Custom Search

Tuesday, May 31, 2016

Suspected Bot List [2016-05-30]

detection period: 2016-05-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 107

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR186.57.2.246Argentina
AR186.57.56.86Argentina
AR190.178.152.63Argentina
BO190.129.78.100Bolivia
CO190.7.146.126Colombia

List from greylisting:

Botnet Statistics [2016-05-30]

detection period: 2016-05-30 00:00-23:59 UTC
total number of suspected botnet IPs: 1655
number of botnet IPs notified to network operators: 1548
number of spam blocked: 3242
recipient count of spam blocked: 26027

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU454
2UNICOM-ZJ84
3CHINANET-JS83
4UNICOM-JS72
5WASU-BB48
6VNPT-VNNIC-VN41
7HINET-NET37
8CHINANET-GD34
9CNCITYNET32
10SONET-NET27

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China924
2India99
3Viet Nam81
4Taiwan68
5Iran52
6Mexico49
7United States27
8Brazil26
9Turkey22
10Pakistan20

Monday, May 30, 2016

Suspected Bot List [2016-05-29]

detection period: 2016-05-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 3

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting: