Custom Search

Thursday, November 3, 2016

Suspected Bot List [2016-11-02]

detection period: 2016-11-02 00:00-23:59 UTC
number of suspected bots' IPs listed here: 129

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.3.117.90Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
CZ89.203.148.35Czech Republic
DZ193.194.69.36Algeria
ES193.219.103.119Spain
GA197.231.143.72Gabon
GA197.231.143.82Gabon
GA197.231.143.96Gabon
IN125.16.240.197India
IN182.71.25.62India
IN182.72.26.130India
IN182.72.146.78India
IN182.73.149.126India
IN182.73.245.86India
IN182.74.112.226India
IN182.74.195.146India
IN182.75.77.50India
IN182.75.84.242India
IN203.192.212.52India
IN223.196.86.215India
IN223.196.86.227India
KE197.254.80.206Kenya
KH43.255.114.242Cambodia
KH103.239.54.178Cambodia
NP202.52.230.210Nepal
PK202.125.129.131Pakistan
SA212.12.175.222Saudi Arabia
SV179.5.32.86El Salvador
SV179.5.32.94El Salvador
SV179.5.32.138El Salvador
SV179.5.32.190El Salvador
SV179.5.33.10El Salvador
SV179.5.33.14El Salvador
SV179.5.33.26El Salvador
SV179.5.33.137El Salvador
SV179.5.33.174El Salvador
SV179.5.33.178El Salvador
SV179.5.33.190El Salvador
TW118.233.116.192Taiwan
US71.91.146.220United States
ZA196.46.23.122South Africa
ZA197.242.203.190South Africa

List from greylisting:

Botnet Statistics [2016-11-02]

detection period: 2016-11-02 00:00-23:59 UTC
total number of suspected botnet IPs: 1480
number of botnet IPs notified to network operators: 1353
number of spam blocked: 7233
recipient count of spam blocked: 80186

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU409
2CHINANET-HN152
3CHINANET-JS64
4HINET-NET29
5VNPT-VNNIC-VN26
6CHINANET-GD22
7BSNLNET22
8BHARTI-IN21
9PTCLBB-PK13
10UNICOM-GX11

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China785
2India118
3Viet Nam67
4Iran48
5Taiwan45
6Brazil28
7Indonesia25
8Pakistan22
9Colombia22
10United States20

Wednesday, November 2, 2016

Suspected Bot List [2016-11-01]

detection period: 2016-11-01 00:00-23:59 UTC
number of suspected bots' IPs listed here: 102

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
CZ89.203.148.35Czech Republic
GA197.231.143.96Gabon
IN125.16.240.197India
IN182.71.25.62India
IN182.72.26.130India
IN182.72.146.78India
IN182.73.149.126India
IN182.73.245.86India
IN182.74.112.226India
IN182.74.195.146India
IN182.75.77.50India
IN182.75.84.242India
IN203.192.212.52India
KH43.255.114.242Cambodia
KH103.239.54.178Cambodia
NP202.52.230.210Nepal
PL185.125.4.249Poland
SV179.5.32.86El Salvador
SV179.5.32.94El Salvador
SV179.5.32.138El Salvador
SV179.5.32.190El Salvador
SV179.5.33.10El Salvador
SV179.5.33.14El Salvador
SV179.5.33.26El Salvador
SV179.5.33.137El Salvador
SV179.5.33.174El Salvador
SV179.5.33.178El Salvador
SV179.5.33.190El Salvador
ZA196.46.23.122South Africa
ZA197.242.203.190South Africa

List from greylisting: