Custom Search

Saturday, January 31, 2015

Suspected Bot List [2015-01-30]

detection period: 2015-01-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 85

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
BO200.87.111.202Bolivia
EC201.219.60.85Ecuador
ID103.16.115.14Indonesia
ID114.6.45.106Indonesia
ID115.69.221.90Indonesia
ID116.68.251.238Indonesia
ID118.97.175.114Indonesia
ID119.82.240.46Indonesia
ID119.252.166.100Indonesia
ID180.250.46.10Indonesia
ID182.30.250.88Indonesia
ID202.77.108.60Indonesia
ID202.95.148.206Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.132.58Indonesia
ID202.150.139.134Indonesia
ID203.190.116.11Indonesia
ID203.201.172.162Indonesia
IN27.251.38.135India
IN117.247.244.167India
IR82.99.220.219Iran
IR194.33.124.42Iran
MN203.91.119.146Mongolia
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PL91.192.206.101Poland
RU193.107.17.59Russian Federation
TR88.247.164.136Turkey
US69.197.135.216United States
ZA196.201.7.31South Africa

List from greylisting:

Botnet Statistics [2015-01-30]

detection period: 2015-01-30 00:00-23:59 UTC
total number of suspected botnet IPs: 975
number of botnet IPs notified to network operators: 890
number of spam blocked: 40246
recipient count of spam blocked: 1548170

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET200
2CHINANET-GD116
3UNICOM-GD108
4KORNET-KR20
5UNICOM-FJ19
6BORANET-KR10
7CHINANET-FJ8
8VNPT-VNNIC-VN7
9CMNET7
10UNICOM-HA5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China380
2Taiwan210
3Russian Federation54
4United States46
5South Korea43
6Indonesia31
7Viet Nam16
8Brazil14
9Hong Kong13
10India11

Friday, January 30, 2015

Suspected Bot List [2015-01-29]

detection period: 2015-01-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 43

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
ID114.6.45.106Indonesia
ID115.69.221.90Indonesia
ID116.68.251.238Indonesia
ID118.97.175.114Indonesia
ID119.82.240.46Indonesia
ID182.30.250.88Indonesia
ID202.77.108.60Indonesia
ID202.95.148.206Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.132.58Indonesia
ID203.190.116.11Indonesia
IN27.251.38.135India
IR82.99.220.219Iran
MN203.91.119.146Mongolia
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PL91.192.206.101Poland
RU193.107.17.59Russian Federation
TR88.247.164.136Turkey
TW180.176.90.186Taiwan
US69.197.135.216United States

List from greylisting:

Botnet Statistics [2015-01-29]

detection period: 2015-01-29 00:00-23:59 UTC
total number of suspected botnet IPs: 1152
number of botnet IPs notified to network operators: 1109
number of spam blocked: 33751
recipient count of spam blocked: 1077326

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET636
2CHINANET-GD157
3UNICOM-GD92
4HICHINA6
5UNICOM-BJ4
6CRTC4
7CHINANET-ZJ4
8CHINANET-FJ4
9UNICOM-HA3
10UNICOM-FJ3

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan638
2China340
3United States29
4Indonesia18
5Russian Federation9
6Iran9
7Viet Nam8
8Hong Kong8
9Germany8
10Brazil8

Thursday, January 29, 2015

Suspected Bot List [2015-01-28]

detection period: 2015-01-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 27

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD180.211.191.198Bangladesh
CA167.114.71.58Canada
GT190.4.19.250Guatemala
ID119.82.240.46Indonesia
ID180.250.46.10Indonesia
ID202.77.108.60Indonesia
ID202.138.249.215Indonesia
ID202.148.7.77Indonesia
IR94.183.247.79Iran
NG41.73.20.98Nigeria

List from greylisting:

Botnet Statistics [2015-01-28]

detection period: 2015-01-28 00:00-23:59 UTC
total number of suspected botnet IPs: 778
number of botnet IPs notified to network operators: 751
number of spam blocked: 50734
recipient count of spam blocked: 1498734

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET345
2CHINANET-GD133
3UNICOM-GD79
4UNICOM-FJ22
5CMNET9
6HICHINA7
7UNICOM-CN6
8UNICOM-SD4
9CHINANET-ZJ4
10VNPT-VNNIC-VN3

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan348
2China312
3United States19
4South Korea10
5Viet Nam9
6Iran7
7Indonesia6
8Brazil6
9Russian Federation5
10India5

Wednesday, January 28, 2015

Suspected Bot List [2015-01-27]

detection period: 2015-01-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 34

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD180.211.191.198Bangladesh
CA167.114.71.58Canada
GT190.4.19.250Guatemala
ID119.82.240.46Indonesia
ID180.250.46.10Indonesia
ID202.77.108.60Indonesia
ID202.138.249.215Indonesia
ID202.148.7.77Indonesia
IR94.183.247.79Iran
NG41.73.20.98Nigeria

List from greylisting:

Botnet Statistics [2015-01-27]

detection period: 2015-01-27 00:00-23:59 UTC
total number of suspected botnet IPs: 519
number of botnet IPs notified to network operators: 485
number of spam blocked: 102118
recipient count of spam blocked: 3020283

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD117
2UNICOM-GD109
3UNICOM-FJ43
4HINET-NET40
5CMNET9
6CHINANET-JS6
7UNICOM-SD5
8UNICOM-HA4
9HICHINA4
10CHINANET-FJ4

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China343
2Taiwan44
3United States27
4Russian Federation20
5Indonesia8
6Iran6
7India6
8Brazil5
9Ukraine4
10South Korea4

Tuesday, January 27, 2015

Suspected Bot List [2015-01-26]

detection period: 2015-01-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 31

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD180.211.191.198Bangladesh
CA167.114.71.58Canada
GT190.4.19.250Guatemala
ID119.82.240.46Indonesia
ID180.250.46.10Indonesia
ID202.77.108.60Indonesia
ID202.138.249.215Indonesia
ID202.148.7.77Indonesia
ID202.150.139.134Indonesia
ID223.165.7.34Indonesia
IR94.183.247.79Iran
NG41.73.20.98Nigeria

List from greylisting:

Botnet Statistics [2015-01-26]

detection period: 2015-01-26 00:00-23:59 UTC
total number of suspected botnet IPs: 615
number of botnet IPs notified to network operators: 584
number of spam blocked: 75969
recipient count of spam blocked: 2248276

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD189
2UNICOM-GD112
3HINET-NET34
4VNPT-VNNIC-VN15
5CMNET9
6UNICOM-FJ8
7UNICOM-SD6
8KORNET-KR6
9CHINANET-JX6
10HICHINA5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China401
2Taiwan40
3Viet Nam28
4United States26
5South Korea14
6Iran8
7Indonesia8
8Russian Federation5
9Spain5
10Brazil5

Monday, January 26, 2015

Suspected Bot List [2015-01-25]

detection period: 2015-01-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 20

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD180.211.191.198Bangladesh
CA167.114.71.58Canada
GT190.4.19.250Guatemala
ID119.82.240.46Indonesia
ID202.138.249.215Indonesia
ID202.148.7.77Indonesia
ID202.150.139.134Indonesia
ID223.165.7.34Indonesia
IR94.183.247.79Iran

List from greylisting:

Botnet Statistics [2015-01-25]

detection period: 2015-01-25 00:00-23:59 UTC
total number of suspected botnet IPs: 473
number of botnet IPs notified to network operators: 453
number of spam blocked: 80049
recipient count of spam blocked: 2368845

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD122
2UNICOM-GD111
3HINET-NET39
4HICHINA10
5CHINANET-JX10
6SUDJAM01-CUST-GAGGLE9
7CMNET9
8UNICOM-BJ6
9UNICOM-SD5
10VNPT-VNNIC-VN4

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China321
2Taiwan40
3United States30
4Iran10
5Indonesia7
6Brazil7
7Hong Kong5
8Viet Nam4
9Russian Federation4
10France4

Sunday, January 25, 2015

Suspected Bot List [2015-01-24]

detection period: 2015-01-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 37

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD180.211.191.198Bangladesh
BD203.76.147.70Bangladesh
CA167.114.71.58Canada
ID114.6.45.106Indonesia
ID118.97.175.114Indonesia
ID119.82.240.46Indonesia
ID119.252.166.100Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.139.134Indonesia
ID223.165.7.34Indonesia
IN117.247.244.167India
IR194.33.124.42Iran
MN203.91.119.146Mongolia
PH58.69.100.234Philippines
PL91.192.206.101Poland
TR88.247.164.136Turkey
TW180.176.90.186Taiwan
US68.188.75.219United States
US96.44.166.162United States

List from greylisting:

Botnet Statistics [2015-01-24]

detection period: 2015-01-24 00:00-23:59 UTC
total number of suspected botnet IPs: 626
number of botnet IPs notified to network operators: 589
number of spam blocked: 86332
recipient count of spam blocked: 2562902

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD225
2UNICOM-GD113
3HINET-NET40
4CMNET9
5VNPT-VNNIC-VN8
6HICHINA7
7UNICOM-SD5
8CHINANET-JX5
9KORNET-KR4
10CHINANET-JS4

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China431
2Taiwan44
3United States30
4Viet Nam14
5Indonesia10
6Russian Federation9
7South Korea7
8Iran7
9Brazil6
10Bangladesh5

Saturday, January 24, 2015

Suspected Bot List [2015-01-23]

detection period: 2015-01-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 71

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
CA167.114.71.58Canada
ID114.6.45.106Indonesia
ID116.68.251.238Indonesia
ID118.97.175.114Indonesia
ID119.82.240.46Indonesia
ID119.252.166.100Indonesia
ID182.30.250.242Indonesia
ID182.253.25.5Indonesia
ID202.77.108.60Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.132.58Indonesia
ID223.165.7.34Indonesia
IN117.247.244.167India
IR194.33.124.42Iran
MN203.91.119.146Mongolia
PH58.69.100.234Philippines
PL91.192.206.101Poland
PL94.42.81.51Poland
TR88.247.164.136Turkey
TW180.176.90.186Taiwan
US68.188.75.219United States
US96.44.166.162United States
US198.1.98.214United States

List from greylisting:

Botnet Statistics [2015-01-23]

detection period: 2015-01-23 00:00-23:59 UTC
total number of suspected botnet IPs: 820
number of botnet IPs notified to network operators: 749
number of spam blocked: 100971
recipient count of spam blocked: 3097027

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD186
2CRTC127
3UNICOM-GD110
4HINET-NET29
5OCN14
6CMNET13
7VNPT-VNNIC-VN7
8ERX-NETBLOCK7
9UNICOM-SD6
10HICHINA6

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China523
2Taiwan41
3United States36
4Japan24
5Viet Nam15
6Indonesia15
7Brazil13
8South Korea12
9Spain12
10Poland8

Friday, January 23, 2015

Suspected Bot List [2015-01-22]

detection period: 2015-01-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 46

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD180.211.191.198Bangladesh
BD203.76.147.70Bangladesh
CA167.114.71.58Canada
ID114.6.45.106Indonesia
ID116.68.251.238Indonesia
ID118.97.175.114Indonesia
ID119.82.240.46Indonesia
ID119.252.166.100Indonesia
ID180.250.133.50Indonesia
ID182.30.250.242Indonesia
ID202.77.108.60Indonesia
ID202.95.148.206Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.132.58Indonesia
ID202.182.185.194Indonesia
ID223.165.7.34Indonesia
IN117.247.244.167India
IR94.183.247.79Iran
IR194.33.124.42Iran
IT31.199.192.17Italy
IT95.227.105.203Italy
MN203.91.119.146Mongolia
MX187.163.164.233Mexico
NG41.73.20.98Nigeria
PH58.69.100.234Philippines
PK125.209.116.29Pakistan
PL91.192.206.101Poland
PL94.42.81.51Poland
RU95.188.112.11Russian Federation
TR88.247.164.136Turkey
TW180.176.90.186Taiwan
US68.188.75.219United States
US96.44.166.162United States

List from greylisting:

Botnet Statistics [2015-01-22]

detection period: 2015-01-22 00:00-23:59 UTC
total number of suspected botnet IPs: 702
number of botnet IPs notified to network operators: 656
number of spam blocked: 100875
recipient count of spam blocked: 3363668

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CRTC109
2CHINANET-GD108
3UNICOM-GD92
4UNICOM-FJ48
5HINET-NET25
6CMNET20
7UNICOM-CN10
8KORNET-KR7
9CHINANET-FJ7
10UNICOM-SD6

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China487
2United States35
3Taiwan30
4Indonesia15
5South Korea12
6Iran12
7Russian Federation9
8Brazil8
9Viet Nam7
10Poland7

Thursday, January 22, 2015

Suspected Bot List [2015-01-21]

detection period: 2015-01-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 48

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD180.211.191.198Bangladesh
BD203.76.147.70Bangladesh
CA167.114.71.58Canada
EG41.33.238.163Egypt
ID114.6.45.106Indonesia
ID115.69.221.90Indonesia
ID116.68.251.238Indonesia
ID119.82.240.46Indonesia
ID119.252.166.100Indonesia
ID180.250.133.50Indonesia
ID182.30.250.242Indonesia
ID202.77.108.60Indonesia
ID202.95.148.206Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.132.58Indonesia
ID202.182.185.194Indonesia
ID223.165.7.34Indonesia
IN117.247.244.167India
IR94.183.247.79Iran
IR194.33.124.42Iran
IT31.199.192.17Italy
IT95.227.105.203Italy
MN203.91.119.146Mongolia
MX187.163.164.233Mexico
NG41.73.20.98Nigeria
PH58.69.100.234Philippines
PL91.192.206.101Poland
TR88.247.164.136Turkey
TW180.176.90.186Taiwan
US68.188.75.219United States
US96.44.166.162United States
VN103.27.236.144Viet Nam

List from greylisting:

Botnet Statistics [2015-01-21]

detection period: 2015-01-21 00:00-23:59 UTC
total number of suspected botnet IPs: 725
number of botnet IPs notified to network operators: 677
number of spam blocked: 94274
recipient count of spam blocked: 3244900

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CRTC159
2UNICOM-GD83
3CHINANET-GD72
4UNICOM-FJ56
5HINET-NET20
6CMNET19
7HICHINA10
8KORNET-KR8
9CHINANET-JS8
10UNICOM-SD7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China508
2United States34
3Taiwan29
4Indonesia16
5South Korea13
6Iran11
7Brazil11
8Russian Federation8
9Hong Kong7
10Viet Nam6

Wednesday, January 21, 2015

Suspected Bot List [2015-01-20]

detection period: 2015-01-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 48

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
ID114.6.45.106Indonesia
ID115.69.221.90Indonesia
ID116.68.251.238Indonesia
ID118.97.175.114Indonesia
ID118.98.117.75Indonesia
ID119.82.240.46Indonesia
ID119.252.166.100Indonesia
ID180.250.133.50Indonesia
ID182.30.250.242Indonesia
ID202.77.108.60Indonesia
ID202.95.148.206Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.132.58Indonesia
ID202.182.185.194Indonesia
ID223.165.7.34Indonesia
IN117.247.244.167India
IR94.183.247.79Iran
IR194.33.124.42Iran
IT95.227.105.203Italy
MN203.91.119.146Mongolia
MX187.210.37.36Mexico
NG41.73.20.98Nigeria
PH58.69.100.234Philippines
PL91.192.206.101Poland
RU95.188.112.11Russian Federation
TR88.247.164.136Turkey
TW180.176.90.186Taiwan
US68.188.75.219United States
US96.44.166.162United States

List from greylisting:

Botnet Statistics [2015-01-20]

detection period: 2015-01-20 00:00-23:59 UTC
total number of suspected botnet IPs: 756
number of botnet IPs notified to network operators: 708
number of spam blocked: 86918
recipient count of spam blocked: 3099176

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CRTC152
2CHINANET-GD96
3UNICOM-GD76
4UNICOM-FJ54
5CMNET17
6HINET-NET13
7MSFT-GFS10
8HICHINA10
9KORNET-KR7
10MSFT6

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China506
2United States59
3Taiwan24
4Indonesia19
5South Korea14
6Brazil13
7Iran11
8Viet Nam9
9Russian Federation9
10Ukraine6

Tuesday, January 20, 2015

Suspected Bot List [2015-01-19]

detection period: 2015-01-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 92

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
ID114.6.45.106Indonesia
ID115.69.221.90Indonesia
ID116.68.251.238Indonesia
ID118.97.175.114Indonesia
ID118.98.117.75Indonesia
ID119.82.240.46Indonesia
ID119.252.166.100Indonesia
ID180.250.133.50Indonesia
ID182.30.250.138Indonesia
ID182.30.250.242Indonesia
ID202.77.108.60Indonesia
ID202.95.148.206Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.132.58Indonesia
ID202.182.185.194Indonesia
ID203.135.182.250Indonesia
ID223.165.7.34Indonesia
IN1.186.80.26India
IN117.244.15.248India
IN117.247.244.167India
IR94.183.247.79Iran
IR194.33.124.42Iran
IT95.227.105.203Italy
MN203.91.119.146Mongolia
MX187.163.164.233Mexico
MX187.210.37.36Mexico
NG41.73.20.98Nigeria
PH58.69.100.234Philippines
PL91.192.206.101Poland
RU95.188.112.11Russian Federation
TR88.247.164.136Turkey
TW180.176.90.186Taiwan
US68.188.75.219United States
US96.44.166.162United States

List from greylisting:

Botnet Statistics [2015-01-19]

detection period: 2015-01-19 00:00-23:59 UTC
total number of suspected botnet IPs: 1029
number of botnet IPs notified to network operators: 937
number of spam blocked: 78124
recipient count of spam blocked: 2912862

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD218
2CRTC185
3UNICOM-GD71
4UNICOM-FJ46
5HINET-NET17
6CMNET16
7KORNET-KR8
8HICHINA8
9BSNLNET8
10UNICOM-CN7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China663
2United States51
3Taiwan31
4Indonesia19
5Viet Nam18
6Spain17
7Brazil17
8India14
9South Korea13
10Italy13

Monday, January 19, 2015

Suspected Bot List [2015-01-18]

detection period: 2015-01-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 52

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
ID114.6.45.106Indonesia
ID115.69.221.90Indonesia
ID116.68.251.238Indonesia
ID118.97.175.114Indonesia
ID118.98.117.75Indonesia
ID119.82.240.46Indonesia
ID119.252.166.100Indonesia
ID180.250.133.50Indonesia
ID182.30.250.138Indonesia
ID202.77.108.60Indonesia
ID202.95.148.206Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.132.58Indonesia
ID202.182.185.194Indonesia
ID203.135.182.250Indonesia
ID223.165.7.34Indonesia
IN1.186.80.26India
IN117.247.244.167India
IR194.33.124.42Iran
IT95.227.105.203Italy
MN203.91.119.146Mongolia
MX187.163.164.233Mexico
MX187.210.37.36Mexico
NG41.73.20.98Nigeria
PH58.69.100.234Philippines
PL91.192.206.101Poland
RU95.188.112.11Russian Federation
TR88.247.164.136Turkey
TW180.176.90.186Taiwan
US68.188.75.219United States
US96.44.166.162United States

List from greylisting:

Botnet Statistics [2015-01-18]

detection period: 2015-01-18 00:00-23:59 UTC
total number of suspected botnet IPs: 854
number of botnet IPs notified to network operators: 802
number of spam blocked: 73973
recipient count of spam blocked: 2770678

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CRTC228
2CHINANET-GD215
3UNICOM-GD62
4CHINANET-HN17
5HINET-NET15
6CHINANET-JS10
7HICHINA8
8CMNET8
9KORNET-KR7
10UNICOM-SD5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China627
2United States30
3Taiwan20
4Indonesia19
5Brazil13
6South Korea11
7Iran11
8Viet Nam9
9Russian Federation9
10Argentina7

Sunday, January 18, 2015

Suspected Bot List [2015-01-17]

detection period: 2015-01-17 00:00-23:59 UTC
number of suspected bots' IPs listed here: 50

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AM37.252.89.174Armenia
BD203.76.147.70Bangladesh
ID114.6.45.106Indonesia
ID115.69.221.90Indonesia
ID116.68.251.238Indonesia
ID118.97.175.114Indonesia
ID118.98.117.75Indonesia
ID119.82.240.46Indonesia
ID119.252.166.100Indonesia
ID180.250.73.2Indonesia
ID180.250.133.50Indonesia
ID182.30.250.138Indonesia
ID182.30.251.165Indonesia
ID182.30.251.251Indonesia
ID202.77.108.60Indonesia
ID202.95.148.206Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.132.58Indonesia
ID202.182.185.194Indonesia
ID203.135.182.250Indonesia
ID223.165.7.34Indonesia
IN1.186.80.26India
IN117.218.50.134India
IN117.247.244.167India
IR194.33.124.42Iran
IT95.227.105.203Italy
MN203.91.119.146Mongolia
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PL91.192.206.101Poland
PL178.217.34.134Poland
RU95.188.112.11Russian Federation
TR88.247.164.136Turkey
TW180.176.90.186Taiwan
US68.188.75.219United States
US69.197.135.216United States
US96.44.166.162United States
US198.1.98.214United States

List from greylisting:

Botnet Statistics [2015-01-17]

detection period: 2015-01-17 00:00-23:59 UTC
total number of suspected botnet IPs: 667
number of botnet IPs notified to network operators: 617
number of spam blocked: 73197
recipient count of spam blocked: 2754953

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD189
2CRTC66
3UNICOM-GD61
4HINET-NET13
5KORNET-KR10
6HICHINA8
7CMNET7
8CHINANET-JX7
9CHINANET-JS6
10UNICOM-SD5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China445
2United States29
3Indonesia23
4Taiwan19
5Brazil16
6Russian Federation14
7Viet Nam13
8South Korea13
9Iran12
10Ukraine9

Saturday, January 17, 2015

Suspected Bot List [2015-01-16]

detection period: 2015-01-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 111

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
ID114.6.45.106Indonesia
ID115.69.221.90Indonesia
ID116.68.251.238Indonesia
ID118.97.175.114Indonesia
ID118.98.117.75Indonesia
ID119.82.240.46Indonesia
ID119.252.166.100Indonesia
ID180.250.46.10Indonesia
ID180.250.73.2Indonesia
ID182.30.251.165Indonesia
ID202.77.108.60Indonesia
ID202.95.148.206Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.132.58Indonesia
ID202.182.185.194Indonesia
ID203.135.182.250Indonesia
ID203.153.100.83Indonesia
ID203.190.116.11Indonesia
ID223.165.7.34Indonesia
IN1.186.80.26India
IN117.218.50.134India
IN117.247.244.167India
IR94.182.162.73Iran
IR194.33.124.42Iran
MN203.91.119.146Mongolia
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PL91.192.206.101Poland
PL178.217.34.134Poland
RU95.188.112.11Russian Federation
SG116.251.209.170Singapore
TR88.247.164.136Turkey
TW180.176.90.186Taiwan
US68.188.75.219United States
US69.197.135.216United States
US96.44.166.162United States
US198.1.98.214United States
ZA196.201.7.31South Africa

List from greylisting:

Botnet Statistics [2015-01-16]

detection period: 2015-01-16 00:00-23:59 UTC
total number of suspected botnet IPs: 986
number of botnet IPs notified to network operators: 875
number of spam blocked: 74918
recipient count of spam blocked: 2825399

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CRTC120
2CHINANET-GD79
3UNICOM-GD70
4UNICOM-FJ65
5HINET-NET18
6KORNET-KR14
7HICHINA9
8CHINANET-JS9
9CMNET8
10UNICOM-CN7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China477
2Russian Federation59
3United States52
4Indonesia32
5Taiwan27
6South Korea25
7Ukraine24
8India22
9Viet Nam20
10Turkey19

Friday, January 16, 2015

Suspected Bot List [2015-01-15]

detection period: 2015-01-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 50

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
ID114.6.45.106Indonesia
ID115.69.221.90Indonesia
ID118.97.175.114Indonesia
ID118.98.117.75Indonesia
ID119.252.166.100Indonesia
ID119.82.240.46Indonesia
ID180.250.46.10Indonesia
ID180.250.73.2Indonesia
ID202.124.205.101Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.132.58Indonesia
ID202.150.139.134Indonesia
ID202.77.108.60Indonesia
ID202.95.148.206Indonesia
ID203.135.182.250Indonesia
ID203.153.100.83Indonesia
ID203.190.116.11Indonesia
ID222.124.146.108Indonesia
ID223.165.7.34Indonesia
IN103.225.204.32India
IN117.247.244.167India
IN121.247.68.156India
IR194.33.124.42Iran
IR94.182.162.73Iran
MN203.91.119.146Mongolia
PL178.217.34.134Poland
PL91.192.206.101Poland
RU193.107.17.59Russian Federation
TR88.247.164.136Turkey
TW180.176.90.186Taiwan
US198.1.98.214United States
US68.188.75.219United States

List from greylisting:

Botnet Statistics [2015-01-15]

detection period: 2015-01-15 00:00-23:59 UTC
total number of suspected botnet IPs: 898
number of botnet IPs notified to network operators: 848
number of spam blocked: 74978
recipient count of spam blocked: 2767140

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD239
2CRTC92
3UNICOM-GD71
4HINET-NET59
5UNICOM-FJ53
6CHINANET-HN13
7HICHINA11
8CHINANET-JS11
9CMNET10
10UNICOM-CN7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China606
2Taiwan68
3United States42
4Indonesia24
5Viet Nam14
6Brazil13
7South Korea12
8Russian Federation11
9Iran9
10Ukraine7

Thursday, January 15, 2015

Suspected Bot List [2015-01-14]

detection period: 2015-01-14 00:00-23:59 UTC
number of suspected bots' IPs listed here: 88

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
BO200.87.111.202Bolivia
CZ109.238.208.242Czech Republic
ID114.6.45.106Indonesia
ID115.69.221.90Indonesia
ID116.68.251.238Indonesia
ID118.97.175.114Indonesia
ID118.98.117.75Indonesia
ID119.252.166.100Indonesia
ID119.82.240.46Indonesia
ID180.250.167.131Indonesia
ID180.250.46.10Indonesia
ID182.30.251.55Indonesia
ID202.124.205.101Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.132.58Indonesia
ID202.150.139.134Indonesia
ID202.77.108.60Indonesia
ID203.135.182.250Indonesia
ID203.190.116.11Indonesia
ID223.165.7.34Indonesia
IN103.225.204.32India
IN117.247.244.167India
IR194.33.124.42Iran
IT31.199.192.17Italy
MN203.91.119.146Mongolia
PL178.217.34.134Poland
PL91.192.206.101Poland
RU193.107.17.59Russian Federation
TR88.247.164.136Turkey
TW180.176.90.186Taiwan
US174.139.238.172United States
US198.1.98.214United States
US68.188.75.219United States

List from greylisting:

Botnet Statistics [2015-01-14]

detection period: 2015-01-14 00:00-23:59 UTC
total number of suspected botnet IPs: 1166
number of botnet IPs notified to network operators: 1078
number of spam blocked: 142018
recipient count of spam blocked: 4709587

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD334
2CRTC217
3HINET-NET68
4UNICOM-GD51
5UNICOM-FJ31
6CHINANET-JS10
7HICHINA9
8VNPT-VNNIC-VN8
9KORNET-KR8
10CHINANET-SH8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China758
2Taiwan76
3United States41
4Viet Nam28
5Indonesia23
6Brazil22
7Italy15
8Germany15
9South Korea12
10Poland11

Wednesday, January 14, 2015

Suspected Bot List [2015-01-13]

detection period: 2015-01-13 00:00-23:59 UTC
number of suspected bots' IPs listed here: 49

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
BO200.87.111.202Bolivia
CZ109.238.208.242Czech Republic
ID114.6.45.106Indonesia
ID115.69.221.90Indonesia
ID116.68.251.238Indonesia
ID118.97.175.114Indonesia
ID118.98.117.75Indonesia
ID119.252.166.100Indonesia
ID119.82.240.46Indonesia
ID180.250.167.131Indonesia
ID180.250.46.10Indonesia
ID180.250.73.2Indonesia
ID182.30.251.55Indonesia
ID202.124.205.101Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.132.58Indonesia
ID202.150.139.134Indonesia
ID202.182.185.194Indonesia
ID203.135.182.250Indonesia
ID203.190.116.11Indonesia
ID223.165.7.34Indonesia
IN103.225.204.32India
IN117.247.244.167India
IR194.33.124.42Iran
IT31.199.192.17Italy
IT95.227.105.203Italy
MN203.91.119.146Mongolia
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PL178.217.34.134Poland
PL91.192.206.101Poland
TR88.247.164.136Turkey
TW180.176.90.186Taiwan
US174.139.238.172United States
US198.1.98.214United States
US68.188.75.219United States

List from greylisting:

Botnet Statistics [2015-01-13]

detection period: 2015-01-13 00:00-23:59 UTC
total number of suspected botnet IPs: 942
number of botnet IPs notified to network operators: 893
number of spam blocked: 157507
recipient count of spam blocked: 5103765

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD229
2CRTC191
3HINET-NET61
4UNICOM-GD51
5UNICOM-FJ23
6NETBLK-NOBIS-TECHNOLOGY-GROUP-1823
7CHINANET-JX16
8UNICOM-SD8
9UNICOM-HA8
10KORNET-KR7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China643
2Taiwan68
3United States60
4Indonesia23
5Viet Nam18
6Brazil11
7South Korea10
8Iran8
9Hong Kong8
10UNKNOWN6

Tuesday, January 13, 2015

Suspected Bot List [2015-01-12]

detection period: 2015-01-12 00:00-23:59 UTC
number of suspected bots' IPs listed here: 53

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
CZ109.238.208.242Czech Republic
ID114.6.45.106Indonesia
ID115.69.221.90Indonesia
ID116.68.251.238Indonesia
ID118.97.146.106Indonesia
ID118.97.175.114Indonesia
ID119.82.240.46Indonesia
ID119.252.166.100Indonesia
ID180.250.46.10Indonesia
ID180.250.73.2Indonesia
ID182.30.250.46Indonesia
ID202.77.108.60Indonesia
ID202.95.148.206Indonesia
ID202.124.205.101Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.132.58Indonesia
ID202.150.139.134Indonesia
ID202.182.185.194Indonesia
ID203.135.182.250Indonesia
ID203.190.116.11Indonesia
ID223.165.7.34Indonesia
IN117.218.50.134India
IN117.247.244.167India
IR194.33.124.42Iran
IT95.227.105.203Italy
MN203.91.119.146Mongolia
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PL91.192.206.101Poland
PL178.217.34.134Poland
TR88.247.164.136Turkey
TW180.176.90.186Taiwan
US68.188.75.219United States
US174.139.238.172United States
US198.154.63.131United States

List from greylisting:

Botnet Statistics [2015-01-12]

detection period: 2015-01-12 00:00-23:59 UTC
total number of suspected botnet IPs: 875
number of botnet IPs notified to network operators: 822
number of spam blocked: 148247
recipient count of spam blocked: 4895914

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD182
2CRTC121
3UNICOM-GD58
4HINET-NET56
5CHINANET-FJ27
6NETBLK-NOBIS-TECHNOLOGY-GROUP-1823
7UNICOM-FJ20
8UNICOM-HA16
9VNPT-VNNIC-VN10
10CHINANET-SH8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China573
2Taiwan64
3United States55
4Indonesia25
5Viet Nam22
6Russian Federation11
7Brazil11
8Iran10
9UNKNOWN8
10Hong Kong7

Monday, January 12, 2015

Suspected Bots' IP List for January 2015

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here (as shown below) 10 days after its respective botnet statistics gets published.

New data will be added here daily. You are free to use them to create more effective defenses, discover latest trends in cyber attacks, etc.

Suspected Bots IP [2015-01-31]
Suspected Bots IP [2015-01-30]
Suspected Bots IP [2015-01-29]
Suspected Bots IP [2015-01-28]
Suspected Bots IP [2015-01-27]
Suspected Bots IP [2015-01-26]
Suspected Bots IP [2015-01-25]
Suspected Bots IP [2015-01-24]
Suspected Bots IP [2015-01-23]
Suspected Bots IP [2015-01-22]
Suspected Bots IP [2015-01-21]
Suspected Bots IP [2015-01-20]
Suspected Bots IP [2015-01-19]
Suspected Bots IP [2015-01-18]
Suspected Bots IP [2015-01-17]
Suspected Bots IP [2015-01-16]
Suspected Bots IP [2015-01-15]
Suspected Bots IP [2015-01-14]
Suspected Bots IP [2015-01-13]
Suspected Bots IP [2015-01-12]
Suspected Bots IP [2015-01-11]
Suspected Bots IP [2015-01-10]
Suspected Bots IP [2015-01-09]
Suspected Bots IP [2015-01-08]
Suspected Bots IP [2015-01-07]
Suspected Bots IP [2015-01-06]
Suspected Bots IP [2015-01-05]
Suspected Bots IP [2015-01-04]
Suspected Bots IP [2015-01-03]
Suspected Bots IP [2015-01-02]
Suspected Bots IP [2015-01-01]

Suspected Bot List [2015-01-11]

detection period: 2015-01-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 47

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
CZ109.238.208.242Czech Republic
ID114.6.45.106Indonesia
ID118.97.146.106Indonesia
ID118.97.175.114Indonesia
ID119.82.240.46Indonesia
ID119.252.166.100Indonesia
ID180.250.46.10Indonesia
ID180.250.73.2Indonesia
ID202.77.108.60Indonesia
ID202.95.148.206Indonesia
ID202.124.205.101Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.150.132.58Indonesia
ID202.150.139.134Indonesia
ID203.135.182.250Indonesia
ID203.190.116.11Indonesia
ID222.124.146.108Indonesia
ID223.165.7.34Indonesia
IN117.218.50.134India
IN117.247.244.167India
IR194.33.124.42Iran
IT31.199.192.17Italy
MN203.91.119.146Mongolia
PK103.4.92.88Pakistan
PL91.192.206.101Poland
PL178.217.34.134Poland
TR88.247.164.136Turkey
US68.188.75.219United States
US69.197.135.216United States
US198.154.63.131United States

List from greylisting:

Botnet Statistics [2015-01-11]

detection period: 2015-01-11 00:00-23:59 UTC
total number of suspected botnet IPs: 805
number of botnet IPs notified to network operators: 758
number of spam blocked: 144253
recipient count of spam blocked: 4804323

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-GD180
2CRTC117
3UNICOM-GD53
4HINET-NET53
5CHINANET-FJ45
6UNICOM-HA13
7CHINANET-HN8
8CHINANET-SN7
9CHINANET-JX7
10ALISOFT7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China528
2Taiwan59
3United States44
4Indonesia20
5Viet Nam18
6Russian Federation11
7Iran10
8Brazil10
9South Korea7
10Hong Kong7

Sunday, January 11, 2015

Botnet Statistics for the year of 2014

detection period: 2014-01-01 00:00 - 2014-12-31 23:59 UTC
total number of suspected botnet IPs: 476581
number of blocked spams: 26490538
recipient count of blocked spams: 847739355
detection methods: fake open relay + greylisting

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China331136
2Taiwan63427
3United States8916
4Viet Nam8791
5India5983
6Russian Federation5008
7Argentina2991
8Italy2559
9South Korea2511
10Brazil2506
11United Kingdom2464
12Peru2401
13France2220
14Indonesia1651
15Spain1609
16Chile1565
17Germany1479
18Colombia1464
19Poland1424
20Turkey1367
21Mexico1272
22Ukraine1175
23Iran1134
24Isreal1049
25Kazakhstan1034

The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:

RankCountry# of blocked spams
1Taiwan12013880
2China6660858
3United States1149260
4Brazil749321
5Russian Federation715848
6Indonesia663566
7Hong Kong332272
8Saudi Arabia300162
9Iran272697
10Ukraine269034
11India189967
12South Korea184997
13Viet Nam179720
14Poland169709
15United Kingdom154353
16Malaysia150996
17Turkey149129
18Colombia148257
19Ivory Coast135947
20Italy129012
21Thailand117765
22Germany102325
23Bangladesh102004
24Philippines83772
25France74414

The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are: