Custom Search

Saturday, May 2, 2020

Suspected Bot List [2020-05-01]

detection period: 2020-05-01 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1671

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans:

Friday, May 1, 2020

Botnet Statistics [2020-04-30]

detection period: 2020-04-30 00:00-23:59 UTC
total number of suspected botnet IPs: 34176
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 31959
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1TencentCloud1107
2Baidu840
3DIGITALOCEAN-162-243-0-0719
4VNPT-VN714
5TENCENT-CN680
6HINET-NET630
7VIETTEL-VN470
8TELKOMNET457
9ORG-VA67-AFRINIC395
10ALISOFT393

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China7634
2United States4495
3Russian Federation2046
4Viet Nam1705
5Indonesia1291
6India1202
7France1017
8Taiwan817
9Thailand764
10South Korea551

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
11024442488
2107412943
3600397276
4102358328
5101357343
660333747
7105330268
88002299831
92008293144
102005284578

Suspected Bot List [2020-04-30]

detection period: 2020-04-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 2217

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans: