Custom Search

Friday, January 31, 2014

Suspected Bot List [2014-01-30]

detection period: 2014-01-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 145

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR200.63.164.22Argentina
BG93.183.155.80Bulgaria
BO190.129.12.162Bolivia
CN150.255.100.224China
GB193.164.207.16United Kingdom
HN190.107.140.76Honduras
IN117.203.143.59India
IN117.240.239.120India
IN122.160.239.39India
IR91.98.117.28Iran
IR94.182.248.19Iran
LB213.175.188.158Lebanon
MO60.246.133.78Macau
MX187.174.173.18Mexico
MX189.204.49.66Mexico
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
TW119.77.133.98Taiwan
TW119.77.158.102Taiwan
TW119.77.215.247Taiwan
TW119.77.224.212Taiwan
TW119.77.246.78Taiwan
UA195.66.204.70Ukraine
US50.201.42.106United States
US74.222.3.249United States
VE190.39.82.232Venezuela

List from greylisting:

Botnet Statistics [2014-01-30]

detection period: 2014-01-30 00:00-23:59 UTC
total number of suspected botnet IPs: 7383
number of botnet IPs notified to network operators: 7238
number of spam blocked: 124023
recipient count of spam blocked: 2942059

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET624
2UNICOM-SD591
3CHINANET-JS414
4UNICOM-HA358
5UNICOM-HE353
6UNICOM-LN285
7CRTC259
8CHINANET-GD227
9UNICOM-HL188
10UNICOM-SX181

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China6566
2Taiwan157
3United States74
4France57
5United Kingdom51
6India28
7Brazil27
8Peru25
9Russian Federation20
10Indonesia20

Thursday, January 30, 2014

Suspected Bot List [2014-01-29]

detection period: 2014-01-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 247

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR200.63.164.22Argentina
BG93.183.155.80Bulgaria
BO190.129.12.162Bolivia
GB193.164.207.16United Kingdom
HN190.107.140.76Honduras
IN117.240.239.120India
IN122.160.239.39India
IN202.62.67.250India
IR91.98.117.28Iran
IR94.182.248.19Iran
LB213.175.188.158Lebanon
MX187.174.173.18Mexico
MX189.204.49.66Mexico
PK115.186.59.70Pakistan
PK210.2.170.42Pakistan
RU193.107.17.55Russian Federation
SA94.77.199.148Saudi Arabia
US50.201.42.106United States
US74.222.3.249United States
VE190.39.82.232Venezuela

List from greylisting:

Botnet Statistics [2014-01-29]

detection period: 2014-01-29 00:00-23:59 UTC
total number of suspected botnet IPs: 2511
number of botnet IPs notified to network operators: 2264
number of spam blocked: 65998
recipient count of spam blocked: 1795451

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-SD105
2CMNET105
3HINET-NET95
4CHINANET-JS79
5CHINANET-GD73
6CRTC72
7UNICOM-HA65
8UNICOM-LN61
9UNICOM-HE50
10CHINANET-XJ46

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1401
2Taiwan120
3India72
4United States64
5France57
6United Kingdom48
7Brazil41
8Indonesia39
9Singapore35
10Kazakhstan31

Wednesday, January 29, 2014

Suspected Bot List [2014-01-28]

detection period: 2014-01-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 104

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR200.63.164.22Argentina
BO190.129.12.162Bolivia
GB193.164.207.16United Kingdom
IN117.240.239.120India
IN122.160.239.39India
IN182.74.135.74India
IN202.62.67.250India
IR91.98.117.28Iran
IR94.182.248.19Iran
LB213.175.188.158Lebanon
MX187.174.173.18Mexico
PK115.186.59.70Pakistan
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
TW119.77.158.102Taiwan
UA195.66.204.70Ukraine
US50.201.42.106United States
US74.222.3.249United States

List from greylisting:

Botnet Statistics [2014-01-28]

detection period: 2014-01-28 00:00-23:59 UTC
total number of suspected botnet IPs: 1695
number of botnet IPs notified to network operators: 1591
number of spam blocked: 50633
recipient count of spam blocked: 1504334

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET125
2CHINANET-GD91
3UNICOM-SD83
4HINET-NET65
5CHINANET-JS61
6CRTC58
7UNICOM-LN56
8UNICOM-HE49
9UNICOM-HA41
10UNICOM-JL33

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1104
2Taiwan80
3United States49
4Brazil37
5United Kingdom27
6France27
7Italy20
8India19
9Russian Federation18
10Spain18

Tuesday, January 28, 2014

Suspected Bot List [2014-01-27]

detection period: 2014-01-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 150

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR200.63.164.22Argentina
BO190.129.12.162Bolivia
ES188.87.211.12Spain
GB193.164.207.16United Kingdom
IN117.240.239.120India
IN122.160.239.39India
IN182.74.135.74India
IN202.62.67.250India
IR91.98.117.28Iran
IR94.182.248.19Iran
LB213.175.188.158Lebanon
MO60.246.149.176Macau
MX187.174.173.18Mexico
PK115.186.59.70Pakistan
PK210.2.170.42Pakistan
RU193.107.17.55Russian Federation
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
UA195.66.204.70Ukraine
US50.201.42.106United States
US74.222.3.249United States

List from greylisting:

Botnet Statistics [2014-01-27]

detection period: 2014-01-27 00:00-23:59 UTC
total number of suspected botnet IPs: 3551
number of botnet IPs notified to network operators: 3401
number of spam blocked: 74449
recipient count of spam blocked: 1908724

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET298
2UNICOM-SD213
3CRTC143
4CHINANET-JS143
5CHINANET-GD127
6UNICOM-HE125
7UNICOM-LN106
8UNICOM-HL101
9UNICOM-JL95
10UNICOM-HA91

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2642
2Taiwan99
3United States98
4France79
5United Kingdom62
6India41
7Italy26
8Brazil25
9Mexico23
10Colombia20

Monday, January 27, 2014

Suspected Bot List [2014-01-26]

detection period: 2014-01-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 63

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR200.63.164.22Argentina
BO190.129.12.162Bolivia
CN150.255.205.136China
ES188.87.211.12Spain
GB193.164.207.16United Kingdom
IN117.218.13.176India
IN117.240.239.120India
IN122.160.239.39India
IN182.74.135.74India
IN202.62.67.250India
IR91.98.117.28Iran
IR94.182.248.19Iran
LB213.175.188.158Lebanon
MO60.246.180.199Macau
MX187.174.173.18Mexico
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
TW61.64.27.123Taiwan
TW119.77.237.2Taiwan
US50.201.42.106United States
US74.222.3.249United States

List from greylisting:

Botnet Statistics [2014-01-26]

detection period: 2014-01-26 00:00-23:59 UTC
total number of suspected botnet IPs: 3689
number of botnet IPs notified to network operators: 3626
number of spam blocked: 92581
recipient count of spam blocked: 2286264

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET316
2UNICOM-SD274
3CHINANET-JS184
4CHINANET-GD154
5CRTC150
6UNICOM-HE147
7UNICOM-LN141
8UNICOM-HA139
9UNICOM-HL107
10CHINANET-XJ107

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China3315
2Taiwan104
3Brazil26
4United States24
5Italy16
6United Kingdom16
7Ukraine13
8Indonesia13
9India12
10Germany11

Sunday, January 26, 2014

Suspected Bot List [2014-01-25]

detection period: 2014-01-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 42

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR200.63.164.22Argentina
BG46.55.147.50Bulgaria
BG93.183.155.80Bulgaria
BO190.129.12.162Bolivia
ES188.87.211.12Spain
GB193.164.207.16United Kingdom
HN190.107.140.76Honduras
IN117.218.13.176India
IN117.240.239.120India
IN122.160.239.39India
IN182.74.135.74India
IN202.62.67.250India
IR91.98.117.28Iran
IR94.182.248.19Iran
LB213.175.188.158Lebanon
MO60.246.147.49Macau
MO60.246.163.224Macau
MX187.174.173.18Mexico
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
UA195.66.204.70Ukraine
US50.201.42.106United States
US74.222.3.249United States

List from greylisting:

Botnet Statistics [2014-01-25]

detection period: 2014-01-25 00:00-23:59 UTC
total number of suspected botnet IPs: 3336
number of botnet IPs notified to network operators: 3294
number of spam blocked: 51022
recipient count of spam blocked: 1525992

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET339
2UNICOM-SD213
3CRTC188
4CHINANET-GD150
5CHINANET-JS146
6UNICOM-HE140
7UNICOM-HA114
8UNICOM-LN107
9HINET-NET103
10UNICOM-JL94

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2965
2Taiwan125
3Brazil25
4United States19
5Indonesia15
6Russian Federation14
7Ukraine12
8Iran11
9Germany11
10India10

Saturday, January 25, 2014

Suspected Bot List [2014-01-24]

detection period: 2014-01-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 191

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR200.63.164.22Argentina
BG93.183.155.80Bulgaria
BO190.129.12.162Bolivia
CN150.255.193.236China
ES188.87.211.12Spain
GB193.164.207.16United Kingdom
HN190.107.140.76Honduras
IN117.240.239.120India
IN122.160.239.39India
IN182.74.135.74India
IN202.62.67.250India
IR91.98.117.28Iran
IR94.182.248.19Iran
LB213.175.188.158Lebanon
MO60.246.183.43Macau
MX187.174.173.18Mexico
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
TW119.77.214.39Taiwan
UA195.66.204.70Ukraine
US50.201.42.106United States
US74.222.3.249United States

List from greylisting:

Botnet Statistics [2014-01-24]

detection period: 2014-01-24 00:00-23:59 UTC
total number of suspected botnet IPs: 3579
number of botnet IPs notified to network operators: 3388
number of spam blocked: 50587
recipient count of spam blocked: 1580958

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET283
2CRTC168
3UNICOM-SD156
4CHINANET-GD148
5CHINANET-JS146
6HINET-NET129
7UNICOM-HE112
8UNICOM-HA106
9UNICOM-LN76
10CHINANET-XJ70

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2471
2Taiwan163
3United States80
4India80
5France63
6United Kingdom42
7Indonesia39
8Italy38
9Singapore35
10Viet Nam28

Friday, January 24, 2014

Suspected Bot List [2014-01-23]

detection period: 2014-01-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 178

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR200.63.164.22Argentina
BG46.55.147.50Bulgaria
BO190.129.12.162Bolivia
CN150.255.247.128China
ES188.87.211.12Spain
GB193.164.207.16United Kingdom
IN117.203.136.244India
IN117.239.29.114India
IN117.240.239.120India
IN122.160.239.39India
IN182.74.135.74India
IN202.62.67.250India
IR94.182.248.19Iran
IT95.227.34.226Italy
LB213.175.188.158Lebanon
MO60.246.154.115Macau
MX187.174.173.18Mexico
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
UA195.66.204.70Ukraine
US50.201.42.106United States
US74.222.3.249United States

List from greylisting:

Botnet Statistics [2014-01-23]

detection period: 2014-01-23 00:00-23:59 UTC
total number of suspected botnet IPs: 3519
number of botnet IPs notified to network operators: 3341
number of spam blocked: 54788
recipient count of spam blocked: 1596032

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET281
2UNICOM-SD169
3CRTC167
4CHINANET-GD129
5CHINANET-JS126
6UNICOM-HE118
7UNICOM-LN101
8UNICOM-HA98
9HINET-NET96
10UNICOM-HL75

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2523
2Taiwan126
3United States96
4France83
5United Kingdom70
6India52
7Italy28
8Brazil28
9South Korea25
10Indonesia23

Thursday, January 23, 2014

Suspected Bot List [2014-01-22]

detection period: 2014-01-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 108

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.15.201.202Argentina
BG46.55.147.50Bulgaria
BO190.129.12.162Bolivia
CO190.90.2.30Colombia
ES188.87.211.12Spain
GB193.164.207.16United Kingdom
HN190.107.140.76Honduras
IN117.239.29.114India
IN117.240.239.120India
IN122.160.239.39India
IN182.74.135.74India
IN202.63.105.226India
IR91.98.117.28Iran
IR94.182.248.19Iran
IT95.227.34.226Italy
MO60.246.155.71Macau
MX187.174.173.18Mexico
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
US50.201.42.106United States
US74.222.3.249United States

List from greylisting:

Botnet Statistics [2014-01-22]

detection period: 2014-01-22 00:00-23:59 UTC
total number of suspected botnet IPs: 2425
number of botnet IPs notified to network operators: 2317
number of spam blocked: 44257
recipient count of spam blocked: 1390357

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET190
2UNICOM-SD129
3CRTC107
4CHINANET-JS99
5UNICOM-HE76
6UNICOM-LN75
7HINET-NET62
8CHINANET-GD61
9UNICOM-HA57
10UNICOM-HL54

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1720
2United States82
3Taiwan81
4France56
5United Kingdom44
6Brazil32
7India29
8Russian Federation23
9Colombia20
10Mexico19

Wednesday, January 22, 2014

Suspected Bot List [2014-01-21]

detection period: 2014-01-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 200

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.15.201.202Argentina
BO190.129.12.162Bolivia
CN150.255.120.113China
CN150.255.194.173China
CN150.255.203.28China
CN150.255.205.166China
CN150.255.208.231China
CO190.90.2.30Colombia
ES188.87.211.12Spain
GB193.164.207.16United Kingdom
HN190.107.140.76Honduras
IN117.240.239.120India
IN122.160.239.39India
IN202.62.67.250India
IN202.63.105.226India
IR91.98.117.28Iran
IR94.182.248.19Iran
IT95.227.34.226Italy
MO60.246.178.161Macau
MX187.174.173.18Mexico
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
UA195.66.204.70Ukraine
US50.201.42.106United States
US74.222.3.249United States

List from greylisting:

Botnet Statistics [2014-01-21]

detection period: 2014-01-21 00:00-23:59 UTC
total number of suspected botnet IPs: 6996
number of botnet IPs notified to network operators: 6796
number of spam blocked: 72741
recipient count of spam blocked: 2153545

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET492
2UNICOM-SD454
3CHINANET-JS338
4UNICOM-HE270
5CRTC257
6UNICOM-LN247
7CHINANET-GD239
8UNICOM-JL209
9UNICOM-HA208
10UNICOM-HL184

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China5950
2Taiwan146
3United States99
4France70
5United Kingdom53
6Brazil49
7Italy48
8Spain42
9India35
10Russian Federation30

Tuesday, January 21, 2014

Suspected Bot List [2014-01-20]

detection period: 2014-01-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 72

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BG46.55.147.50Bulgaria
BO190.129.12.162Bolivia
CO190.90.2.30Colombia
ES188.87.211.12Spain
GB193.164.207.16United Kingdom
IN117.240.239.120India
IN122.160.239.39India
IN202.62.67.250India
IN202.63.105.226India
IR94.182.248.19Iran
IT95.227.34.226Italy
MX187.174.173.18Mexico
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
US50.201.42.106United States
US74.222.3.249United States

List from greylisting:

Botnet Statistics [2014-01-20]

detection period: 2014-01-20 00:00-23:59 UTC
total number of suspected botnet IPs: 2594
number of botnet IPs notified to network operators: 2522
number of spam blocked: 38276
recipient count of spam blocked: 1366367

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD187
2UNICOM-HB172
3UNICOM-SD148
4CMNET124
5UNICOM-LN107
6CHINANET-JS94
7UNICOM-HA75
8CRTC72
9UNICOM-HL71
10UNICOM-HE69

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2087
2Taiwan70
3United States38
4India35
5Brazil32
6Russian Federation28
7France27
8United Kingdom25
9Indonesia19
10Italy12

Monday, January 20, 2014

Suspected Bot List [2014-01-19]

detection period: 2014-01-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 51

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BG46.55.147.50Bulgaria
BO190.129.12.162Bolivia
CN150.255.1.110China
CN150.255.177.73China
CO190.90.2.30Colombia
ES188.87.211.12Spain
GB193.164.207.16United Kingdom
HN190.107.140.76Honduras
IN117.240.239.120India
IN202.62.67.250India
IN202.63.105.226India
IR94.182.248.19Iran
IT95.227.34.226Italy
MO60.246.148.42Macau
MX187.174.173.18Mexico
PE200.31.105.172Peru
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-01-19]

detection period: 2014-01-19 00:00-23:59 UTC
total number of suspected botnet IPs: 2609
number of botnet IPs notified to network operators: 2558
number of spam blocked: 54729
recipient count of spam blocked: 1470582

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD172
2UNICOM-SD164
3CMNET158
4CHINANET-JS139
5CRTC107
6UNICOM-LN103
7UNICOM-HA96
8UNICOM-HE90
9UNICOM-HL70
10UNICOM-SX63

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2246
2Taiwan76
3Brazil27
4United States21
5Russian Federation21
6Italy19
7Ukraine12
8Poland10
9South Korea10
10Indonesia10

Sunday, January 19, 2014

Suspected Bot List [2014-01-18]

detection period: 2014-01-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 59

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BG46.55.147.50Bulgaria
BO190.129.12.162Bolivia
CO190.90.2.30Colombia
ES188.87.211.12Spain
GB193.164.207.16United Kingdom
HN190.107.140.76Honduras
IN117.240.239.120India
IN122.160.239.39India
IN202.62.67.250India
IN202.63.105.226India
IR94.182.248.19Iran
IT95.227.34.226Italy
LB213.175.188.158Lebanon
MO60.246.179.215Macau
MX187.174.173.18Mexico
PK210.2.170.42Pakistan
RU193.107.17.55Russian Federation
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-01-18]

detection period: 2014-01-18 00:00-23:59 UTC
total number of suspected botnet IPs: 3004
number of botnet IPs notified to network operators: 2945
number of spam blocked: 62803
recipient count of spam blocked: 1589305

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-HB317
2UNICOM-HB206
3UNICOM-SD178
4CMNET154
5CHINANET-GD129
6CHINANET-JS121
7UNICOM-HA105
8CRTC101
9UNICOM-LN96
10UNICOM-HE91

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2613
2Taiwan91
3Brazil28
4United States25
5Russian Federation23
6Italy19
7India15
8South Korea11
9Indonesia11
10Turkey10

Saturday, January 18, 2014

Suspected Bot List [2014-01-17]

detection period: 2014-01-17 00:00-23:59 UTC
number of suspected bots' IPs listed here: 90

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.15.201.202Argentina
BG46.55.147.50Bulgaria
BO190.129.12.162Bolivia
CN150.255.195.170China
CO190.90.2.30Colombia
ES188.87.211.12Spain
GB193.164.207.16United Kingdom
HN190.107.140.76Honduras
IN117.239.29.114India
IN117.240.239.120India
IN122.160.239.39India
IN182.74.135.74India
IN202.62.67.250India
IN202.63.105.226India
IR91.98.117.28Iran
IR94.182.248.19Iran
LB213.175.188.158Lebanon
MO60.246.146.129Macau
MX187.174.173.18Mexico
PE190.232.218.209Peru
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
TW61.64.21.68Taiwan
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-01-17]

detection period: 2014-01-17 00:00-23:59 UTC
total number of suspected botnet IPs: 3455
number of botnet IPs notified to network operators: 3365
number of spam blocked: 57578
recipient count of spam blocked: 1633009

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-HB293
2UNICOM-HB201
3UNICOM-SD183
4CMNET159
5CHINANET-GD139
6UNICOM-HA113
7CRTC106
8CHINANET-JS106
9UNICOM-LN103
10UNICOM-HE94

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2754
2Taiwan85
3United States73
4France53
5Brazil36
6Russian Federation34
7India32
8United Kingdom30
9Indonesia21
10South Korea19

Friday, January 17, 2014

Suspected Bot List [2014-01-16]

detection period: 2014-01-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 171

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.15.201.202Argentina
BO190.129.12.162Bolivia
CO190.90.2.30Colombia
ES188.87.211.12Spain
GB193.164.207.16United Kingdom
HN190.107.140.76Honduras
IN117.240.239.120India
IN122.160.239.39India
IN182.74.135.74India
IN202.62.67.250India
IN202.63.105.226India
IR91.98.117.28Iran
IR94.182.248.19Iran
LB213.175.188.158Lebanon
MX187.174.173.18Mexico
PE190.232.218.209Peru
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-01-16]

detection period: 2014-01-16 00:00-23:59 UTC
total number of suspected botnet IPs: 2808
number of botnet IPs notified to network operators: 2637
number of spam blocked: 39143
recipient count of spam blocked: 1437298

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD148
2CMNET133
3UNICOM-SD129
4CRTC97
5UNICOM-HA87
6CHINANET-JS85
7UNICOM-LN81
8UNICOM-HL75
9UNICOM-HE69
10HINET-NET64

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1916
2United States125
3Taiwan82
4Brazil49
5France48
6India45
7Russian Federation39
8United Kingdom35
9Spain23
10Italy22

Thursday, January 16, 2014

Suspected Bot List [2014-01-15]

detection period: 2014-01-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 125

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.15.201.202Argentina
BG46.55.147.50Bulgaria
BO190.129.12.162Bolivia
CO190.90.2.30Colombia
GB193.164.207.16United Kingdom
GH212.96.12.199Ghana
HN190.107.140.76Honduras
IN117.240.239.120India
IN122.160.239.39India
IN182.74.135.74India
IN202.63.105.226India
IR91.98.117.28Iran
IR94.182.248.19Iran
LB213.175.188.158Lebanon
MX187.174.173.18Mexico
PE200.31.105.172Peru
PK124.109.47.66Pakistan
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
US50.201.42.106United States
US184.82.162.122United States

List from greylisting:

Botnet Statistics [2014-01-15]

detection period: 2014-01-15 00:00-23:59 UTC
total number of suspected botnet IPs: 2312
number of botnet IPs notified to network operators: 2187
number of spam blocked: 35381
recipient count of spam blocked: 1300918

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD145
2CMNET134
3UNICOM-SD105
4CRTC96
5CHINANET-JS66
6UNICOM-HA64
7UNICOM-LN60
8UNICOM-HE53
9HINET-NET52
10UNICOM-HL49

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1597
2United States86
3Taiwan68
4France60
5India51
6Brazil37
7Russian Federation31
8United Kingdom31
9Indonesia21
10Ukraine17

Wednesday, January 15, 2014

Suspected Bot List [2014-01-14]

detection period: 2014-01-14 00:00-23:59 UTC
number of suspected bots' IPs listed here: 184

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.15.201.202Argentina
BG46.55.147.50Bulgaria
BO190.129.12.162Bolivia
DO190.94.63.166Dominican Republic
GB193.164.207.16United Kingdom
GH212.96.12.199Ghana
HN190.107.140.76Honduras
IN117.239.29.114India
IN117.240.239.120India
IN122.160.239.39India
IN182.74.135.74India
IN202.63.105.226India
IR91.98.117.28Iran
IR91.98.117.30Iran
IR94.182.248.19Iran
MX187.174.173.18Mexico
PK124.109.47.66Pakistan
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
TW61.64.21.68Taiwan
US50.201.42.106United States
US184.82.162.122United States

List from greylisting:

Botnet Statistics [2014-01-14]

detection period: 2014-01-14 00:00-23:59 UTC
total number of suspected botnet IPs: 2557
number of botnet IPs notified to network operators: 2373
number of spam blocked: 38115
recipient count of spam blocked: 1409887

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD144
2CRTC143
3CMNET137
4CTTNET88
5UNICOM-SD78
6CHINANET-JS62
7UNICOM-HE58
8IP2000-ADSL-BAS56
9CHINANET-FJ56
10UNICOM-LN54

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1484
2United States213
3France155
4United Kingdom74
5Taiwan59
6India52
7Brazil38
8Russian Federation35
9Indonesia22
10South Korea21

Tuesday, January 14, 2014

Suspected Bot List [2014-01-13]

detection period: 2014-01-13 00:00-23:59 UTC
number of suspected bots' IPs listed here: 135

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.15.201.202Argentina
BO190.129.12.162Bolivia
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.76Honduras
IN117.240.239.120India
IN122.160.239.39India
IN182.73.111.2India
IN182.74.135.74India
IN202.63.105.226India
IR91.98.117.30Iran
IR94.182.248.19Iran
MN183.177.98.154Mongolia
MX187.174.173.18Mexico
PE190.81.249.18Peru
PE200.31.105.172Peru
PK124.109.47.66Pakistan
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
US50.201.42.106United States
US184.82.162.122United States

List from greylisting:

Botnet Statistics [2014-01-13]

detection period: 2014-01-13 00:00-23:59 UTC
total number of suspected botnet IPs: 2062
number of botnet IPs notified to network operators: 1927
number of spam blocked: 36899
recipient count of spam blocked: 1375295

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CRTC194
2CHINANET-GD156
3CMNET129
4CHINANET-JS58
5UNICOM-SD53
6UNICOM-LN53
7HINET-NET48
8UNICOM-HE45
9CHINANET-FJ45
10CTTNET31

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1318
2France115
3United States102
4Taiwan57
5India46
6Brazil34
7Russian Federation25
8South Korea21
9Indonesia21
10United Kingdom21

Monday, January 13, 2014

Suspected Bot List [2014-01-12]

detection period: 2014-01-12 00:00-23:59 UTC
number of suspected bots' IPs listed here: 31

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.15.201.202Argentina
BO190.129.12.162Bolivia
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.76Honduras
IN117.240.239.120India
IN122.160.239.39India
IN182.73.111.2India
IN182.74.135.74India
IN202.63.105.226India
IR91.98.117.30Iran
IR94.182.248.19Iran
MN183.177.98.154Mongolia
MO60.246.203.195Macau
MX187.174.173.18Mexico
PE190.81.249.18Peru
PK124.109.47.66Pakistan
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
TW61.64.21.68Taiwan
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-01-12]

detection period: 2014-01-12 00:00-23:59 UTC
total number of suspected botnet IPs: 1378
number of botnet IPs notified to network operators: 1347
number of spam blocked: 12642
recipient count of spam blocked: 456072

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD132
2CMNET103
3CRTC75
4UNICOM-SD67
5UNICOM-HE45
6CHINANET-JS42
7UNICOM-LN41
8CHINANET-FJ37
9UNICOM-HA36
10HINET-NET36

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1122
2Taiwan46
3United States36
4Brazil23
5Russian Federation15
6Ukraine10
7South Korea9
8India9
9Indonesia8
10Hong Kong6

Sunday, January 12, 2014

Suspected Bots' IP List for January 2014

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here (as shown below) 10 days after its respective botnet statistics gets published.

You are free to use them to create more effective defenses, discover latest trends in cyber attacks, etc.

Suspected Bots IP [2014-01-31]
Suspected Bots IP [2014-01-30]
Suspected Bots IP [2014-01-29]
Suspected Bots IP [2014-01-28]
Suspected Bots IP [2014-01-27]
Suspected Bots IP [2014-01-26]
Suspected Bots IP [2014-01-25]
Suspected Bots IP [2014-01-24]
Suspected Bots IP [2014-01-23]
Suspected Bots IP [2014-01-22]
Suspected Bots IP [2014-01-21]
Suspected Bots IP [2014-01-20]
Suspected Bots IP [2014-01-19]
Suspected Bots IP [2014-01-18]
Suspected Bots IP [2014-01-17]
Suspected Bots IP [2014-01-16]
Suspected Bots IP [2014-01-15]
Suspected Bots IP [2014-01-14]
Suspected Bots IP [2014-01-13]
Suspected Bots IP [2014-01-12]
Suspected Bots IP [2014-01-11]
Suspected Bots IP [2014-01-10]
Suspected Bots IP [2014-01-09]
Suspected Bots IP [2014-01-08]
Suspected Bots IP [2014-01-07]
Suspected Bots IP [2014-01-06]
Suspected Bots IP [2014-01-05]
Suspected Bots IP [2014-01-04]
Suspected Bots IP [2014-01-03]
Suspected Bots IP [2014-01-02]
Suspected Bots IP [2014-01-01]

Suspected Bot List [2014-01-11]

detection period: 2014-01-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 156

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.15.201.202Argentina
BO190.129.12.162Bolivia
CN150.255.102.244China
DO190.94.63.166Dominican Republic
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.76Honduras
IN112.133.209.36India
IN122.160.239.39India
IN182.73.111.2India
IN182.74.135.74India
IN202.63.105.226India
IR91.98.117.30Iran
IR94.182.248.19Iran
MO60.246.144.75Macau
MO60.246.203.22Macau
MX187.174.173.18Mexico
PE200.31.105.172Peru
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
TW61.64.21.68Taiwan
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-01-11]

detection period: 2014-01-11 00:00-23:59 UTC
total number of suspected botnet IPs: 2332
number of botnet IPs notified to network operators: 2176
number of spam blocked: 34159
recipient count of spam blocked: 1255490

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET163
2CHINANET-GD134
3CRTC118
4HINET-NET93
5UNICOM-SD88
6CHINANET-JS68
7UNICOM-HE65
8UNICOM-LN55
9CTTNET47
10CHINANET-FJ42

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1447
2Taiwan121
3United States107
4India50
5France45
6Russian Federation34
7Kazakhstan34
8United Kingdom26
9Viet Nam25
10Brazil25

Botnet Statistics for the year of 2013

detection period: 2013-01-01 00:00 - 2013-12-31 23:59 UTC
total number of suspected botnet IPs: 778866
number of blocked spams: 28179569
recipient count of blocked spams: 955885959
detection methods: fake open relay + greylisting

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China369154
2Taiwan102278
3Belarus46978
4United States35984
5Kazakhstan17177
6India15853
7Ukraine12413
8Viet Nam11292
9Spain10118
10Argentina9909
11Peru9839
12Russian Federation8655
13Colombia7655
14Italy7523
15United Kingdom6824
16Mexico6634
17Iran6276
18Brazil5781
19Germany5725
20Poland5161
21Romania4212
22Canada3955
23South Korea3898
24Chile3857
25Turkey3822

The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:

RankCountry# of blocked spams
1Taiwan6339165
2China5870709
3Brazil2849191
4United States2275300
5Russian Federation1560085
6United Kingdom691147
7Iran515977
8India509058
9Ukraine483038
10South Korea470287
11France415739
12Colombia328107
13Germany300302
14Indonesia293460
15Thailand268891
16Peru267810
17Poland245957
18Argentina236023
19Mexico233041
20Kuwait222378
21Saudi Arabia179580
22Pakistan157184
23Hong Kong157036
24Philippines154559
25Israel150750

The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:

Botnet Statistics for December 2013

detection period: 2013-12-01 00:00 - 2013-12-31 23:59 UTC
total number of suspected botnet IPs: 43949
number of blocked spams: 1569918
recipient count of blocked spams: 53876753

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China24876
2Taiwan7844
3United States1542
4India630
5Spain555
6Argentina484
7Italy478
8United Kingdom461
9France461
10Peru383
11Brazil351
12Colombia313
13Mexico312
14Iran273
15Germany244
16Turkey241
17Singapore225
18South Korea223
19Israel222
20Indonesia219
21Chile207
22Hong Kong196
23Russian Federation193
24Romania184
25Viet Nam178

The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:

RankCountry# of blocked spams
1Taiwan490656
2China418397
3Brazil121751
4Russian Federation64126
5United States45722
6India24217
7United Kingdom23474
8Saudi Arabia22135
9Indonesia20984
10Colombia20351
11Ukraine19165
12South Korea18552
13Iran17700
14Germany16925
15Poland16324
16Philippines16270
17Israel15745
18Hong Kong12432
19Ivory Coast12308
20Mexico11075
21Turkey11050
22Peru10822
23Republic of Maldives10358
24Romania10356
25Argentina8443

The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:

Saturday, January 11, 2014

Suspected Bot List [2014-01-10]

detection period: 2014-01-10 00:00-23:59 UTC
number of suspected bots' IPs listed here: 259

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.15.201.202Argentina
BO190.129.12.162Bolivia
ES188.85.187.227Spain
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.76Honduras
IN112.133.209.36India
IN117.240.239.120India
IN122.160.239.39India
IN182.73.111.2India
IN182.74.135.74India
IN202.63.105.226India
IR91.98.117.30Iran
IR94.182.248.19Iran
MN183.177.98.154Mongolia
MX187.174.173.18Mexico
PE200.31.105.172Peru
PK210.2.170.42Pakistan
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
TW61.64.21.68Taiwan
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-01-10]

detection period: 2014-01-10 00:00-23:59 UTC
total number of suspected botnet IPs: 2326
number of botnet IPs notified to network operators: 2067
number of spam blocked: 40564
recipient count of spam blocked: 1499581

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD132
2CMNET72
3CRTC63
4HINET-NET61
5UNICOM-SD43
6CHINANET-JS38
7CHINANET-FJ37
8UNICOM-LN33
9UNICOM-HA33
10IP2000-ADSL-BAS32

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China832
2United States290
3France113
4Taiwan86
5India74
6United Kingdom62
7Singapore40
8Hong Kong38
9Viet Nam37
10Russian Federation34