Custom Search

Thursday, October 10, 2013

Suspected Bot List [2013-10-09]

detection period: 2013-10-09 00:00-23:59 UTC
number of suspected bots' IPs listed here: 499

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.14.170.249Argentina
AR190.15.201.202Argentina
AR190.228.175.82Argentina
AR200.55.57.214Argentina
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.239.29.114India
IN117.240.239.120India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
IR85.9.73.68Iran
IR91.98.117.30Iran
IR94.183.223.16Iran
MX187.174.173.18Mexico
MX189.204.49.66Mexico
MX200.92.57.205Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TR82.222.189.43Turkey
UA109.251.115.24Ukraine
US50.159.67.200United States
US50.197.38.178United States
US74.222.3.249United States

List from greylisting:

Botnet Statistics [2013-10-09]

detection period: 2013-10-09 00:00-23:59 UTC
total number of suspected botnet IPs: 3825
number of botnet IPs notified to network operators: 3326
number of spam blocked: 88190
recipient count of spam blocked: 2891481

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET983
2CHINANET-JS690
3UNICOM-GD171
4CHINANET-GD80
5CHINANET-FJ40
6UNICOM-LN29
7CBC-CM-419
8TELSTRAINTERNET49-AU17
9CMNET17
10AR-PRSA-LACNIC16

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1232
2Taiwan996
3United States349
4United Kingdom101
5Australia98
6India68
7Argentina66
8Mexico65
9Brazil57
10Spain50

Wednesday, October 9, 2013

Suspected Bot List [2013-10-08]

detection period: 2013-10-08 00:00-23:59 UTC
number of suspected bots' IPs listed here: 399

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AO196.223.13.230Angola
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.240.239.120India
IN122.183.99.146India
IN202.63.105.226India
IR91.98.117.30Iran
IR94.183.223.16Iran
MX187.174.173.18Mexico
MX189.204.49.66Mexico
MX200.92.57.205Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TR82.222.189.43Turkey
UA109.251.115.24Ukraine
US50.159.67.200United States
US74.222.3.249United States
US204.152.219.115United States

List from greylisting: