Custom Search

Monday, December 2, 2019

Suspected Bot List [2019-12-01]

detection period: 2019-12-01 00:00-23:59 UTC
number of suspected bots' IPs listed here: 761

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans:

Sunday, December 1, 2019

Botnet Statistics [2019-11-30]

detection period: 2019-11-30 00:00-23:59 UTC
total number of suspected botnet IPs: 18895
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 18172
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1TencentCloud714
2Baidu578
3TENCENT-CN564
4KORNET292
5HINET-NET265
6CHINANET-JS265
7VNPT-VN230
8DO-13211
9VIETTEL-VN207
10DIGITALOCEAN-12198

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China4806
2United States2222
3India901
4Brazil796
5Russian Federation740
6France739
7Viet Nam684
8South Korea466
9Indonesia429
10Singapore389

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
144593594
22258161
32324003
422219662
5822218095
62616206
7143314140
8220010116
922059476
1033899371

Suspected Bot List [2019-11-30]

detection period: 2019-11-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 723

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans: