Custom Search

Wednesday, October 2, 2019

Suspected Bot List [2019-10-01]

detection period: 2019-10-01 00:00-23:59 UTC
number of suspected bots' IPs listed here: 692

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry
CA51.79.86.150Canada

List from TCP port scans:

Tuesday, October 1, 2019

Botnet Statistics [2019-09-30]

detection period: 2019-09-30 00:00-23:59 UTC
total number of suspected botnet IPs: 15301
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 14429
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1TENCENT-CN500
2TencentCloud472
3Baidu458
4KORNET322
5HINET-NET320
6DO-13216
7DIGITALOCEAN-12209
8VNPT-VN199
9OVH178
10CMNET165

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China3506
2United States1914
3France801
4Russian Federation639
5India573
6Viet Nam549
7Brazil543
8South Korea523
9Indonesia447
10Taiwan384

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
12219411
22315865
344515297
4338911894
522005838
680805137
72225120
822224982
959004978
1071234965

Suspected Bot List [2019-09-30]

detection period: 2019-09-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 872

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry
AO196.32.194.90Angola
LU213.135.230.147Luxembourg
MX201.110.79.43Mexico
ZA102.165.35.137South Africa

List from TCP port scans: