Custom Search

Sunday, November 8, 2020

Suspected Bot List [2020-11-07]

detection period: 2020-11-07 00:00-23:59 UTC
number of suspected bots' IPs listed here: 2195

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans:

Saturday, November 7, 2020

Botnet Statistics [2020-11-06]

detection period: 2020-11-06 00:00-23:59 UTC
total number of suspected botnet IPs: 36211
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 33856
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1TencentCloud1463
2VIETTEL-VN824
3HINET-NET804
4TENCENT-CN697
5Baidu673
6DIGITALOCEAN-192-241-128-0613
7VNPT-VN583
8ALISOFT477
9TELKOMNET476
10UNICOM-HA425

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China8412
2United States4192
3India2463
4Russian Federation2121
5Viet Nam2097
6Brazil1705
7Indonesia1350
8Taiwan994
9Thailand853
10France823

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
1445372507
2143359559
340052771
450051874
52239959
62333079
74620369
8220017520
9130013383
1058713051

Suspected Bot List [2020-11-06]

detection period: 2020-11-06 00:00-23:59 UTC
number of suspected bots' IPs listed here: 2355

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans: