.160.68.142Poland
PL95.160.90.193Poland
PL95.160.137.41Poland
PL95.160.177.29Poland
PL95.160.208.113Poland
PL95.160.220.125Poland
PL95.160.249.96Poland
PL213.92.170.104Poland
PL213.92.184.164Poland
PR196.42.50.102Puerto Rico
PT78.130.9.45Portugal
PT78.130.20.250Portugal
PT78.130.75.91Portugal
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US24.177.206.168United States
US24.207.213.64United States
US24.217.110.206United States
US24.231.226.69United States
US50.201.42.106United States
US65.28.87.9United States
US65.184.203.46United States
US65.191.250.21United States
US66.190.216.29United States
US68.114.254.192United States
US68.117.73.252United States
US68.117.101.115United States
US68.119.11.220United States
US68.184.59.98United States
US69.163.37.119United States
US71.83.75.47United States
US71.84.110.118United States
US71.91.110.198United States
US74.129.192.123United States
US74.132.159.99United States
US75.128.69.144United States
US75.131.17.141United States
US75.131.124.62United States
US75.135.3.237United States
US75.135.224.106United States
US75.139.220.50United States
US75.141.251.121United States
US75.142.145.240United States
US96.32.72.12United States
US96.39.187.235United States
UZ89.236.219.106Uzbekistan
VE190.202.116.101Venezuela

List from greylisting: