Custom Search

Tuesday, March 11, 2014

Suspected Bot List [2014-03-10]

detection period: 2014-03-10 00:00-23:59 UTC
number of suspected bots' IPs listed here: 48

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AL80.78.75.103Albania
AR200.63.19.165Argentina
BO190.129.12.162Bolivia
CO200.80.43.248Colombia
CZ80.188.121.251Czech Republic
HN190.107.140.77Honduras
IR91.98.36.84Iran
IT95.227.34.226Italy
LB213.175.188.158Lebanon
MO60.246.152.136Macau
MO122.100.206.222Macau
MO122.100.242.45Macau
NL5.255.87.156Netherlands
RU95.188.112.11Russian Federation
SA94.77.199.148Saudi Arabia
SG116.251.211.100Singapore
SG116.251.217.213Singapore
SK93.184.71.66Slovakia
TW115.165.252.42Taiwan
TW119.77.139.166Taiwan
TW122.100.84.15Taiwan
TW211.76.92.31Taiwan
US50.201.42.106United States
US74.222.3.249United States
VE190.39.82.232Venezuela

List from greylisting:

Botnet Statistics [2014-03-10]

detection period: 2014-03-10 00:00-23:59 UTC
total number of suspected botnet IPs: 2513
number of botnet IPs notified to network operators: 2465
number of spam blocked: 39597
recipient count of spam blocked: 1285974

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CMNET478
2CRTC340
3CHINANET-GD174
4CTTNET117
5HINET-NET92
6UNICOM-SD82
7CHINANET-JS80
8CHINANET-FJ55
9CHINANET-XJ41
10UNICOM-LN36

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2114
2Taiwan123
3France35
4United States33
5Russian Federation17
6Brazil16
7Indonesia13
8Italy12
9Ukraine10
10Germany10

Monday, March 10, 2014

Suspected Bot List [2014-03-09]

detection period: 2014-03-09 00:00-23:59 UTC
number of suspected bots' IPs listed here: 36

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AL80.78.75.103Albania
AR200.63.19.165Argentina
BO190.129.12.162Bolivia
CN202.142.20.8China
CO200.80.43.248Colombia
CZ80.188.121.251Czech Republic
HN190.107.140.77Honduras
IN117.240.239.120India
IR91.98.36.84Iran
IT95.227.34.226Italy
LB213.175.188.158Lebanon
MO60.246.153.81Macau
MX187.174.173.18Mexico
MX189.204.49.66Mexico
NL5.255.87.156Netherlands
PH124.107.165.60Philippines
RU95.188.112.11Russian Federation
SA94.77.199.148Saudi Arabia
SG116.251.217.213Singapore
TW122.100.84.15Taiwan
US50.201.42.106United States
US74.222.3.249United States
VE190.39.82.232Venezuela

List from greylisting: