detection period: 2025-04-02 00:00-23:59 UTC
total number of suspected botnet IPs: 24776
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 22962
number of spam blocked: 0
recipient count of spam blocked: 0
The top 10 networks (as found in WHOIS), ordered by the number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | MSFT | 1525 |
2 | AL-3 | 1150 |
3 | HINET-NET | 1018 |
4 | GOOGLE-CLOUD | 1018 |
5 | PAN-22 | 966 |
6 | ASEPL-SG | 794 |
7 | BSNLNET | 629 |
8 | ALISOFT | 545 |
9 | KORNET-KR | 470 |
10 | HURRICANE-4 | 450 |
The top 10 countries (as defined by the 2-character country code), ordered by the number of suspected botnet IPs are:
The top 10 TCP ports, ordered by the number of connection attempts received are:
Rank | Country/Region | # of suspected botnet IPs |
---|---|---|
1 | United States | 7832 |
2 | China | 5256 |
3 | India | 1367 |
4 | Taiwan | 1182 |
5 | Singapore | 961 |
6 | South Korea | 730 |
7 | United Kingdom | 630 |
8 | Hong Kong | 549 |
9 | Russian Federation | 488 |
10 | European Union | 398 |
Wednesday, April 2, 2025
Botnet Statistics [2025-04-01]
(To download the latest zombie ip list, please visit the Daily Zombie IP Lists for January 2025. To get an idea of what IP is scanning the Internet currently, please watch: Daily Botnet Detection Live Streaming.)
detection period: 2025-04-01 00:00-23:59 UTC
total number of suspected botnet IPs: 24996
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 23200
number of spam blocked: 0
recipient count of spam blocked: 0
The top 10 networks (as found in WHOIS), ordered by the number of suspected botnet IPs are:
detection period: 2025-04-01 00:00-23:59 UTC
total number of suspected botnet IPs: 24996
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 23200
number of spam blocked: 0
recipient count of spam blocked: 0
The top 10 networks (as found in WHOIS), ordered by the number of suspected botnet IPs are:
Rank | TCP port number | # of connection attempts received |
---|---|---|
1 | 5900 | 142010 |
2 | 37699 | 64229 |
3 | 223 | 54776 |
4 | 6000 | 53261 |
5 | 6001 | 53124 |
6 | 8765 | 50651 |
7 | 22 | 48223 |
8 | 7722 | 25374 |
9 | 8763 | 22240 |
10 | 7652 | 21100 |
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | MSFT | 1539 |
2 | HINET-NET | 1291 |
3 | GOOGLE-CLOUD | 990 |
4 | AL-3 | 975 |
5 | PAN-22 | 952 |
6 | BSNLNET | 668 |
7 | ASEPL-SG | 601 |
8 | ALISOFT | 507 |
9 | KORNET-KR | 449 |
10 | HURRICANE-4 | 449 |
The top 10 countries (as defined by the 2-character country code), ordered by the number of suspected botnet IPs are:
The top 10 TCP ports, ordered by the number of connection attempts received are:
Rank | Country/Region | # of suspected botnet IPs |
---|---|---|
1 | United States | 7897 |
2 | China | 5308 |
3 | Taiwan | 1448 |
4 | India | 1369 |
5 | Singapore | 823 |
6 | South Korea | 664 |
7 | United Kingdom | 651 |
8 | Hong Kong | 541 |
9 | Russian Federation | 471 |
10 | Indonesia | 402 |
Daily Zombie Lists for April 2025(2025年04月,每日殭屍電腦IP清單)
To facilitate security research, I will release the daily zombie IP lists in CSV format here for anyone interested to download. The data columns are defined as follows:
為協助資安方面的研究,我將每日釋出CSV格式的殭屍電腦IP清單,供任何有興趣的人下載。資料欄位定義如下:
Column 1: The date and time in UTC when the last connection attempt (port scans) from the zombie IP (column 2) was detected;
第1欄:該殭屍電腦最後一次被偵測到企圖連線的日期、時間,時區為UTC;
Column 2: Zombie IP;
第2欄:該殭屍電腦的IP位址;
Column 3: TCP destination port number scanned by the zombie.
第3欄:該殭屍電腦所掃描的TCP埠號。
Join the "Suspected Zombie IP List" Telegram channel to get notified when the latest data are ready for download.
想在第一時間取得資料下載網址?請加入Suspected Zombie IP List的Telegram頻道。
Here are the download links of the daily zombie IP lists for April 2025 (without excluding IP addresses of TOR exits and so-called security researchers' nodes.):
以下是2025年04月的每日殭屍電腦IP清單的下載網址(未濾除TOR exit與所謂“資安研究者”的主機IP):
04/01: download link 下載網址; MD5sum: e5ff9f3444de0d50d7eaeba63f678732
04/02: download link 下載網址; MD5sum: c4a81ea8202d12847b8cc4d83a439d57
Subscribe to:
Posts (Atom)
Rank | TCP port number | # of connection attempts received |
---|---|---|
1 | 22 | 50836 |
2 | 6000 | 28462 |
3 | 6001 | 28163 |
4 | 5900 | 27950 |
5 | 8763 | 23582 |
6 | 7652 | 22533 |
7 | 23 | 22272 |
8 | 2202 | 20079 |
9 | 10000 | 16864 |
10 | 2323 | 15452 |