Custom Search

Monday, July 31, 2017

Botnet Statistics [2017-07-30]

detection period: 2017-07-30 00:00-23:59 UTC
total number of suspected botnet IPs: 478
number of botnet IPs notified to network operators: 435
number of spam blocked: 82317
recipient count of spam blocked: 2161008

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HOST4GEEKS53
2Baidu39
3WASU35
4CMNET35
5CHINANET-HA24
6CHINANET-JS20
7EONIX-NET-173-44-128-0-1-BLK-417
8EONIX-NET-50-2-0-0-1-BLK-716
9CLOUD-SOUTH16
10CHINANET-HB15

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China274
2United States92
3Hong Kong54
4Netherlands11
5Russian Federation9
6Taiwan5
7South Korea5
8Brazil3
9Turkey2
10Saint Kitts And Nevis2

Suspected Bot List [2017-07-30]

detection period: 2017-07-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 43

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN203.115.99.218India
MO116.193.10.34Macau
RU91.197.234.102Russian Federation
ZA196.46.23.122South Africa

List from greylisting:

Sunday, July 30, 2017

Botnet Statistics [2017-07-29]

detection period: 2017-07-29 00:00-23:59 UTC
total number of suspected botnet IPs: 402
number of botnet IPs notified to network operators: 368
number of spam blocked: 94597
recipient count of spam blocked: 2523898

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HOST4GEEKS41
2CMNET39
3Baidu39
4CC-1723
5SHARKTECH-317
6CHINANET-GD14
7CHINANET-ZJ13
8CHINANET-JS12
9EONIX-NET-173-44-128-0-1-BLK-411
10SERVERCRATE-0310

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China184
2United States92
3Hong Kong42
4Netherlands11
5Poland10
6Russian Federation9
7Taiwan7
8Viet Nam4
9India4
10South Africa3

Suspected Bot List [2017-07-29]

detection period: 2017-07-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 34

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN203.115.99.218India
MO116.193.10.34Macau
RU91.197.234.102Russian Federation
US206.125.41.139United States
ZA196.46.23.122South Africa

List from greylisting:

Saturday, July 29, 2017

Botnet Statistics [2017-07-28]

detection period: 2017-07-28 00:00-23:59 UTC
total number of suspected botnet IPs: 656
number of botnet IPs notified to network operators: 596
number of spam blocked: 55938
recipient count of spam blocked: 1185101

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET94
2WASU69
3HOST4GEEKS44
4Baidu39
5SHARKTECH-329
6UNICOM-ZJ28
7dhakavoice26
8EONIX-NET-170-130-0-0-1-BLK-1117
9CHINANET-HA17
10HOSTKEY-NET16

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China329
2United States99
3Hong Kong45
4United Kingdom38
5Russian Federation26
6India21
7Poland15
8Netherlands11
9Viet Nam9
10Taiwan8

Suspected Bot List [2017-07-28]

detection period: 2017-07-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 60

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN203.115.99.218India
MO116.193.10.34Macau
MO116.193.10.35Macau
RU91.197.234.102Russian Federation

List from greylisting:

Friday, July 28, 2017

Botnet Statistics [2017-07-27]

detection period: 2017-07-27 00:00-23:59 UTC
total number of suspected botnet IPs: 790
number of botnet IPs notified to network operators: 777
number of spam blocked: 25313
recipient count of spam blocked: 272103

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET97
2WASU71
3HOST4GEEKS69
4CHINANET-HB60
5UNICOM-ZJ52
6Baidu39
7UNICOM-HB29
8SHARKTECH-329
9EONIX-NET-173-44-128-0-1-BLK-428
10PL-ARTNET-2012070420

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China459
2United States123
3Hong Kong72
4Poland30
5Netherlands24
6United Kingdom19
7Taiwan13
8Russian Federation8
9Viet Nam5
10Italy3

Suspected Bot List [2017-07-27]

detection period: 2017-07-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 13

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN203.115.99.218India
MO116.193.10.34Macau

List from greylisting:

Thursday, July 27, 2017

Botnet Statistics [2017-07-26]

detection period: 2017-07-26 00:00-23:59 UTC
total number of suspected botnet IPs: 693
number of botnet IPs notified to network operators: 654
number of spam blocked: 23307
recipient count of spam blocked: 241387

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU59
2CMNET59
3HOST4GEEKS54
4CHINANET-HB49
5Baidu39
6UNICOM-HB32
7CHINANET-JS32
8UNICOM-ZJ28
9SERVERCRATE-0323
10HINET-NET19

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China372
2United States122
3Hong Kong58
4Netherlands26
5Taiwan21
6Poland12
7Viet Nam9
8Russian Federation8
9India8
10Germany5

Suspected Bot List [2017-07-26]

detection period: 2017-07-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 39

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN203.115.99.218India
MO116.193.10.34Macau
RU91.197.234.102Russian Federation
US206.125.41.139United States

List from greylisting:

Wednesday, July 26, 2017

Botnet Statistics [2017-07-25]

detection period: 2017-07-25 00:00-23:59 UTC
total number of suspected botnet IPs: 727
number of botnet IPs notified to network operators: 707
number of spam blocked: 25165
recipient count of spam blocked: 240432

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET116
2WASU73
3CHINANET-HB56
4Baidu39
5HOST4GEEKS34
6SHARKTECH-329
7CHINANET-JS28
8UNICOM-HB27
9UNICOM-ZJ26
10UA-LIRUCC-2014070826

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China448
2United States93
3Hong Kong37
4Poland29
5Ukraine26
6Taiwan19
7Netherlands15
8Russian Federation11
9South Korea5
10Italy4

Suspected Bot List [2017-07-25]

detection period: 2017-07-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 20

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN203.115.99.218India
MO116.193.10.34Macau
US23.129.64.11United States
US23.129.64.12United States
US23.129.64.13United States
US23.129.64.14United States
US206.125.41.139United States

List from greylisting:

Tuesday, July 25, 2017

Botnet Statistics [2017-07-24]

detection period: 2017-07-24 00:00-23:59 UTC
total number of suspected botnet IPs: 771
number of botnet IPs notified to network operators: 713
number of spam blocked: 78611
recipient count of spam blocked: 1615147

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET82
2CHINANET-JS57
3WASU52
4CHINANET-HB50
5HOST4GEEKS41
6Baidu30
7EONIX-NET-50-2-0-0-1-BLK-726
8UNICOM-ZJ24
9CC-1024
10UNICOM-HB22

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China428
2United States146
3Hong Kong45
4Russian Federation17
5Poland15
6Netherlands13
7Singapore12
8Taiwan11
9Italy8
10Ukraine6

Suspected Bot List [2017-07-24]

detection period: 2017-07-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 58

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.110.72.131Arab Emirates
ID219.83.84.146Indonesia
IN203.115.99.218India
LY197.215.136.166Libya
MO116.193.10.34Macau
MX189.211.198.181Mexico
NO193.150.121.66Norway
RU90.188.95.206Russian Federation
RU91.197.234.102Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
ZA196.46.23.122South Africa

List from greylisting:

Monday, July 24, 2017

Botnet Statistics [2017-07-23]

detection period: 2017-07-23 00:00-23:59 UTC
total number of suspected botnet IPs: 644
number of botnet IPs notified to network operators: 595
number of spam blocked: 64694
recipient count of spam blocked: 1664933

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-ZJ51
2WASU50
3CMNET46
4CHINANET-HB41
5CHINANET-JS38
6CLOUD-SOUTH32
7Baidu30
8HOST4GEEKS25
9EONIX-NET-173-44-128-0-1-BLK-418
10HINET-NET13

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China404
2United States108
3Hong Kong30
4Taiwan14
5Russian Federation14
6Singapore13
7Germany6
8South Korea5
9Italy5
10France4

Suspected Bot List [2017-07-23]

detection period: 2017-07-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 50

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN203.115.99.218India
LY197.215.136.166Libya
MO116.193.10.34Macau
MX189.211.198.181Mexico
MY161.139.20.49Malaysia
NO193.150.121.66Norway
RU91.197.234.102Russian Federation
RU185.127.25.68Russian Federation
RU194.79.7.70Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
TH203.144.162.142Thailand
US206.125.41.139United States
ZA196.46.23.122South Africa

List from greylisting:

Sunday, July 23, 2017

Botnet Statistics [2017-07-22]

detection period: 2017-07-22 00:00-23:59 UTC
total number of suspected botnet IPs: 535
number of botnet IPs notified to network operators: 510
number of spam blocked: 69749
recipient count of spam blocked: 1724837

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET58
2UNICOM-ZJ42
3HOST4GEEKS42
4CHINANET-JS39
5CHINANET-ZJ27
6WASU23
7Baidu21
8CLOUD-SOUTH16
9CHINANET-HB13
10SERVERCRATE12

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China302
2United States106
3Hong Kong46
4Singapore12
5Russian Federation11
6Taiwan7
7Brazil6
8Germany5
9Italy4
10France4

Suspected Bot List [2017-07-22]

detection period: 2017-07-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 26

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
LY197.215.136.166Libya
RU78.107.233.237Russian Federation
RU89.111.177.211Russian Federation
RU90.188.95.206Russian Federation
RU91.197.234.102Russian Federation
RU185.127.25.68Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
TH61.7.228.51Thailand
US206.125.41.139United States

List from greylisting:

Saturday, July 22, 2017

Botnet Statistics [2017-07-21]

detection period: 2017-07-21 00:00-23:59 UTC
total number of suspected botnet IPs: 861
number of botnet IPs notified to network operators: 799
number of spam blocked: 88272
recipient count of spam blocked: 2034731

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET77
2CHINANET-HB68
3CHINANET-JS62
4HOST4GEEKS61
5UNICOM-HB44
6WASU41
7UNICOM-ZJ34
8SHARKTECH-329
9Baidu20
10ThrustVPS_PT15

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China500
2United States138
3Hong Kong65
4Russian Federation17
5United Kingdom15
6Singapore12
7India12
8Viet Nam10
9Netherlands10
10Republic Of Moldova10

Suspected Bot List [2017-07-21]

detection period: 2017-07-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 62

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
FR185.42.178.130France
IN122.174.69.252India
LY197.215.136.166Libya
MX189.211.198.181Mexico
PL91.185.189.179Poland
RU91.197.234.102Russian Federation
RU185.127.25.68Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
TH61.7.228.51Thailand
US71.10.36.98United States
US206.125.41.139United States
US216.176.186.131United States
US216.176.186.132United States
US216.176.186.133United States
US216.176.186.134United States

List from greylisting:

Friday, July 21, 2017

Botnet Statistics [2017-07-20]

detection period: 2017-07-20 00:00-23:59 UTC
total number of suspected botnet IPs: 920
number of botnet IPs notified to network operators: 853
number of spam blocked: 94272
recipient count of spam blocked: 2140063

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-HB126
2CMNET109
3WASU78
4CHINANET-JS61
5UNICOM-HB45
6PSINETA29
7UNICOM-ZJ24
8CHINANET-GD23
9Baidu22
10HOST4GEEKS20

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China604
2United States131
3Netherlands24
4Hong Kong24
5Russian Federation19
6Poland15
7Germany14
8Singapore12
9Taiwan8
10Viet Nam7

Suspected Bot List [2017-07-20]

detection period: 2017-07-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 67

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.110.72.131Arab Emirates
ID219.83.84.146Indonesia
IN106.201.37.191India
IN106.201.116.222India
IN110.227.108.231India
LY197.215.136.166Libya
MO116.193.10.34Macau
MX189.211.198.181Mexico
MY161.139.20.49Malaysia
PH210.1.87.118Philippines
PL91.185.189.179Poland
RU91.197.234.102Russian Federation
RU194.79.7.70Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
US206.125.41.139United States
US216.176.186.131United States
US216.176.186.132United States
US216.176.186.133United States
US216.176.186.134United States
ZA196.46.23.122South Africa

List from greylisting:

Thursday, July 20, 2017

Botnet Statistics [2017-07-19]

detection period: 2017-07-19 00:00-23:59 UTC
total number of suspected botnet IPs: 1017
number of botnet IPs notified to network operators: 969
number of spam blocked: 116636
recipient count of spam blocked: 2803077

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET135
2WASU111
3UNICOM-ZJ96
4CHINANET-HB63
5CHINANET-JS52
6CHINANET-GD37
7UNICOM-HB33
8MELBICOM-NL29
9HOSTKEY-NET28
10HOST4GEEKS23

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China667
2United States90
3Russian Federation49
4Netherlands28
5Hong Kong27
6Viet Nam19
7Germany15
8Singapore13
9Poland13
10Taiwan12

Suspected Bot List [2017-07-19]

detection period: 2017-07-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 48

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
FR185.42.178.130France
ID219.83.84.146Indonesia
IN1.186.128.5India
IN182.73.244.70India
IN203.115.99.218India
KW37.34.243.227Kuwait
LY197.215.136.166Libya
MO116.193.10.34Macau
MX148.243.192.238Mexico
PL91.185.189.179Poland
RS24.135.172.134Serbia
RU90.188.18.74Russian Federation
RU91.197.234.102Russian Federation
RU194.79.7.70Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
TH61.7.228.51Thailand
TH203.146.249.104Thailand
US206.125.41.139United States
ZA196.46.23.122South Africa

List from greylisting:

Wednesday, July 19, 2017

Botnet Statistics [2017-07-18]

detection period: 2017-07-18 00:00-23:59 UTC
total number of suspected botnet IPs: 1049
number of botnet IPs notified to network operators: 995
number of spam blocked: 124506
recipient count of spam blocked: 3048600

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-ZJ188
2WASU112
3CMNET82
4CHINANET-JS62
5CHINANET-GD44
6CHINANET-HB41
7SHARKTECH-329
8LU-ROOT-2008102125
9UNICOM-HB20
10HOST4GEEKS19

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China699
2United States116
3Luxembourg26
4Russian Federation25
5Hong Kong24
6Germany19
7Netherlands15
8Singapore13
9India13
10Viet Nam9

Suspected Bot List [2017-07-18]

detection period: 2017-07-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 54

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
CN111.231.0.79China
CN118.89.153.22China
CN118.89.163.233China
ID219.83.84.146Indonesia
IN171.60.196.13India
IN182.64.70.26India
IN182.73.97.202India
IN203.115.99.218India
LY197.215.136.166Libya
MY161.139.20.49Malaysia
NO193.150.121.66Norway
PL91.185.189.179Poland
RU90.188.18.74Russian Federation
RU91.197.234.102Russian Federation
RU194.79.7.70Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
US206.125.41.139United States
ZA196.46.23.122South Africa

List from greylisting:

Tuesday, July 18, 2017

Suspected Bots' IP List for June 2017

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here (as shown below). You are free to use them to create more effective defenses, discover latest trends in cyber attacks, etc.

Suspected Bots IP [2017-06-01]
Suspected Bots IP [2017-06-02]
Suspected Bots IP [2017-06-03]
Suspected Bots IP [2017-06-04]
Suspected Bots IP [2017-06-05]
Suspected Bots IP [2017-06-06]
Suspected Bots IP [2017-06-07]
Suspected Bots IP [2017-06-08]
Suspected Bots IP [2017-06-09]
Suspected Bots IP [2017-06-10]
Suspected Bots IP [2017-06-11]
Suspected Bots IP [2017-06-12]
Suspected Bots IP [2017-06-13]
Suspected Bots IP [2017-06-14]
Suspected Bots IP [2017-06-15]
Suspected Bots IP [2017-06-16]
Suspected Bots IP [2017-06-17]
Suspected Bots IP [2017-06-18]
Suspected Bots IP [2017-06-19]
Suspected Bots IP [2017-06-20]
Suspected Bots IP [2017-06-21]
Suspected Bots IP [2017-06-22]
Suspected Bots IP [2017-06-23]
Suspected Bots IP [2017-06-24]
Suspected Bots IP [2017-06-25]
Suspected Bots IP [2017-06-26]
Suspected Bots IP [2017-06-27]
Suspected Bots IP [2017-06-28]
Suspected Bots IP [2017-06-29]
Suspected Bots IP [2017-06-30]

Botnet Statistics [2017-07-17]

detection period: 2017-07-17 00:00-23:59 UTC
total number of suspected botnet IPs: 1195
number of botnet IPs notified to network operators: 1153
number of spam blocked: 65049
recipient count of spam blocked: 1473608

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-ZJ201
2WASU180
3CMNET118
4CHINANET-JS96
5CHINANET-GD42
6CHINANET-HB28
7dhakavoice26
8UNICOM-JS23
9LSN-DLLSTX-220
10VPLSNET17

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China840
2United States143
3United Kingdom28
4Russian Federation27
5Netherlands21
6Hong Kong19
7Germany17
8Poland16
9Taiwan15
10Singapore13

Suspected Bot List [2017-07-17]

detection period: 2017-07-17 00:00-23:59 UTC
number of suspected bots' IPs listed here: 42

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
ID219.83.84.146Indonesia
IN203.115.99.218India
LY197.215.136.166Libya
MX189.211.198.181Mexico
MY161.139.20.49Malaysia
PL91.185.189.179Poland
RU90.188.95.206Russian Federation
RU91.197.234.102Russian Federation
RU91.201.117.228Russian Federation
RU194.79.7.70Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
US206.125.41.139United States
ZA196.46.23.122South Africa

List from greylisting:

Monday, July 17, 2017

Botnet Statistics [2017-07-16]

detection period: 2017-07-16 00:00-23:59 UTC
total number of suspected botnet IPs: 966
number of botnet IPs notified to network operators: 883
number of spam blocked: 76693
recipient count of spam blocked: 1727435

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-ZJ179
2WASU135
3CMNET95
4CHINANET-JS59
5CHINANET-GD45
6EONIX-NET-173-44-128-0-1-BLK-429
7VPLSNET18
8PVS-BLOCK0216
9UNICOM-JS15
10SERVERCRATE-0313

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China691
2United States124
3Russian Federation21
4Netherlands20
5Germany14
6Singapore12
7Poland9
8Taiwan5
9Hong Kong5
10France5

Suspected Bot List [2017-07-16]

detection period: 2017-07-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 83

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
ID219.83.84.146Indonesia
IN203.115.99.218India
MO116.193.10.34Macau
MY161.139.20.49Malaysia
PK202.83.163.219Pakistan
PL91.185.189.179Poland
RU90.188.95.206Russian Federation
RU194.79.7.70Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
TH61.7.228.51Thailand
US206.125.41.139United States
ZA196.46.23.122South Africa

List from greylisting:

Sunday, July 16, 2017

Botnet Statistics [2017-07-15]

detection period: 2017-07-15 00:00-23:59 UTC
total number of suspected botnet IPs: 688
number of botnet IPs notified to network operators: 653
number of spam blocked: 94788
recipient count of spam blocked: 2120235

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-ZJ109
2WASU73
3CHINANET-JS54
4CMNET36
5CHINANET-GD35
6CHINANET-HA23
7HINET-NET22
8CHINANET-AH21
9SERVERYOU-NET-LAX17
10CHINANET-HN15

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China476
2United States80
3Taiwan22
4Russian Federation19
5Singapore13
6Poland11
7Germany9
8France5
9South Korea4
10Viet Nam3

Suspected Bot List [2017-07-15]

detection period: 2017-07-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 36

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN203.115.99.218India
LY197.215.136.166Libya
MO116.193.10.34Macau
MO116.193.10.35Macau
MY161.139.20.49Malaysia
PK202.83.163.219Pakistan
PL91.185.189.179Poland
RU90.188.95.206Russian Federation
RU91.197.234.102Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
TH61.7.228.51Thailand
TH203.151.206.113Thailand
US206.125.41.139United States
ZA196.46.23.122South Africa

List from greylisting:

Saturday, July 15, 2017

Botnet Statistics [2017-07-14]

detection period: 2017-07-14 00:00-23:59 UTC
total number of suspected botnet IPs: 675
number of botnet IPs notified to network operators: 657
number of spam blocked: 77064
recipient count of spam blocked: 1810016

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-ZJ130
2WASU74
3CMNET56
4CHINANET-JS44
5CHINANET-AH32
6CHINANET-GD31
7CHINANET-HN24
8HINET-NET18
9CHINANET-HA18
10ALISOFT15

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China528
2United States25
3Russian Federation23
4Taiwan18
5Singapore10
6South Korea6
7Italy4
8Hong Kong4
9France4
10Germany4

Suspected Bot List [2017-07-14]

detection period: 2017-07-14 00:00-23:59 UTC
number of suspected bots' IPs listed here: 18

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
LY197.215.136.166Libya
MO116.193.10.34Macau
NO193.150.121.66Norway
PL91.185.189.179Poland
RU90.188.95.206Russian Federation
RU91.197.234.102Russian Federation
RU194.67.184.222Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
TH203.151.206.113Thailand
US206.125.41.139United States
ZA196.46.23.122South Africa

List from greylisting:

Friday, July 14, 2017

Botnet Statistics [2017-07-13]

detection period: 2017-07-13 00:00-23:59 UTC
total number of suspected botnet IPs: 740
number of botnet IPs notified to network operators: 726
number of spam blocked: 41430
recipient count of spam blocked: 750712

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU145
2UNICOM-ZJ125
3CMNET69
4CHINANET-AH58
5CHINANET-HN41
6CHINANET-GD41
7CHINANET-JS32
8ALISOFT16
9CHINANET-HA12
10Baidu11

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China635
2United States19
3Russian Federation13
4Taiwan10
5Netherlands5
6South Korea5
7Germany5
8Italy4
9Brazil4
10Ukraine2

Suspected Bot List [2017-07-13]

detection period: 2017-07-13 00:00-23:59 UTC
number of suspected bots' IPs listed here: 14

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
CA72.55.186.57Canada
IN203.115.99.218India
MK62.162.139.19Macedonia
MO116.193.10.34Macau
RU91.197.234.102Russian Federation
RU194.67.184.222Russian Federation
ZA196.46.23.122South Africa

List from greylisting:

Thursday, July 13, 2017

Botnet Statistics [2017-07-12]

detection period: 2017-07-12 00:00-23:59 UTC
total number of suspected botnet IPs: 841
number of botnet IPs notified to network operators: 815
number of spam blocked: 36854
recipient count of spam blocked: 795998

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU169
2UNICOM-ZJ158
3CMNET106
4CHINANET-JS50
5CHINANET-GD48
6CHINANET-AH37
7ALISOFT23
8CHINANET-HB15
9CHINANET-ZJ-JH9
10CHINANET-ZJ9

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China719
2United States33
3Russian Federation14
4Brazil7
5South Korea6
6Viet Nam5
7Italy5
8India4
9Taiwan3
10Iran3

Suspected Bot List [2017-07-12]

detection period: 2017-07-12 00:00-23:59 UTC
number of suspected bots' IPs listed here: 26

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN203.115.99.218India
MO116.193.10.34Macau
MO116.193.10.35Macau
MX148.243.192.238Mexico
PK202.61.51.123Pakistan
RU83.242.139.67Russian Federation
RU91.197.234.102Russian Federation
RU109.111.189.234Russian Federation
RU194.67.184.222Russian Federation
SA212.76.76.242Saudi Arabia
SG112.140.187.82Singapore
TH203.156.163.35Thailand
UY167.57.140.123Uruguay
ZA196.46.23.122South Africa

List from greylisting:

Wednesday, July 12, 2017

Botnet Statistics [2017-07-11]

detection period: 2017-07-11 00:00-23:59 UTC
total number of suspected botnet IPs: 844
number of botnet IPs notified to network operators: 811
number of spam blocked: 70961
recipient count of spam blocked: 823835

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET140
2UNICOM-ZJ133
3WASU117
4CHINANET-GD40
5MELBICOM-DE27
6CHINANET-AH27
7CHINANET-JS24
8CHINANET-ZJ20
9CHINANET-HA13
10CC-1712

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China636
2United States79
3Russian Federation42
4Hong Kong8
5Viet Nam7
6South Korea7
7Taiwan6
8Colombia4
9Brazil4
10Ukraine3

Suspected Bot List [2017-07-11]

detection period: 2017-07-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 33

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
ID103.254.107.10Indonesia
IN203.115.99.218India
MO116.193.10.34Macau
MO116.193.10.35Macau
RU80.254.115.87Russian Federation
RU83.242.222.4Russian Federation
RU91.197.234.102Russian Federation
RU95.53.247.194Russian Federation
RU194.67.184.222Russian Federation
SA212.76.76.242Saudi Arabia
TH61.19.202.171Thailand
TH122.154.239.122Thailand
TH123.242.161.20Thailand
UY167.57.1.221Uruguay
ZA196.46.23.122South Africa

List from greylisting:

Monday, July 10, 2017

Botnet Statistics [2017-07-09]

detection period: 2017-07-09 00:00-23:59 UTC
total number of suspected botnet IPs: 558
number of botnet IPs notified to network operators: 505
number of spam blocked: 62327
recipient count of spam blocked: 913359

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-ZJ107
2CMNET95
3WASU93
4EONIX-NET-173-44-128-0-1-BLK-416
5CHINANET-GD16
6SERVERYOU-NET-LAX14
7AHRDIRECT-NET14
8EONIX-NET-50-2-0-0-1-BLK-713
9BG-POWERNET-2007073113
10CC-1712

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China368
2United States79
3Netherlands16
4Russian Federation13
5Bulgaria13
6South Korea11
7Taiwan6
8Viet Nam4
9Italy3
10India3

Suspected Bot List [2017-07-09]

detection period: 2017-07-09 00:00-23:59 UTC
number of suspected bots' IPs listed here: 54

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN1.186.128.5India
IN122.165.237.29India
MO116.193.10.35Macau
MX148.243.192.238Mexico
NO193.150.121.66Norway
PK202.61.49.204Pakistan
PL91.185.189.179Poland
RU81.23.145.254Russian Federation
RU91.197.234.102Russian Federation
RU95.53.247.194Russian Federation
RU95.165.236.130Russian Federation
SA212.76.76.242Saudi Arabia
TH122.154.239.122Thailand
TH203.151.206.113Thailand
UY167.57.124.15Uruguay
ZA196.46.23.122South Africa

List from greylisting:

Sunday, July 9, 2017

Botnet Statistics [2017-07-08]

detection period: 2017-07-08 00:00-23:59 UTC
total number of suspected botnet IPs: 324
number of botnet IPs notified to network operators: 264
number of spam blocked: 53061
recipient count of spam blocked: 896992

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-ZJ49
2SHUB-NETBLK-DAL29
3WASU21
4CMNET19
5NL-HOSTKEY16
6COLOAT11
7CC-1011
8JOESDC-0110
9EONIX-NET-50-2-0-0-1-BLK-77
10CHINANET-GD7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China136
2United States90
3Netherlands18
4Russian Federation13
5Taiwan7
6South Korea6
7Hong Kong5
8Italy4
9Viet Nam3
10Thailand3

Suspected Bot List [2017-07-08]

detection period: 2017-07-08 00:00-23:59 UTC
number of suspected bots' IPs listed here: 60

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN203.115.99.218India
MO116.193.10.34Macau
MO116.193.10.35Macau
NO193.150.121.66Norway
SA212.76.76.242Saudi Arabia
SG112.140.187.82Singapore
TH123.242.161.20Thailand
TH203.146.249.104Thailand
TH203.151.206.113Thailand
UY167.57.148.137Uruguay
ZA196.46.23.122South Africa

List from greylisting:

Saturday, July 8, 2017

Botnet Statistics [2017-07-07]

detection period: 2017-07-07 00:00-23:59 UTC
total number of suspected botnet IPs: 699
number of botnet IPs notified to network operators: 670
number of spam blocked: 96670
recipient count of spam blocked: 1922629

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-ZJ169
2WASU96
3CMNET78
4CUBEMOTION34
5CHINANET-JS17
6HOSTKEY-NET16
7CC-1812
8UNIFIEDLAYER-NETWORK-119
9CHINANET-GD8
10ALISOFT8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China467
2United States75
3Russian Federation21
4Netherlands18
5Poland13
6Singapore10
7Italy8
8South Korea7
9Brazil7
10Taiwan6

Suspected Bot List [2017-07-07]

detection period: 2017-07-07 00:00-23:59 UTC
number of suspected bots' IPs listed here: 29

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR200.41.87.215Argentina
IN203.115.99.218India
MO116.193.10.34Macau
MO116.193.10.35Macau
MX148.243.192.238Mexico
NO193.150.121.66Norway
PK202.83.163.219Pakistan
RU90.188.18.74Russian Federation
RU90.188.95.206Russian Federation
RU91.197.234.102Russian Federation
RU109.111.189.234Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
TH61.7.228.51Thailand
TH122.154.239.122Thailand
TH203.151.206.113Thailand
TH203.156.163.35Thailand
US206.125.41.139United States
VE150.187.41.90Venezuela
ZA196.46.23.122South Africa

List from greylisting:

Friday, July 7, 2017

Botnet Statistics [2017-07-06]

detection period: 2017-07-06 00:00-23:59 UTC
total number of suspected botnet IPs: 782
number of botnet IPs notified to network operators: 737
number of spam blocked: 102100
recipient count of spam blocked: 1965266

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-ZJ127
2WASU103
3CMNET91
4CHINANET-JS30
5SERVERCRATE25
6ALISOFT25
7BG-POWERNET-2007073122
8CHINANET-GD20
9CHINANET-HA15
10EONIX-NET-50-2-0-0-1-BLK-712

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China500
2United States113
3Russian Federation23
4Bulgaria22
5Germany16
6Singapore11
7Taiwan10
8Poland8
9Hong Kong7
10South Korea6

Suspected Bot List [2017-07-06]

detection period: 2017-07-06 00:00-23:59 UTC
number of suspected bots' IPs listed here: 45

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.110.72.131Arab Emirates
AR200.41.87.215Argentina
ID219.83.84.146Indonesia
IN203.115.99.218India
MO116.193.10.34Macau
MO116.193.10.35Macau
MX189.211.198.181Mexico
NO193.150.121.66Norway
PK202.83.163.219Pakistan
PL91.185.189.179Poland
RU91.197.234.102Russian Federation
RU109.111.189.234Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
TH61.7.228.51Thailand
TH203.151.206.113Thailand
US206.125.41.139United States
ZA196.46.23.122South Africa

List from greylisting:

Thursday, July 6, 2017

Botnet Statistics [2017-07-05]

detection period: 2017-07-05 00:00-23:59 UTC
total number of suspected botnet IPs: 874
number of botnet IPs notified to network operators: 840
number of spam blocked: 114671
recipient count of spam blocked: 2229423

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-ZJ164
2WASU109
3CMNET95
4CHINANET-JS44
5CC-1522
6CHINANET-GD18
7PVS-BLOCK0216
8CHINANET-HA16
9ALISOFT14
10VIRPUS-KC-212

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China566
2United States111
3Russian Federation31
4Netherlands18
5Singapore12
6Poland12
7Romania10
8Taiwan9
9Hong Kong9
10South Korea8

Suspected Bot List [2017-07-05]

detection period: 2017-07-05 00:00-23:59 UTC
number of suspected bots' IPs listed here: 34

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.110.72.131Arab Emirates
ID219.83.84.146Indonesia
IN203.115.99.218India
MO116.193.10.34Macau
MO116.193.10.35Macau
MX189.211.198.181Mexico
PK202.83.163.219Pakistan
PL91.185.189.179Poland
RU31.173.216.163Russian Federation
RU82.179.134.236Russian Federation
RU87.226.213.86Russian Federation
RU109.194.197.79Russian Federation
RU185.76.145.20Russian Federation
RU185.127.25.68Russian Federation
RU195.98.189.178Russian Federation
RU195.190.124.202Russian Federation
RU212.34.39.230Russian Federation
RU212.46.215.107Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
TH103.40.132.18Thailand
TH203.146.249.104Thailand
TH203.151.206.113Thailand
US71.14.28.163United States
US96.33.171.230United States
US206.125.41.139United States
VE150.187.41.90Venezuela
ZA196.46.23.122South Africa

List from greylisting:

Wednesday, July 5, 2017

Botnet Statistics [2017-07-04]

detection period: 2017-07-04 00:00-23:59 UTC
total number of suspected botnet IPs: 910
number of botnet IPs notified to network operators: 856
number of spam blocked: 104680
recipient count of spam blocked: 2087985

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-ZJ182
2WASU107
3CMNET103
4CHINANET-JS32
5MELBICOM-NL30
6CUBEMOTION23
7CHINANET-GD19
8VNPT-VNNIC-VN18
9SERVERYOU-NET-LAX18
10CHINANET-HA15

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China579
2United States85
3Russian Federation63
4Viet Nam33
5Brazil14
6India13
7Singapore12
8Taiwan9
9Poland8
10France7

Suspected Bot List [2017-07-04]

detection period: 2017-07-04 00:00-23:59 UTC
number of suspected bots' IPs listed here: 54

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.110.72.131Arab Emirates
DZ193.194.86.122Algeria
IN203.115.99.218India
LY197.215.136.166Libya
MO116.193.10.34Macau
MO116.193.10.35Macau
MX189.211.198.181Mexico
MX201.163.21.226Mexico
NO193.150.121.66Norway
PK202.83.163.219Pakistan
PL91.185.189.179Poland
RS89.216.28.123Serbia
RU37.1.11.205Russian Federation
RU37.29.7.122Russian Federation
RU62.183.72.122Russian Federation
RU82.179.134.236Russian Federation
RU87.226.213.86Russian Federation
RU90.188.18.74Russian Federation
RU91.122.195.202Russian Federation
RU91.197.234.102Russian Federation
RU109.94.95.237Russian Federation
RU109.111.189.234Russian Federation
RU109.171.97.88Russian Federation
RU176.118.237.85Russian Federation
RU178.141.249.246Russian Federation
RU185.52.69.197Russian Federation
RU185.76.145.20Russian Federation
RU185.127.25.68Russian Federation
RU194.67.184.222Russian Federation
RU194.79.7.70Russian Federation
RU195.98.189.178Russian Federation
RU195.190.124.202Russian Federation
RU212.46.215.107Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
TH103.40.132.18Thailand
TH203.151.206.113Thailand
TW106.1.195.68Taiwan
US96.33.171.230United States
US206.125.41.139United States
ZA196.46.23.122South Africa

List from greylisting: