Custom Search

Thursday, April 28, 2022

Botnet Statistics [2022-04-27]

(To download the latest zombie ip list, please visit the Daily Zombie IP Lists for April 2022. To get an idea of what IP is scanning the Internet currently, please watch: Daily Botnet Detection Live Streaming.)
detection period: 2022-04-27 00:00-23:59 UTC
total number of suspected botnet IPs: 27159
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 25316
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by the number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1ACEVILLEPTELTD-SG1633
2DIGITALOCEAN-192-241-128-0940
3VNPT-VN527
4CMNET473
5Baidu415
6VIETTEL-VN387
7ALISOFT361
8BSNLNET316
9HINET-NET313
10MSFT268


The top 10 countries (as defined by the 2-character country code), ordered by the number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1United States5161
2China4225
3Singapore1763
4India1733
5Russian Federation1457
6Viet Nam1311
7Brazil1153
8Indonesia738
9Hong Kong641
10Taiwan513

The top 10 TCP ports, ordered by the number of connection attempts received are:

RankTCP port number# of connection attempts received
1122279464
2422262389
3622259045
4522255864
5322239985
66699116183
7912279634
8302159966
92351499
10600250970

20220428 Botnet Detection Live Streaming 1200+ zombies detected)

1 comment:

  1. Hello. You might want to remove TOR exit nodes from the list of attackers before you send email to their abuse address. Or rather, TOR operators all over the world might want you to do that. :-P

    ReplyDelete