Custom Search

Thursday, April 2, 2015

Botnet Statistics [2015-04-01]

detection period: 2015-04-01 00:00-23:59 UTC
total number of suspected botnet IPs: 1821
number of botnet IPs notified to network operators: 1726
number of spam blocked: 210287
recipient count of spam blocked: 7175602

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET965
2UNICOM-GD73
3CHINANET-GD35
4UNICOM-FJ28
5CCCH3-413
6UNICOM-BJ11
7WASU-BB10
8ALISOFT9
9KORNET-KR8
10CHINANET-ZJ-HZ8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan978
2China335
3United States170
4Canada23
5India20
6South Korea19
7Indonesia18
8Russian Federation16
9Turkey14
10Spain14

Wednesday, April 1, 2015

Suspected Bot List [2015-03-31]

detection period: 2015-03-31 00:00-23:59 UTC
number of suspected bots' IPs listed here: 164

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD180.211.193.190Bangladesh
BD203.76.147.62Bangladesh
CI213.136.105.210Ivory Coast
CI213.136.105.212Ivory Coast
CM195.24.217.58Cameroon
EC201.219.60.86Ecuador
EC201.219.60.118Ecuador
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID203.201.172.162Indonesia
MN203.91.119.146Mongolia
MX200.94.141.149Mexico
PE200.1.183.82Peru
US69.197.156.227United States
US96.35.58.176United States
US209.220.168.177United States

List from greylisting:

Botnet Statistics [2015-03-31]

detection period: 2015-03-31 00:00-23:59 UTC
total number of suspected botnet IPs: 2347
number of botnet IPs notified to network operators: 2183
number of spam blocked: 207859
recipient count of spam blocked: 7012235

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET970
2UNICOM-GD101
3CHINANET-GD28
4CCCH3-423
5CBC-CM-420
6UNICOM-FJ19
7WASU-BB11
8NETBLK-CHARTER-NET11
9CRTC10
10CMNET10

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan983
2United States365
3China339
4Canada66
5France47
6Russian Federation42
7United Kingdom37
8Spain37
9Germany25
10Turkey21