Custom Search

Friday, October 31, 2014

Suspected Bot List [2014-10-30]

detection period: 2014-10-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 122

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
IN59.180.233.90India
IN117.211.42.53India
IR91.99.36.85Iran
IR194.33.124.42Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
LB62.84.79.245Lebanon
PE200.110.35.150Peru
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PK202.154.226.90Pakistan
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US69.197.128.170United States
US174.139.8.82United States
US192.161.180.146United States
VE201.248.227.12Venezuela

List from greylisting:

Botnet Statistics [2014-10-30]

detection period: 2014-10-30 00:00-23:59 UTC
total number of suspected botnet IPs: 1680
number of botnet IPs notified to network operators: 1558
number of spam blocked: 138642
recipient count of spam blocked: 4054893

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET836
2CHINANET-HB40
3CHINANET-GD40
4UNICOM-BJ16
5UNICOM-HA14
6BHARTI-IN14
7VNPT-VNNIC-VN12
8BORANET-KR11
9ALIBABA-US-CDN11
10KORNET-KR10

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan842
2China216
3United States82
4India66
5Russian Federation51
6Indonesia32
7South Korea30
8Viet Nam28
9Hong Kong21
10South Africa20

Thursday, October 30, 2014

Suspected Bot List [2014-10-29]

detection period: 2014-10-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 109

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
GB176.35.77.154United Kingdom
IR194.33.124.42Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
MX201.116.227.163Mexico
PE200.110.35.150Peru
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PK202.154.226.90Pakistan
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US69.197.128.170United States
US174.139.8.82United States
US192.161.180.146United States
UZ89.236.219.106Uzbekistan
VE201.248.227.12Venezuela

List from greylisting:

Botnet Statistics [2014-10-29]

detection period: 2014-10-29 00:00-23:59 UTC
total number of suspected botnet IPs: 1725
number of botnet IPs notified to network operators: 1616
number of spam blocked: 136646
recipient count of spam blocked: 4352167

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET931
2CHINANET-GD40
3CHINANET-HB26
4KORNET-KR18
5BORANET-KR18
6ALIBABA-US-CDN15
7UNICOM-BJ14
8HICHINA10
9VNPT-VNNIC-VN7
10UNICOM-GD7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan938
2China200
3United States86
4Russian Federation61
5South Korea44
6India37
7Indonesia27
8Viet Nam20
9Hong Kong20
10Arab Emirates20

Wednesday, October 29, 2014

Suspected Bot List [2014-10-28]

detection period: 2014-10-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 87

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
GB176.35.77.154United Kingdom
IR194.33.124.42Iran
MX201.116.227.163Mexico
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PK202.154.226.90Pakistan
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US69.197.128.170United States
US174.139.8.82United States
US192.161.180.146United States

List from greylisting:

Botnet Statistics [2014-10-28]

detection period: 2014-10-28 00:00-23:59 UTC
total number of suspected botnet IPs: 1531
number of botnet IPs notified to network operators: 1444
number of spam blocked: 133486
recipient count of spam blocked: 4302945

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET883
2CHINANET-GD58
3CHINANET-HB25
4UNICOM-GD14
5BHARTI-IN12
6ALIBABA-US-CDN12
7UNICOM-BJ11
8HICHINA9
9VNPT-VNNIC-VN8
10SINGNET-SG6

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan885
2China215
3United States90
4India47
5Indonesia29
6Viet Nam20
7South Korea20
8Hong Kong20
9South Korea17
10Brazil15

Tuesday, October 28, 2014

Suspected Bot List [2014-10-27]

detection period: 2014-10-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 62

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
IR91.99.3.199Iran
IR194.33.124.42Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
LB194.126.140.247Lebanon
MX201.116.227.163Mexico
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PK202.154.226.90Pakistan
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US69.197.128.170United States
US174.139.8.82United States
US192.161.180.146United States
VE201.248.227.12Venezuela

List from greylisting:

Botnet Statistics [2014-10-27]

detection period: 2014-10-27 00:00-23:59 UTC
total number of suspected botnet IPs: 1594
number of botnet IPs notified to network operators: 1532
number of spam blocked: 135635
recipient count of spam blocked: 4341394

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET912
2CHINANET-GD132
3CHINANET-HB23
4UNICOM-BJ18
5ALIBABA-US-CDN13
6UNICOM-GD12
7CHINANET-JX9
8HICHINA8
9CMNET8
10CHINANET-JS8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan921
2China290
3United States77
4India30
5Indonesia27
6Hong Kong20
7Russian Federation19
8Viet Nam18
9Iran16
10South Africa15

Monday, October 27, 2014

Suspected Bot List [2014-10-26]

detection period: 2014-10-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 40

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
CA184.107.73.239Canada
IN117.247.241.27India
IR91.98.234.195Iran
IR91.99.3.199Iran
IR194.33.124.42Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
LB194.126.140.247Lebanon
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PK202.154.226.90Pakistan
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
TW180.218.34.59Taiwan
US50.201.42.106United States
US69.197.128.170United States
US174.139.8.82United States
VE201.248.227.12Venezuela

List from greylisting:

Botnet Statistics [2014-10-26]

detection period: 2014-10-26 00:00-23:59 UTC
total number of suspected botnet IPs: 1400
number of botnet IPs notified to network operators: 1360
number of spam blocked: 134056
recipient count of spam blocked: 4323902

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET893
2CHINANET-GD87
3CHINANET-HB38
4ALIBABA-US-CDN19
5UNICOM-GD15
6UNICOM-BJ14
7CMNET7
8CHINANET-JS7
9UNICOM-SD6
10HICHINA6

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan896
2China241
3United States66
4Iran19
5Indonesia18
6Hong Kong16
7Russian Federation15
8Brazil10
9Ukraine8
10India7

Sunday, October 26, 2014

Suspected Bot List [2014-10-25]

detection period: 2014-10-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 53

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
BO200.87.35.170Bolivia
CA184.107.73.239Canada
CL200.111.103.69Chile
IN117.218.50.134India
IN117.247.241.27India
IR91.98.234.195Iran
IR91.99.3.199Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
LB194.126.140.247Lebanon
MX201.116.227.163Mexico
PE200.110.35.150Peru
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US69.197.128.170United States
US174.139.8.82United States

List from greylisting:

Botnet Statistics [2014-10-25]

detection period: 2014-10-25 00:00-23:59 UTC
total number of suspected botnet IPs: 1454
number of botnet IPs notified to network operators: 1401
number of spam blocked: 143577
recipient count of spam blocked: 4608260

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET927
2CHINANET-GD92
3CHINANET-HB35
4ALIBABA-US-CDN24
5MSFT-GFS9
6CHINANET-JX6
7CHINANET-JS6
8HICHINA5
9UNICOM-HA4
10UNICOM-BJ4

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan929
2China220
3United States80
4Indonesia19
5India18
6Hong Kong17
7Brazil16
8Russian Federation15
9Iran12
10Viet Nam10

Saturday, October 25, 2014

Suspected Bot List [2014-10-24]

detection period: 2014-10-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 50

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
BO200.87.35.170Bolivia
CL200.111.103.69Chile
IN117.218.50.134India
IN117.247.241.27India
IR91.98.234.195Iran
IR194.33.124.42Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
LB194.126.140.247Lebanon
MX201.116.227.163Mexico
PE200.110.35.150Peru
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US69.197.128.170United States
US174.139.8.82United States

List from greylisting:

Botnet Statistics [2014-10-24]

detection period: 2014-10-24 00:00-23:59 UTC
total number of suspected botnet IPs: 1532
number of botnet IPs notified to network operators: 1482
number of spam blocked: 141665
recipient count of spam blocked: 4544951

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET937
2CHINANET-GD84
3CHINANET-HB43
4ALIBABA-US-CDN24
5CHINANET-JX12
6CHINANET-JS8
7UNICOM-SD7
8VNPT-VNNIC-VN6
9UNICOM-HA5
10MTN_ADSL5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan940
2China231
3United States81
4Indonesia25
5Russian Federation16
6Brazil15
7Viet Nam14
8Hong Kong14
9South Africa12
10Iran12

Friday, October 24, 2014

Suspected Bot List [2014-10-23]

detection period: 2014-10-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 59

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR200.59.134.43Argentina
BD203.76.147.70Bangladesh
CL200.111.103.69Chile
IN117.218.50.134India
IR91.98.234.195Iran
IR194.33.124.42Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
MX201.116.227.163Mexico
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US69.197.128.170United States
US174.139.8.82United States

List from greylisting:

Botnet Statistics [2014-10-23]

detection period: 2014-10-23 00:00-23:59 UTC
total number of suspected botnet IPs: 1724
number of botnet IPs notified to network operators: 1665
number of spam blocked: 140054
recipient count of spam blocked: 4472654

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET981
2UNICOM-ZJ144
3CHINANET-GD49
4CHINANET-HB31
5ALIBABA-US-CDN24
6UNICOM-GD21
7UNICOM-BJ15
8SINGNET-SG11
9UNICOM-SD10
10KORNET-KR9

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan985
2China366
3United States92
4Indonesia23
5Brazil21
6South Korea16
7Viet Nam14
8Hong Kong14
9Singapore13
10Iran13

Thursday, October 23, 2014

Suspected Bot List [2014-10-22]

detection period: 2014-10-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 154

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR200.59.134.43Argentina
AR200.63.169.61Argentina
BD203.76.147.70Bangladesh
CL200.111.103.69Chile
IR91.98.234.195Iran
IR194.33.124.42Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
MX201.116.227.163Mexico
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US69.197.128.170United States
US174.139.8.82United States

List from greylisting:

Botnet Statistics [2014-10-22]

detection period: 2014-10-22 00:00-23:59 UTC
total number of suspected botnet IPs: 2158
number of botnet IPs notified to network operators: 2004
number of spam blocked: 129210
recipient count of spam blocked: 3984083

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1094
2UNICOM-ZJ175
3CHINANET-GD49
4VNPT-VNNIC-VN48
5CHINANET-HB33
6UNICOM-FJ25
7UNICOM-GD22
8VIETEL-VNNIC-VN12
9UNICOM-SD12
10KORNET-KR10

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1104
2China424
3Viet Nam76
4United States55
5India29
6Russian Federation28
7Brazil28
8Turkey27
9South Korea27
10Indonesia27

Wednesday, October 22, 2014

Suspected Bot List [2014-10-21]

detection period: 2014-10-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 69

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR200.59.134.43Argentina
BD203.76.147.70Bangladesh
CL200.111.103.69Chile
IR91.98.234.195Iran
IR194.33.124.42Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
MX201.116.227.163Mexico
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US50.201.42.106United States
US69.197.128.170United States
US174.139.8.82United States

List from greylisting:

Botnet Statistics [2014-10-21]

detection period: 2014-10-21 00:00-23:59 UTC
total number of suspected botnet IPs: 1834
number of botnet IPs notified to network operators: 1765
number of spam blocked: 103298
recipient count of spam blocked: 3164584

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1116
2UNICOM-ZJ122
3UNICOM-FJ88
4CHINANET-GD38
5CHINANET-HB25
6UNICOM-SD15
7UNICOM-CN14
8UNICOM-BJ14
9UNICOM-GD10
10CHINANET-JX7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1119
2China413
3United States39
4Brazil22
5Indonesia21
6Russian Federation19
7Turkey15
8Iran12
9Hong Kong12
10Viet Nam11

Tuesday, October 21, 2014

Suspected Bot List [2014-10-20]

detection period: 2014-10-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 84

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
CL200.111.103.69Chile
MX201.116.227.163Mexico

List from greylisting:

Botnet Statistics [2014-10-20]

detection period: 2014-10-20 00:00-23:59 UTC
total number of suspected botnet IPs: 1888
number of botnet IPs notified to network operators: 1804
number of spam blocked: 54204
recipient count of spam blocked: 1615528

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1164
2UNICOM-ZJ141
3CHINANET-GD64
4CHINANET-HB42
5UNICOM-FJ38
6UNICOM-GD14
7UNICOM-BJ14
8UNICOM-SD13
9BHARTI-IN10
10VNPT-VNNIC-VN8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1170
2China373
3India38
4United States28
5Russian Federation26
6South Korea25
7Viet Nam20
8Turkey17
9Indonesia13
10Brazil12

Monday, October 20, 2014

Suspected Bot List [2014-10-19]

detection period: 2014-10-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 22

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
MX201.116.227.163Mexico

List from greylisting:

Botnet Statistics [2014-10-19]

detection period: 2014-10-19 00:00-23:59 UTC
total number of suspected botnet IPs: 756
number of botnet IPs notified to network operators: 734
number of spam blocked: 28271
recipient count of spam blocked: 838748

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET461
2CHINANET-GD49
3UNICOM-ZJ43
4CHINANET-HB29
5UNICOM-GD14
6UNICOM-BJ10
7UNICOM-SD6
8CHINANET-SH3
9AMEN-FR-NETWORK3
10AE-EMIRNET-200504203

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan461
2China185
3United States11
4United Kingdom7
5France7
6India6
7Russian Federation5
8South Korea5
9Viet Nam4
10Hong Kong4

Sunday, October 19, 2014

Suspected Bot List [2014-10-18]

detection period: 2014-10-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 39

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
MX201.116.227.163Mexico

List from greylisting:

Botnet Statistics [2014-10-18]

detection period: 2014-10-18 00:00-23:59 UTC
total number of suspected botnet IPs: 970
number of botnet IPs notified to network operators: 931
number of spam blocked: 40537
recipient count of spam blocked: 1208971

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET720
2CHINANET-GD36
3UNICOM-BJ17
4CHINANET-HB14
5yueyangcnc6
6UNICOM-GD3
7RCOM3
8CMNET3
9BHARTI-IN3
10AMEN-FR-NETWORK3

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan723
2China100
3United States14
4India14
5Brazil13
6Viet Nam6
7Turkey6
8United Kingdom6
9Ukraine5
10Hong Kong5

Saturday, October 18, 2014

Suspected Bot List [2014-10-17]

detection period: 2014-10-17 00:00-23:59 UTC
number of suspected bots' IPs listed here: 67

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
IR91.98.147.62Iran
IR91.98.234.195Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
LB194.126.140.247Lebanon
MX201.116.227.163Mexico
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US69.197.128.170United States
UZ89.236.219.106Uzbekistan

List from greylisting:

Botnet Statistics [2014-10-17]

detection period: 2014-10-17 00:00-23:59 UTC
total number of suspected botnet IPs: 1354
number of botnet IPs notified to network operators: 1287
number of spam blocked: 52260
recipient count of spam blocked: 1554325

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET844
2CHINANET-GD65
3CHINANET-HB28
4UNICOM-BJ21
5UNICOM-GD13
6UNICOM-SD7
7HICHINA6
8KORNET-KR5
9003.420.926/0002-055
10TATAINDICOM-IN4

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan852
2China197
3United States47
4India26
5Brazil19
6South Africa14
7Turkey13
8Italy12
9United Kingdom12
10Iran11

Friday, October 17, 2014

Suspected Bot List [2014-10-16]

detection period: 2014-10-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 105

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
IR91.98.147.62Iran
IR91.98.234.195Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
LB194.126.140.247Lebanon
MX201.116.227.163Mexico
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US63.246.128.42United States
US69.197.128.170United States
UZ89.236.219.106Uzbekistan

List from greylisting:

Botnet Statistics [2014-10-16]

detection period: 2014-10-16 00:00-23:59 UTC
total number of suspected botnet IPs: 1849
number of botnet IPs notified to network operators: 1744
number of spam blocked: 94951
recipient count of spam blocked: 2883564

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1135
2CHINANET-GD97
3CHINANET-HB36
4UNICOM-BJ21
5VNPT-VNNIC-VN17
6UNICOM-GD11
7UNICOM-SD10
8BSNLNET7
9CHINANET-SH6
10003.420.926/0002-056

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1143
2China255
3United States51
4India40
5Brazil33
6Viet Nam26
7Indonesia21
8Russian Federation19
9Italy18
10United Kingdom17

Thursday, October 16, 2014

Suspected Bot List [2014-10-15]

detection period: 2014-10-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 101

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
IR91.98.147.62Iran
IR91.98.234.195Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
LB194.126.140.247Lebanon
RU95.188.112.11Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US69.197.128.170United States
UZ89.236.219.106Uzbekistan

List from greylisting:

Botnet Statistics [2014-10-15]

detection period: 2014-10-15 00:00-23:59 UTC
total number of suspected botnet IPs: 2082
number of botnet IPs notified to network operators: 1981
number of spam blocked: 115514
recipient count of spam blocked: 3602515

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1241
2UNICOM-ZJ144
3CHINANET-GD77
4UNICOM-FJ41
5CHINANET-HB41
6UNICOM-GD11
7UNICOM-BJ10
8CHINANET-JS8
9VNPT-VNNIC-VN7
10HICHINA7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1250
2China412
3United States56
4India41
5Russian Federation36
6Brazil23
7Viet Nam20
8Turkey19
9Indonesia16
10Italy14

Wednesday, October 15, 2014

Suspected Bot List [2014-10-14]

detection period: 2014-10-14 00:00-23:59 UTC
number of suspected bots' IPs listed here: 39

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
IR91.98.147.62Iran
IR91.98.234.195Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
LB194.126.140.247Lebanon
RU95.188.112.11Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US69.197.128.170United States
UZ89.236.219.106Uzbekistan

List from greylisting:

Botnet Statistics [2014-10-14]

detection period: 2014-10-14 00:00-23:59 UTC
total number of suspected botnet IPs: 2055
number of botnet IPs notified to network operators: 2016
number of spam blocked: 200626
recipient count of spam blocked: 4538837

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1244
2UNICOM-ZJ201
3CHINANET-GD192
4UNICOM-FJ30
5CHINANET-HB29
6UNICOM-GD14
7UNICOM-BJ13
8UNICOM-SD8
9CHINANET-JS7
10UNICOM-CN5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1249
2China554
3United States44
4Brazil18
5Indonesia16
6Hong Kong14
7Russian Federation12
8Iran11
9Viet Nam8
10Ukraine8

Tuesday, October 14, 2014

Suspected Bot List [2014-10-13]

detection period: 2014-10-13 00:00-23:59 UTC
number of suspected bots' IPs listed here: 105

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
IR91.98.234.195Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
LB194.126.140.247Lebanon
RU95.188.112.11Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US69.197.128.170United States
UZ89.236.219.106Uzbekistan

List from greylisting:

Botnet Statistics [2014-10-13]

detection period: 2014-10-13 00:00-23:59 UTC
total number of suspected botnet IPs: 2185
number of botnet IPs notified to network operators: 2080
number of spam blocked: 189812
recipient count of spam blocked: 4553808

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1242
2UNICOM-ZJ138
3CHINANET-GD136
4CHINANET-HB52
5UNICOM-FJ38
6BHARTI-IN15
7UNICOM-GD12
8UNICOM-BJ11
9CHINANET-JS9
10MINDSPRING-DEDA-C3008

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1249
2China466
3India61
4Russian Federation49
5United States48
6Turkey26
7Indonesia22
8Viet Nam20
9Brazil20
10Ukraine15

Monday, October 13, 2014

Suspected Bot List [2014-10-12]

detection period: 2014-10-12 00:00-23:59 UTC
number of suspected bots' IPs listed here: 23

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
IR91.98.234.195Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
LB194.126.140.247Lebanon
RU95.188.112.11Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US69.197.128.170United States
UZ89.236.219.106Uzbekistan
ZA209.203.59.30South Africa

List from greylisting:

Botnet Statistics [2014-10-12]

detection period: 2014-10-12 00:00-23:59 UTC
total number of suspected botnet IPs: 1679
number of botnet IPs notified to network operators: 1656
number of spam blocked: 148515
recipient count of spam blocked: 4345018

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1246
2CHINANET-GD42
3UNICOM-FJ32
4CHINANET-HB12
5UNICOM-GD11
6UNICOM-BJ9
7VPSQUAN-3236
8CHINANET-JS6
9UNICOM-CN5
10HICHINA5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1251
2China190
3United States66
4Russian Federation17
5Indonesia15
6Brazil12
7Viet Nam10
8Ukraine8
9Iran8
10Hong Kong8

Sunday, October 12, 2014

Suspected Bots' IP List for October 2014

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here (as shown below) 10 days after its respective botnet statistics gets published.

New data will be added here daily. You are free to use them to create more effective defenses, discover latest trends in cyber attacks, etc.

Suspected Bots IP [2014-10-31]
Suspected Bots IP [2014-10-30]
Suspected Bots IP [2014-10-29]
Suspected Bots IP [2014-10-28]
Suspected Bots IP [2014-10-27]
Suspected Bots IP [2014-10-26]
Suspected Bots IP [2014-10-25]
Suspected Bots IP [2014-10-24]
Suspected Bots IP [2014-10-23]
Suspected Bots IP [2014-10-22]
Suspected Bots IP [2014-10-21]
Suspected Bots IP [2014-10-20]
Suspected Bots IP [2014-10-19]
Suspected Bots IP [2014-10-18]
Suspected Bots IP [2014-10-17]
Suspected Bots IP [2014-10-16]
Suspected Bots IP [2014-10-15]
Suspected Bots IP [2014-10-14]
Suspected Bots IP [2014-10-13]
Suspected Bots IP [2014-10-12]
Suspected Bots IP [2014-10-11]
Suspected Bots IP [2014-10-10]
Suspected Bots IP [2014-10-09]
Suspected Bots IP [2014-10-08]
Suspected Bots IP [2014-10-07]
Suspected Bots IP [2014-10-06]
Suspected Bots IP [2014-10-05]
Suspected Bots IP [2014-10-04]
Suspected Bots IP [2014-10-03]
Suspected Bots IP [2014-10-02]
Suspected Bots IP [2014-10-01]

Suspected Bot List [2014-10-11]

detection period: 2014-10-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 35

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
IR91.98.147.62Iran
IR91.98.234.195Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
RU95.188.112.11Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US63.246.128.42United States
US69.197.128.170United States
UZ89.236.219.106Uzbekistan
ZA209.203.59.30South Africa

List from greylisting:

Botnet Statistics [2014-10-11]

detection period: 2014-10-11 00:00-23:59 UTC
total number of suspected botnet IPs: 1806
number of botnet IPs notified to network operators: 1771
number of spam blocked: 185909
recipient count of spam blocked: 4788500

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1218
2UNICOM-ZJ110
3CHINANET-GD48
4CHINANET-HB45
5UNICOM-BJ15
6UNICOM-GD14
7UNICOM-FJ13
8HICHINA9
9MINDSPRING-DEDA-C3008
10VPSQUAN-3236

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1221
2China318
3United States84
4Russian Federation17
5Brazil16
6Indonesia15
7Iran11
8Ukraine8
9Italy8
10Hong Kong8

Saturday, October 11, 2014

Suspected Bot List [2014-10-10]

detection period: 2014-10-10 00:00-23:59 UTC
number of suspected bots' IPs listed here: 91

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
CO200.80.43.248Colombia
IR81.31.224.171Iran
IR91.98.234.195Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
RU95.188.112.11Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US50.201.42.106United States
US69.165.75.131United States
US69.165.75.134United States
US69.165.75.135United States
US69.165.75.136United States
US69.165.75.139United States
US69.165.75.148United States
US69.165.75.149United States
US69.165.75.151United States
US69.165.75.152United States
US69.165.75.153United States
US69.165.75.154United States
US69.165.75.157United States
US69.165.75.160United States
US69.165.75.161United States
US69.165.75.165United States
US69.165.75.168United States
US69.165.75.170United States
US69.165.75.174United States
US69.165.75.189United States
US69.165.75.190United States
US69.165.75.193United States
US69.165.75.194United States
US69.165.75.195United States
US69.165.75.199United States
US69.165.75.206United States
US69.165.75.207United States
US69.165.75.210United States
US69.165.75.211United States
US69.165.75.213United States
US69.165.75.215United States
US69.165.75.222United States
US69.165.75.225United States
US69.165.75.227United States
US69.165.75.232United States
US69.165.75.235United States
US69.165.75.238United States
US69.165.75.244United States
US69.197.128.170United States
UZ89.236.219.106Uzbekistan
ZA209.203.59.30South Africa

List from greylisting:

Botnet Statistics [2014-10-10]

detection period: 2014-10-10 00:00-23:59 UTC
total number of suspected botnet IPs: 1952
number of botnet IPs notified to network operators: 1861
number of spam blocked: 177071
recipient count of spam blocked: 4636611

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1224
2UNICOM-ZJ165
3UNKNOWN37
4CHINANET-HB34
5CHINANET-GD31
6UNICOM-HA16
7UNICOM-GD16
8UNICOM-BJ13
9MINDSPRING-DEDA-C3007
10HICHINA7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1230
2China371
3United States113
4Russian Federation27
5Brazil23
6India15
7Indonesia15
8Viet Nam14
9Iran10
10Turkey9

Friday, October 10, 2014

Suspected Bot List [2014-10-09]

detection period: 2014-10-09 00:00-23:59 UTC
number of suspected bots' IPs listed here: 44

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
CO200.80.43.248Colombia
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
RU95.188.112.11Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
TR193.255.143.62Turkey
TW180.218.34.210Taiwan
US50.201.42.106United States
UZ89.236.219.106Uzbekistan

List from greylisting:

Botnet Statistics [2014-10-09]

detection period: 2014-10-09 00:00-23:59 UTC
total number of suspected botnet IPs: 1941
number of botnet IPs notified to network operators: 1897
number of spam blocked: 183041
recipient count of spam blocked: 4536689

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1226
2UNICOM-ZJ190
3CHINANET-GD77
4ZJU-CN53
5CHINANET-HB26
6UNICOM-BJ19
7UNICOM-GD15
8HICHINA7
9CHINANET-JS7
10UNICOM-HA6

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1231
2China472
3United States66
4Brazil24
5Russian Federation15
6Indonesia14
7Viet Nam9
8Turkey8
9Iran8
10Hong Kong8

Thursday, October 9, 2014

Suspected Bot List [2014-10-08]

detection period: 2014-10-08 00:00-23:59 UTC
number of suspected bots' IPs listed here: 53

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
CO200.80.43.248Colombia
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
PK103.4.92.88Pakistan
RU95.188.112.11Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-10-08]

detection period: 2014-10-08 00:00-23:59 UTC
total number of suspected botnet IPs: 1951
number of botnet IPs notified to network operators: 1898
number of spam blocked: 180592
recipient count of spam blocked: 4588128

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1200
2UNICOM-ZJ147
3ZJU-CN93
4CHINANET-GD54
5CHINANET-HB27
6UNICOM-BJ22
7UNICOM-GD16
8HICHINA8
9CHINANET-JS7
10UNICOM-HA6

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1209
2China447
3United States66
4Russian Federation23
5Brazil17
6Indonesia15
7Italy11
8Iran11
9Viet Nam10
10South Korea10

Wednesday, October 8, 2014

Suspected Bot List [2014-10-07]

detection period: 2014-10-07 00:00-23:59 UTC
number of suspected bots' IPs listed here: 58

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
CO200.80.43.248Colombia
CZ80.188.121.251Czech Republic
IR91.98.234.195Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
LV85.9.201.199Latvia
PE200.110.35.150Peru
PK103.4.92.88Pakistan
RU95.188.112.11Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US50.201.42.106United States
US68.114.102.5United States
US71.91.111.68United States
UZ89.236.219.106Uzbekistan

List from greylisting:

Botnet Statistics [2014-10-07]

detection period: 2014-10-07 00:00-23:59 UTC
total number of suspected botnet IPs: 2011
number of botnet IPs notified to network operators: 1953
number of spam blocked: 153667
recipient count of spam blocked: 4385332

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1210
2UNICOM-ZJ106
3CHINANET-GD73
4ZJU-CN50
5CRTC26
6CHINANET-JS20
7UNICOM-GD16
8UNICOM-BJ16
9CHINANET-HB14
10CHINANET-LN11

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1220
2China432
3United States61
4Russian Federation46
5Indonesia26
6Brazil19
7Viet Nam14
8Iran14
9Hong Kong14
10South Korea10

Tuesday, October 7, 2014

Suspected Bot List [2014-10-06]

detection period: 2014-10-06 00:00-23:59 UTC
number of suspected bots' IPs listed here: 87

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AM178.78.163.52Armenia
AR181.16.161.33Argentina
AR190.0.109.237Argentina
AR190.11.106.227Argentina
AR191.103.50.211Argentina
AR201.219.181.198Argentina
BD203.76.147.70Bangladesh
BG95.111.23.132Bulgaria
CL181.43.34.164Chile
CL190.91.92.204Chile
CO200.80.43.248Colombia
CZ80.188.121.251Czech Republic
IN106.216.224.76India
IR91.98.234.195Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT62.18.148.104Italy
IT79.50.132.140Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
MX201.132.170.35Mexico
PE190.12.65.146Peru
PE200.110.35.150Peru
PK103.4.92.88Pakistan
PT78.130.75.207Portugal
RU95.188.112.11Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
US68.114.102.5United States
US68.184.59.98United States
US71.91.111.68United States
US74.128.103.194United States
UZ89.236.219.106Uzbekistan

List from greylisting:

Botnet Statistics [2014-10-06]

detection period: 2014-10-06 00:00-23:59 UTC
total number of suspected botnet IPs: 2028
number of botnet IPs notified to network operators: 1941
number of spam blocked: 139322
recipient count of spam blocked: 4180922

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1166
2CHINANET-GD90
3CRTC67
4CHINANET-SN27
5CHINANET-JS27
6ZJU-CN21
7CHINANET-LN19
8UNICOM-GD12
9VNPT-VNNIC-VN11
10UNICOM-BJ11

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1171
2China398
3United States85
4Russian Federation44
5Brazil34
6Indonesia25
7Viet Nam21
8Argentina16
9Poland13
10Iran13