Custom Search

Wednesday, February 1, 2017

Suspected Bot List [2017-01-31]

detection period: 2017-01-31 00:00-23:59 UTC
number of suspected bots' IPs listed here: 25

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
AR190.104.231.246Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
CO190.242.119.220Colombia
IN125.16.240.197India
IN203.192.212.52India
IN223.196.86.228India
KZ185.19.194.234Kazakhstan
SA212.12.175.222Saudi Arabia
TW106.1.195.68Taiwan
TW118.232.62.225Taiwan
TW118.233.116.192Taiwan
TW123.194.119.227Taiwan
US206.125.41.139United States
US206.125.47.5United States
US206.125.47.7United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-01-31]

detection period: 2017-01-31 00:00-23:59 UTC
total number of suspected botnet IPs: 665
number of botnet IPs notified to network operators: 642
number of spam blocked: 21465
recipient count of spam blocked: 355215

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET78
2CHINANET-JS48
3UNICOM-SD46
4UNICOM-GX40
5UNICOM-LN20
6UNICOM-SX18
7UNICOM-HA13
8UNICOM-GD11
9CHINANET-YN11
10CHINANET-GZ11

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China419
2Taiwan114
3Brazil18
4United States17
5Russian Federation14
6Germany11
7Ukraine6
8India6
9Colombia6
10South Korea4

Tuesday, January 31, 2017

Suspected Bot List [2017-01-30]

detection period: 2017-01-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 23

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
AR190.104.231.246Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
CO190.242.119.197Colombia
IN125.16.240.197India
IN203.192.212.52India
IN223.196.86.228India
KZ185.19.194.234Kazakhstan
SA212.12.175.222Saudi Arabia
TW106.1.195.68Taiwan
TW118.233.116.192Taiwan
TW123.194.119.227Taiwan
US206.125.41.139United States
US206.125.47.5United States
US206.125.47.7United States
ZA196.46.23.122South Africa

List from greylisting: