Custom Search

Tuesday, June 2, 2020

Suspected Bot List [2020-06-01]

detection period: 2020-06-01 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1508

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans:

Monday, June 1, 2020

Botnet Statistics [2020-05-31]

detection period: 2020-05-31 00:00-23:59 UTC
total number of suspected botnet IPs: 29175
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 27799
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1TencentCloud1265
2Baidu941
3TENCENT-CN747
4HINET-NET643
5VNPT-VN547
6DIGITALOCEAN-162-243-0-0527
7ALISOFT459
8KORNET390
9CHINANET-GD363
10CHINANET-JS348

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China8049
2United States3354
3Russian Federation1582
4Brazil1390
5Viet Nam1285
6India1050
7France917
8Taiwan836
9South Korea658
10Indonesia648

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
1789485155
22001147322
33022137128
4123109927
5121107350
644592887
7121272048
82271322
9702358341
102351589

Suspected Bot List [2020-05-31]

detection period: 2020-05-31 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1376

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans: