Custom Search

Tuesday, April 30, 2013

Suspected Bot List [2013-04-29]

detection period: 2013-04-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 622

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE194.170.149.21Arab Emirates
AL82.114.70.102Albania
AO196.223.13.230Angola
BG212.73.156.197Bulgaria
BY91.149.167.80Belarus
CA68.70.150.92Canada
CA70.38.37.207Canada
CA206.248.184.100Canada
CI213.136.105.210Ivory Coast
CO190.6.160.146Colombia
CZ77.104.244.69Czech Republic
CZ89.177.122.232Czech Republic
DE78.138.117.42Germany
DE84.11.89.66Germany
DE84.246.251.237Germany
DE85.116.198.151Germany
DE85.205.253.214Germany
DZ193.194.87.59Algeria
EC186.42.182.5Ecuador
EG196.218.229.14Egypt
ES149.126.34.213Spain
ES213.171.239.5Spain
GB37.220.19.147United Kingdom
GB46.17.63.169United Kingdom
GB46.32.233.152United Kingdom
GB46.166.178.84United Kingdom
GB77.246.20.2United Kingdom
GB83.218.130.114United Kingdom
GB89.105.3.212United Kingdom
GB89.106.131.16United Kingdom
GB93.93.129.119United Kingdom
GB109.204.5.228United Kingdom
GB193.164.207.16United Kingdom
GE92.241.80.222Republic Of Georgia
GH212.96.12.199Ghana
GR78.87.9.40Greece
GT200.30.165.178Guatemala
HN190.107.140.77Honduras
IL80.250.154.233Israel
IN117.211.91.147India
IN117.240.239.120India
IN122.180.96.110India
IN122.183.99.146India
IN125.17.98.200India
IN182.72.118.131India
IN182.73.139.30India
IN202.63.105.226India
IR93.126.25.35Iran
IT62.97.40.214Italy
JO87.236.232.231Jordan
KE41.89.96.20Kenya
KE41.139.206.178Kenya
KW62.150.12.46Kuwait
KW213.132.241.7Kuwait
LV46.183.219.137Latvia
MD77.89.251.70Republic Of Moldova
MV202.21.182.26Republic of Maldives
MX177.227.88.125Mexico
MX187.162.207.98Mexico
MX187.241.73.253Mexico
MX200.33.20.40Mexico
MX201.159.106.90Mexico
MX201.164.145.236Mexico
NG41.223.66.86Nigeria
NI186.1.10.154Nicaragua
NO212.4.34.78Norway
NZ202.169.192.130New Zealand
PH121.97.26.86Philippines
PH124.104.141.204Philippines
PH202.124.193.11Philippines
PK111.68.104.132Pakistan
PK111.68.104.133Pakistan
PK115.186.58.131Pakistan
PK124.109.47.66Pakistan
PK202.69.45.52Pakistan
RO89.120.102.13Romania
RO91.220.26.4Romania
RS84.22.61.190Serbia
RS91.150.124.71Serbia
RS178.149.182.28Serbia
RS194.106.178.161Serbia
RS212.200.156.184Serbia
RU188.134.20.63Russian Federation
SA94.77.199.148Saudi Arabia
TR82.222.171.203Turkey
TR82.222.189.43Turkey
TR85.105.126.140Turkey
TR89.145.185.42Turkey
TR95.9.55.90Turkey
UA82.207.51.92Ukraine
UA91.212.124.153Ukraine
US50.194.150.131United States
US65.98.75.14United States
US66.109.21.60United States
US67.20.29.147United States
US67.236.113.226United States
US69.18.205.139United States
US108.163.195.37United States
US198.55.102.12United States
US198.154.60.221United States
US199.36.74.133United States
US199.87.232.107United States
US200.62.8.50United States
US205.208.148.104United States
US206.217.198.12United States
US207.157.71.132United States
US208.89.209.81United States
US209.239.112.104United States

List from greylisting:

Botnet Statistics [2013-04-29]

detection period: 2013-04-29 00:00-23:59 UTC
total number of suspected botnet IPs: 3278
number of botnet IPs notified to network operators: 2659
number of spam blocked: 68018
recipient count of spam blocked: 2090193

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BY-BELPAK-20091210190
2CHINANET-HE180
3CHINANET-GD86
4BSNLNET67
5CHINANET-HA61
6HINET-NET56
7BY-BELPAK-2012033047
8BY-BELPAK-2008021342
9MSFT-EP39
10RCOM36

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China749
2Belarus346
3United States244
4India210
5Ukraine148
6Kazakhstan127
7Russian Federation111
8Brazil107
9Taiwan97
10Romania89

Monday, April 29, 2013

Suspected Bot List [2013-04-28]

detection period: 2013-04-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 633

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE194.170.149.21Arab Emirates
AL82.114.70.102Albania
AO196.223.13.230Angola
BG212.73.156.197Bulgaria
BY91.149.167.80Belarus
CA68.70.150.92Canada
CA70.38.37.207Canada
CA206.248.184.100Canada
CI213.136.105.210Ivory Coast
CU190.6.90.204Cuba
CZ77.104.244.69Czech Republic
CZ89.177.122.232Czech Republic
CZ212.67.82.93Czech Republic
DE78.138.117.42Germany
DE84.11.89.66Germany
DE84.246.251.237Germany
DE85.116.198.151Germany
DE85.205.253.214Germany
DE88.152.29.67Germany
DZ193.194.87.59Algeria
EC186.42.182.5Ecuador
EG196.218.229.14Egypt
ES149.126.34.213Spain
ES213.171.239.5Spain
EU84.40.11.180European Union
GB37.220.19.147United Kingdom
GB46.17.63.169United Kingdom
GB46.166.178.84United Kingdom
GB77.246.20.2United Kingdom
GB83.218.130.114United Kingdom
GB89.105.3.212United Kingdom
GB89.106.131.16United Kingdom
GB93.93.129.119United Kingdom
GB193.164.207.16United Kingdom
GE92.241.80.222Republic Of Georgia
GH212.96.12.199Ghana
GR78.87.9.40Greece
GT200.30.165.178Guatemala
HN190.107.140.77Honduras
IL80.250.154.233Israel
IL82.102.158.5Israel
IN117.211.91.147India
IN117.240.239.120India
IN122.180.96.110India
IN122.183.99.146India
IN125.17.98.200India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IR82.99.246.10Iran
IR93.126.25.35Iran
IT62.97.40.214Italy
IT213.149.213.37Italy
JO87.236.232.231Jordan
KE41.89.96.20Kenya
KE41.139.206.178Kenya
KW213.132.241.7Kuwait
LV46.183.219.137Latvia
LV94.30.129.199Latvia
MD77.89.251.70Republic Of Moldova
MD95.65.86.236Republic Of Moldova
MV202.21.182.26Republic of Maldives
MX177.227.88.125Mexico
MX177.228.74.54Mexico
MX187.137.22.85Mexico
MX187.141.185.118Mexico
MX187.162.207.98Mexico
MX187.174.173.18Mexico
MX187.241.73.253Mexico
MX187.247.92.77Mexico
MX200.33.20.40Mexico
MX201.147.189.118Mexico
MX201.159.106.90Mexico
MX201.164.145.236Mexico
NG41.223.66.86Nigeria
NI186.1.10.154Nicaragua
NO212.4.34.78Norway
NZ202.169.192.130New Zealand
PH121.97.26.86Philippines
PH124.104.141.204Philippines
PH202.124.193.11Philippines
PK111.68.104.132Pakistan
PK111.68.104.133Pakistan
PK115.186.58.131Pakistan
PK124.109.47.66Pakistan
PK202.69.45.52Pakistan
PK210.2.171.13Pakistan
RO89.120.102.13Romania
RO91.220.26.4Romania
RS84.22.61.190Serbia
RS91.150.124.71Serbia
RS178.149.182.28Serbia
RS194.106.178.161Serbia
RS212.200.156.184Serbia
RU188.134.20.63Russian Federation
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
SN196.207.216.131Senegal
TN41.230.10.190Tunisia
TR82.222.171.203Turkey
TR82.222.189.43Turkey
TR85.105.126.140Turkey
TR89.145.185.42Turkey
TR95.9.55.90Turkey
TR159.253.44.163Turkey
TZ196.41.61.58Tanzania
UA82.207.51.92Ukraine
UA91.212.124.153Ukraine
US50.194.150.131United States
US64.19.97.130United States
US65.98.75.14United States
US67.20.29.147United States
US67.236.113.226United States
US108.163.195.37United States
US129.79.148.159United States
US198.55.102.12United States
US198.143.159.144United States
US198.154.60.221United States
US199.241.136.105United States
US200.62.8.50United States
US205.208.148.104United States
US206.217.198.12United States
US207.157.71.132United States
US208.89.209.81United States
ZA196.211.119.139South Africa

List from greylisting:

Botnet Statistics [2013-04-28]

detection period: 2013-04-28 00:00-23:59 UTC
total number of suspected botnet IPs: 3212
number of botnet IPs notified to network operators: 2582
number of spam blocked: 65340
recipient count of spam blocked: 1975253

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1BY-BELPAK-20091210202
2CHINANET-HE153
3CHINANET-GD109
4BY-BELPAK-2012033096
5UNICOM-HA93
6HINET-NET54
7BY-BELPAK-2008021353
8BY-BELPAK-2012010648
9MSFT-EP39
10BSNLNET39

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China707
2Belarus448
3Ukraine195
4United States166
5India143
6Kazakhstan137
7Russian Federation127
8Romania104
9Brazil100
10Taiwan81

Sunday, April 28, 2013

Suspected Bot List [2013-04-27]

detection period: 2013-04-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 628

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE94.200.108.10Arab Emirates
AL82.114.70.102Albania
AO196.223.13.230Angola
BD180.211.179.30Bangladesh
BG212.73.156.197Bulgaria
BY91.149.167.80Belarus
CA68.70.150.92Canada
CA70.38.37.207Canada
CI213.136.105.210Ivory Coast
CZ77.104.244.69Czech Republic
CZ89.177.122.232Czech Republic
CZ212.67.82.93Czech Republic
DE77.23.13.20Germany
DE84.11.89.66Germany
DE84.246.251.237Germany
DE85.116.198.151Germany
DE85.205.253.214Germany
DZ193.194.87.59Algeria
EC186.42.182.5Ecuador
EG196.218.229.14Egypt
ES84.124.36.238Spain
ES213.171.239.5Spain
GB37.220.19.147United Kingdom
GB46.17.63.169United Kingdom
GB77.246.20.2United Kingdom
GB83.218.130.114United Kingdom
GB89.105.3.212United Kingdom
GB89.106.131.16United Kingdom
GB93.93.129.119United Kingdom
GB193.164.207.16United Kingdom
GH212.96.12.199Ghana
GR78.87.9.40Greece
GT200.30.165.178Guatemala
HN190.107.140.77Honduras
IN27.49.107.83India
IN117.211.91.147India
IN117.240.239.120India
IN122.180.96.110India
IN122.183.99.146India
IN125.17.98.200India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IQ95.159.105.2Iraq
IR31.47.40.88Iran
IR82.99.246.10Iran
IR89.165.109.165Iran
IR93.126.25.35Iran
IT62.97.40.214Italy
IT95.171.57.129Italy
IT213.149.213.37Italy
JO87.236.232.231Jordan
KE41.89.96.20Kenya
KW213.132.241.7Kuwait
LV46.183.219.137Latvia
MV202.21.182.26Republic of Maldives
MX177.227.88.125Mexico
MX177.228.74.54Mexico
MX187.137.22.85Mexico
MX187.141.185.118Mexico
MX187.162.207.98Mexico
MX187.174.173.18Mexico
MX187.241.73.253Mexico
MX187.247.92.77Mexico
MX189.198.198.35Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX201.147.189.118Mexico
MX201.159.106.90Mexico
NI186.1.10.154Nicaragua
NO212.4.34.78Norway
NZ121.73.60.67New Zealand
NZ202.169.192.130New Zealand
PH121.97.26.86Philippines
PH124.104.141.204Philippines
PH202.124.193.11Philippines
PK111.68.104.133Pakistan
PK124.109.47.66Pakistan
PK210.2.171.13Pakistan
RO78.97.216.93Romania
RO89.120.102.13Romania
RO91.220.26.4Romania
RS84.22.61.190Serbia
RS91.150.124.71Serbia
RS178.149.182.28Serbia
RS194.106.178.161Serbia
RU178.237.184.222Russian Federation
RU188.134.20.63Russian Federation
SA94.77.199.148Saudi Arabia
SK85.237.244.128Slovakia
SK93.184.71.66Slovakia
SN196.207.216.131Senegal
SV201.247.174.177El Salvador
TN41.230.10.190Tunisia
TR82.222.171.203Turkey
TR82.222.189.43Turkey
TR89.145.185.42Turkey
TR95.9.55.90Turkey
TZ196.41.61.58Tanzania
UA91.212.124.153Ukraine
US50.194.150.131United States
US64.19.97.130United States
US65.98.75.14United States
US67.20.29.147United States
US67.236.113.226United States
US108.163.195.37United States
US129.79.148.159United States
US198.55.102.12United States
US198.143.159.144United States
US199.241.136.105United States
US200.62.8.50United States
US205.208.148.104United States
US207.157.71.132United States
US208.89.209.81United States
ZA196.211.119.139South Africa

List from greylisting:

Botnet Statistics [2013-04-27]

detection period: 2013-04-27 00:00-23:59 UTC
total number of suspected botnet IPs: 3884
number of botnet IPs notified to network operators: 3257
number of spam blocked: 48662
recipient count of spam blocked: 1452915

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-JS600
2UNICOM-HA391
3BY-BELPAK-20091210191
4CHINANET-HE125
5CHINANET-GD104
6BY-BELPAK-2012033055
7BSNLNET55
8HINET-NET53
9BY-BELPAK-2012010647
10KZ-KAZAKTELECOM-2009112639

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1615
2Belarus371
3Ukraine181
4India168
5United States153
6Kazakhstan150
7Russian Federation112
8Romania110
9Brazil92
10Taiwan83

Saturday, April 27, 2013

Suspected Bot List [2013-04-26]

detection period: 2013-04-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 471

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE94.200.108.10Arab Emirates
AE194.170.149.21Arab Emirates
AL82.114.70.102Albania
AO196.223.13.230Angola
BD180.211.179.30Bangladesh
BG77.85.175.82Bulgaria
BG212.73.156.197Bulgaria
BR150.161.30.7Brazil
BY176.60.192.54Belarus
CA68.70.150.92Canada
CA70.38.37.207Canada
CA99.244.26.71Canada
CH81.17.19.31Switzerland
CI213.136.105.210Ivory Coast
CZ77.104.244.69Czech Republic
DE77.23.13.20Germany
DE78.138.117.42Germany
DE84.11.89.66Germany
DE84.246.251.237Germany
DE85.116.198.151Germany
DE85.205.253.214Germany
DZ193.194.87.59Algeria
EG196.218.229.14Egypt
ES84.124.36.238Spain
ES149.126.34.213Spain
ES213.171.239.5Spain
GB37.220.19.147United Kingdom
GB46.17.63.169United Kingdom
GB77.246.20.2United Kingdom
GB83.218.130.114United Kingdom
GB89.105.3.212United Kingdom
GB93.93.129.119United Kingdom
GB95.154.243.37United Kingdom
GB188.227.161.40United Kingdom
GB188.227.161.46United Kingdom
GB188.227.161.47United Kingdom
GB193.164.207.16United Kingdom
GB217.30.116.142United Kingdom
GH212.96.12.199Ghana
GR78.87.9.40Greece
GT200.30.165.178Guatemala
HN190.107.140.77Honduras
IL82.102.153.250Israel
IN117.240.239.120India
IN122.180.96.110India
IN122.183.99.146India
IN125.17.98.200India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IN203.153.39.18India
IQ95.159.105.2Iraq
IR31.47.40.88Iran
IR82.99.246.10Iran
IR89.165.109.165Iran
IR93.126.25.35Iran
IT95.171.57.129Italy
IT213.149.213.37Italy
JO87.236.232.231Jordan
KE41.89.96.20Kenya
KW62.150.12.46Kuwait
KW213.132.241.7Kuwait
LV46.183.219.137Latvia
MD77.89.251.70Republic Of Moldova
MN180.149.96.169Mongolia
MV202.21.182.26Republic of Maldives
MX177.227.88.125Mexico
MX177.228.74.54Mexico
MX187.137.22.85Mexico
MX187.141.185.118Mexico
MX187.162.207.98Mexico
MX187.174.173.18Mexico
MX187.174.234.99Mexico
MX187.241.73.253Mexico
MX187.247.92.77Mexico
MX189.198.198.35Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX201.147.189.118Mexico
MX201.159.106.90Mexico
NI186.1.10.154Nicaragua
NO212.4.34.78Norway
NZ121.73.60.67New Zealand
NZ202.169.192.130New Zealand
PA190.33.184.107Panama
PH121.97.26.86Philippines
PH124.104.141.204Philippines
PH202.124.193.11Philippines
PK111.68.104.133Pakistan
PK121.52.154.230Pakistan
PK210.2.171.13Pakistan
RO78.97.216.93Romania
RO91.220.26.4Romania
RO188.27.126.232Romania
RS84.22.61.190Serbia
RS178.149.182.28Serbia
RS194.106.178.161Serbia
RU188.134.20.63Russian Federation
RU195.190.118.6Russian Federation
SA94.77.199.148Saudi Arabia
SV201.247.174.177El Salvador
TN41.230.10.190Tunisia
TR82.222.171.203Turkey
TR82.222.189.43Turkey
TR85.105.126.140Turkey
TR89.145.185.42Turkey
TR95.9.55.90Turkey
TR188.132.237.61Turkey
UA91.212.124.153Ukraine
US50.20.219.165United States
US50.194.150.131United States
US64.33.143.164United States
US65.98.75.14United States
US67.20.29.147United States
US67.236.113.226United States
US72.249.55.100United States
US108.163.195.37United States
US192.184.3.251United States
US198.55.102.12United States
US199.231.85.222United States
US199.241.136.105United States
US205.208.148.104United States
US207.157.71.132United States
US208.89.209.81United States
US209.239.112.104United States
ZA196.211.119.139South Africa

List from greylisting:

Botnet Statistics [2013-04-26]

detection period: 2013-04-26 00:00-23:59 UTC
total number of suspected botnet IPs: 4902
number of botnet IPs notified to network operators: 4438
number of spam blocked: 64421
recipient count of spam blocked: 1851240

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-HA1079
2CHINANET-JS786
3CHINANET-HE252
4BY-BELPAK-20091210188
5UNICOM-GD149
6CHINANET-GD123
7TimeNet57
8BY-BELPAK-2012033043
9BY-BELPAK-2008021337
10VNPT-VNNIC-VN36

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2871
2Belarus335
3United States249
4Ukraine146
5Kazakhstan139
6Russian Federation96
7Brazil89
8India67
9Peru62
10Viet Nam57

Friday, April 26, 2013

Suspected Bot List [2013-04-25]

detection period: 2013-04-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 549

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE194.170.149.21Arab Emirates
AL82.114.70.102Albania
AO196.223.13.230Angola
BD180.211.179.30Bangladesh
BR150.161.30.7Brazil
BY91.149.167.80Belarus
CA70.38.37.207Canada
CH81.17.19.31Switzerland
CI213.136.105.210Ivory Coast
CU190.6.90.204Cuba
CZ77.104.244.69Czech Republic
DE77.23.13.20Germany
DE78.138.117.42Germany
DE84.11.89.66Germany
DE84.246.251.237Germany
DE85.116.198.151Germany
DE85.205.253.214Germany
DZ193.194.87.59Algeria
ES149.126.34.213Spain
ES213.171.239.5Spain
GB37.220.19.147United Kingdom
GB46.17.63.169United Kingdom
GB77.246.20.2United Kingdom
GB83.218.130.114United Kingdom
GB89.105.3.212United Kingdom
GB93.93.129.119United Kingdom
GB95.154.243.37United Kingdom
GB188.227.161.40United Kingdom
GB188.227.161.46United Kingdom
GB188.227.161.47United Kingdom
GB193.164.207.16United Kingdom
GB217.30.116.142United Kingdom
GH212.96.12.199Ghana
GR46.246.190.198Greece
GR78.87.9.40Greece
HN190.107.140.77Honduras
IN27.49.107.83India
IN117.240.239.120India
IN122.183.99.146India
IN125.17.98.200India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IN203.153.39.18India
IQ95.159.105.2Iraq
IR31.47.40.88Iran
IR82.99.246.10Iran
IR93.126.25.35Iran
IT213.149.213.37Italy
JO87.236.232.231Jordan
KE41.89.96.20Kenya
KW62.150.12.46Kuwait
KW213.132.241.7Kuwait
LV46.183.219.137Latvia
LV94.30.129.199Latvia
MD77.89.251.70Republic Of Moldova
MN180.149.96.169Mongolia
MX177.227.88.125Mexico
MX177.228.74.54Mexico
MX187.162.207.98Mexico
MX187.247.92.77Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX201.159.106.90Mexico
NI186.1.10.154Nicaragua
NZ202.169.192.130New Zealand
PA190.33.184.107Panama
PH121.97.26.86Philippines
PH124.104.141.204Philippines
PH202.124.193.11Philippines
PK121.52.154.230Pakistan
PK210.2.171.13Pakistan
RO91.220.26.4Romania
RS84.22.61.190Serbia
RS194.106.178.161Serbia
RU178.237.184.222Russian Federation
RU188.134.20.63Russian Federation
RU195.190.118.6Russian Federation
SA94.77.199.148Saudi Arabia
TN41.230.10.190Tunisia
TR82.222.171.203Turkey
TR82.222.189.43Turkey
TR85.105.126.140Turkey
TR89.145.185.42Turkey
TR95.9.55.90Turkey
TR188.132.237.61Turkey
TZ196.41.61.58Tanzania
US50.194.150.131United States
US66.109.21.60United States
US67.20.29.147United States
US67.236.113.226United States
US108.163.195.37United States
US192.184.3.251United States
US198.55.102.12United States
US199.231.85.222United States
US205.208.148.104United States
US207.157.71.132United States
US208.89.209.81United States
US209.239.112.104United States
US216.224.166.223United States
ZA41.185.36.50South Africa
ZA196.211.119.139South Africa

List from greylisting:

Botnet Statistics [2013-04-25]

detection period: 2013-04-25 00:00-23:59 UTC
total number of suspected botnet IPs: 5155
number of botnet IPs notified to network operators: 4618
number of spam blocked: 27486
recipient count of spam blocked: 631412

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here 10 days after its respective botnet statistics gets published.

Suspected Bots IP [2013-04-25]

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-HA1450
2CHINANET-JS496
3CHINANET-HE287
4BY-BELPAK-20091210214
5CHINANET-GD114
6UNICOM-GD97
7BY-BELPAK-2012033060
8TimeNet49
9BY-BELPAK-2008021346
10VNPT-VNNIC-VN44

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2915
2Belarus392
3United States297
4Ukraine178
5Kazakhstan145
6Russian Federation90
7Brazil89
8India82
9Viet Nam72
10Iran53

Thursday, April 25, 2013

Suspected Bot List [2013-04-24]

detection period: 2013-04-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 609

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2013-04-24]

detection period: 2013-04-24 00:00-23:59 UTC
total number of suspected botnet IPs: 6119
number of botnet IPs notified to network operators: 5510
number of spam blocked: 18265
recipient count of spam blocked: 143754

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here 10 days after its respective botnet statistics gets published.

Suspected Bots IP [2013-04-24]

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-JS1468
2UNICOM-HA1026
3CRTC349
4CHINANET-HE340
5BY-BELPAK-20091210185
6UNICOM-GD177
7CHINANET-GD126
8CTTNET104
9TimeNet56
10BY-BELPAK-2012033049

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China4004
2Belarus343
3United States261
4Ukraine156
5Kazakhstan138
6Peru98
7Viet Nam71
8Korea71
9India63
10Russian Federation53

Wednesday, April 24, 2013

Suspected Bot List [2013-04-23]

detection period: 2013-04-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 598

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AL82.114.70.102Albania
AO196.223.13.230Angola
BG77.85.175.82Bulgaria
BG78.90.20.249Bulgaria
BR150.161.30.7Brazil
CA70.38.37.207Canada
CI41.66.25.36Ivory Coast
CN202.107.222.50China
CZ77.104.244.69Czech Republic
DE5.45.179.226Germany
DE77.23.13.20Germany
DE80.241.211.18Germany
DE84.246.251.237Germany
DE85.205.253.214Germany
DE88.152.29.67Germany
DZ193.194.87.59Algeria
EG196.218.229.14Egypt
ES87.216.240.245Spain
GB37.220.10.52United Kingdom
GB37.220.19.147United Kingdom
GB46.17.63.169United Kingdom
GB46.32.233.152United Kingdom
GB46.166.178.84United Kingdom
GB77.246.20.2United Kingdom
GB83.218.130.114United Kingdom
GB88.107.176.95United Kingdom
GB89.105.3.212United Kingdom
GB93.93.129.119United Kingdom
GB95.154.243.37United Kingdom
GB188.227.161.40United Kingdom
GB188.227.161.46United Kingdom
GB193.164.207.16United Kingdom
GR78.87.9.40Greece
GT186.151.253.186Guatemala
IN59.96.66.2India
IN117.239.29.114India
IN117.240.239.120India
IN122.180.96.110India
IN122.183.99.146India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IN203.153.39.18India
IR77.237.185.33Iran
IR93.126.25.35Iran
IT62.97.40.214Italy
IT213.149.213.37Italy
JO87.236.232.231Jordan
KE41.89.96.20Kenya
KG212.112.107.188Kyrgyzstan
KW62.150.12.46Kuwait
KW213.132.241.7Kuwait
MA41.214.129.22Morocco
MD95.65.86.236Republic Of Moldova
MV202.21.182.26Republic of Maldives
MX177.227.88.125Mexico
MX177.228.74.54Mexico
MX187.137.22.85Mexico
MX187.141.185.118Mexico
MX187.162.207.98Mexico
MX187.174.173.18Mexico
MX187.244.120.28Mexico
MX187.247.92.77Mexico
MX189.198.198.35Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX201.159.106.90Mexico
MX201.164.145.236Mexico
NI186.1.10.154Nicaragua
NL185.13.224.51Netherlands
NL212.7.210.177Netherlands
NL213.126.90.227Netherlands
NO80.202.250.41Norway
NO212.4.34.78Norway
NZ121.73.60.67New Zealand
NZ202.169.192.130New Zealand
PH121.97.26.86Philippines
PH124.104.141.204Philippines
PH202.124.193.11Philippines
PK61.5.156.195Pakistan
PK202.69.45.52Pakistan
PK210.2.171.13Pakistan
RO78.97.216.93Romania
RO89.32.226.102Romania
RO89.120.102.13Romania
RO91.220.26.4Romania
RS84.22.61.190Serbia
RS178.149.182.28Serbia
RS194.106.178.161Serbia
RU178.237.184.222Russian Federation
RU188.134.20.63Russian Federation
SA94.77.199.148Saudi Arabia
SE79.138.113.235Sweden
TN41.230.10.190Tunisia
TR82.222.189.43Turkey
TR89.145.185.42Turkey
TR188.132.237.61Turkey
TZ196.41.61.58Tanzania
UA37.1.218.252Ukraine
UA91.212.124.153Ukraine
UA178.136.129.216Ukraine
UA188.191.238.205Ukraine
US50.194.150.131United States
US64.33.143.164United States
US67.20.29.147United States
US67.236.113.226United States
US87.76.30.198United States
US108.163.195.37United States
US108.166.205.163United States
US192.30.84.153United States
US192.81.249.4United States
US192.184.3.251United States
US199.15.251.184United States
US199.231.85.222United States
US199.241.136.105United States
US205.208.148.104United States
US206.190.158.235United States
US207.157.71.132United States
US207.182.133.221United States
US208.89.209.81United States
ZW41.57.125.190Zimbabwe

List from greylisting:

Botnet Statistics [2013-04-23]

detection period: 2013-04-23 00:00-23:59 UTC
total number of suspected botnet IPs: 6080
number of botnet IPs notified to network operators: 5490
number of spam blocked: 64784
recipient count of spam blocked: 2015974

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here 10 days after its respective botnet statistics gets published.

Suspected Bots IP [2013-04-23]

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-JS1891
2CRTC347
3UNICOM-HA311
4CHINANET-HE283
5BY-BELPAK-20091210192
6UNICOM-GD187
7CHINANET-GD153
8CTTNET121
9TimeNet58
10BY-BELPAK-2012033049

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China3818
2Belarus343
3United States270
4Ukraine173
5Kazakhstan122
6Russian Federation102
7Brazil93
8India83
9Peru69
10Viet Nam60

Tuesday, April 23, 2013

Suspected Bot List [2013-04-22]

detection period: 2013-04-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 658

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE195.229.241.181Arab Emirates
AL77.242.27.111Albania
AL80.78.67.98Albania
AL82.114.70.102Albania
AL213.207.41.34Albania
AM141.136.65.119Armenia
AO196.223.13.230Angola
BD180.211.179.30Bangladesh
BG77.85.175.82Bulgaria
BR150.161.30.7Brazil
BR177.137.0.123Brazil
CA70.38.37.207Canada
CA99.244.26.71Canada
CA174.142.104.5Canada
CN202.107.222.50China
CO190.0.60.238Colombia
CZ77.104.244.69Czech Republic
DE62.113.213.202Germany
DE77.23.13.20Germany
DE78.138.117.42Germany
DE80.241.212.224Germany
DE84.11.89.66Germany
DE84.246.251.237Germany
DE88.152.29.67Germany
DZ41.221.30.242Algeria
DZ193.194.87.59Algeria
EC186.5.102.162Ecuador
EC186.42.182.5Ecuador
EG196.218.229.14Egypt
ES87.216.240.245Spain
ES149.126.34.213Spain
GB46.17.63.169United Kingdom
GB77.246.20.2United Kingdom
GB83.218.130.114United Kingdom
GB87.113.141.230United Kingdom
GB89.105.3.212United Kingdom
GB93.93.129.119United Kingdom
GB95.154.243.37United Kingdom
GB146.185.31.170United Kingdom
GB188.227.161.40United Kingdom
GB188.227.161.46United Kingdom
GB188.227.161.47United Kingdom
GB193.164.207.16United Kingdom
GH212.96.12.199Ghana
GR78.87.9.40Greece
HN190.107.140.77Honduras
IL82.102.153.250Israel
IN14.139.191.193India
IN112.133.201.70India
IN117.211.91.147India
IN117.239.29.114India
IN117.239.132.146India
IN117.240.124.68India
IN117.240.239.120India
IN122.180.96.110India
IN122.183.99.146India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IN203.153.39.18India
IQ95.159.105.2Iraq
IQ109.224.20.138Iraq
IR82.99.246.10Iran
IR89.165.109.165Iran
IR93.126.25.35Iran
IR185.2.12.98Iran
IT213.149.213.37Italy
JO87.236.232.231Jordan
KE41.89.96.20Kenya
KW62.150.12.46Kuwait
KW213.132.241.7Kuwait
MA41.214.129.22Morocco
MD77.89.251.70Republic Of Moldova
MD95.65.86.236Republic Of Moldova
MN180.149.96.169Mongolia
MV202.21.182.26Republic of Maldives
MX177.227.88.125Mexico
MX177.228.74.54Mexico
MX187.162.207.98Mexico
MX187.244.120.28Mexico
MX187.247.92.77Mexico
MX189.198.198.35Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX200.76.63.75Mexico
MX201.159.106.90Mexico
MX201.164.145.236Mexico
NI186.1.10.154Nicaragua
NL185.13.224.51Netherlands
NL213.126.90.227Netherlands
NO80.202.250.41Norway
NO212.4.34.78Norway
NZ121.73.60.67New Zealand
NZ202.169.192.130New Zealand
PA190.33.184.107Panama
PH112.199.89.158Philippines
PH121.97.26.86Philippines
PH124.104.141.204Philippines
PH202.124.193.11Philippines
PH210.16.60.5Philippines
PK61.5.156.195Pakistan
PK111.68.104.132Pakistan
PK121.52.154.230Pakistan
PK202.69.45.52Pakistan
PK210.2.171.13Pakistan
RO89.32.226.102Romania
RO91.220.26.4Romania
RS84.22.61.190Serbia
RS89.216.30.165Serbia
RS178.149.182.28Serbia
RS194.106.178.161Serbia
RU84.17.27.245Russian Federation
RU94.154.74.145Russian Federation
RU178.237.184.222Russian Federation
RU188.134.20.63Russian Federation
SA94.77.199.148Saudi Arabia
SE89.160.116.194Sweden
SK195.168.85.26Slovakia
SN196.207.216.131Senegal
SV190.86.180.193El Salvador
TN41.230.10.190Tunisia
TN193.95.90.194Tunisia
TR82.222.189.43Turkey
TR89.145.185.42Turkey
TR188.132.237.61Turkey
UA188.191.238.205Ukraine
US50.156.91.52United States
US50.194.150.131United States
US67.20.29.147United States
US67.236.113.226United States
US108.163.195.37United States
US108.166.205.163United States
US184.82.232.167United States
US192.30.84.133United States
US192.30.84.153United States
US192.81.249.4United States
US192.184.3.251United States
US199.101.48.123United States
US199.188.194.208United States
US205.208.148.104United States
US207.157.71.132United States
US207.182.133.221United States
US208.89.209.81United States
US209.239.112.104United States

List from greylisting:

Botnet Statistics [2013-04-22]

detection period: 2013-04-22 00:00-23:59 UTC
total number of suspected botnet IPs: 6545
number of botnet IPs notified to network operators: 5900
number of spam blocked: 85260
recipient count of spam blocked: 2523918

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here 10 days after its respective botnet statistics gets published.

Suspected Bots IP [2013-04-22]

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-JS2496
2CRTC343
3CHINANET-HE273
4BY-BELPAK-20091210193
5CHINANET-GD156
6CTTNET120
7UNICOM-GD119
8BY-BELPAK-2012033051
9BY-BELPAK-2008021347
10TimeNet43

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China4032
2United States378
3Belarus368
4Ukraine212
5Kazakhstan143
6Brazil108
7Russian Federation101
8India76
9Peru70
10Viet Nam62

Monday, April 22, 2013

Suspected Bot List [2013-04-21]

detection period: 2013-04-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 482

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE94.200.108.10Arab Emirates
AL77.242.27.111Albania
AL80.78.67.98Albania
AL82.114.70.102Albania
AL213.207.41.34Albania
AM141.136.65.119Armenia
AO196.223.13.230Angola
BD180.211.179.30Bangladesh
BG77.85.175.82Bulgaria
BR150.161.30.7Brazil
BR177.137.0.123Brazil
CA70.38.37.207Canada
CA99.244.26.71Canada
CH31.7.63.44Switzerland
CN202.107.222.50China
CO190.0.60.238Colombia
CZ77.104.244.69Czech Republic
DE62.113.213.202Germany
DE77.23.13.20Germany
DE78.138.117.42Germany
DE80.241.212.224Germany
DE84.11.89.66Germany
DE84.246.251.237Germany
DE85.195.73.98Germany
DE87.106.91.124Germany
DE88.152.29.67Germany
DZ41.221.30.242Algeria
EC186.5.102.162Ecuador
EC186.42.182.5Ecuador
EE5.34.241.93Estonia
EG196.218.229.14Egypt
ES84.124.36.238Spain
ES87.216.240.245Spain
ES149.126.34.213Spain
GB46.17.63.169United Kingdom
GB46.166.178.84United Kingdom
GB77.246.20.2United Kingdom
GB83.218.130.114United Kingdom
GB89.105.3.212United Kingdom
GB93.93.129.119United Kingdom
GB95.154.243.37United Kingdom
GB146.185.31.170United Kingdom
GB188.227.161.40United Kingdom
GB188.227.161.46United Kingdom
GB188.227.161.47United Kingdom
GB193.164.207.16United Kingdom
GH212.96.12.199Ghana
GR78.87.9.40Greece
GT186.151.253.186Guatemala
HN190.107.140.77Honduras
IN14.139.191.193India
IN61.1.33.177India
IN117.211.91.147India
IN117.239.29.114India
IN117.239.132.146India
IN117.240.124.68India
IN117.240.239.120India
IN122.180.96.110India
IN122.183.99.146India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IN203.153.39.18India
IQ95.159.105.2Iraq
IQ109.224.20.138Iraq
IR82.99.246.10Iran
IR89.165.109.165Iran
IR93.126.25.35Iran
IR185.2.12.98Iran
IT213.149.213.37Italy
JO87.236.232.231Jordan
KE41.89.96.20Kenya
KW62.150.12.46Kuwait
KW213.132.241.7Kuwait
LV94.30.129.199Latvia
MA41.214.129.22Morocco
MD77.89.251.70Republic Of Moldova
MN180.149.96.169Mongolia
MV202.21.182.26Republic of Maldives
MX177.227.88.125Mexico
MX187.162.207.98Mexico
MX189.198.198.35Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX200.57.144.81Mexico
MX200.76.63.75Mexico
MX201.159.106.90Mexico
MX201.164.145.236Mexico
NI186.1.10.154Nicaragua
NO80.202.250.41Norway
NO212.4.34.78Norway
NZ121.73.60.67New Zealand
NZ202.169.192.130New Zealand
PA190.33.184.107Panama
PH121.97.26.86Philippines
PH124.104.141.204Philippines
PH202.124.193.11Philippines
PH210.16.60.5Philippines
PK61.5.156.195Pakistan
PK116.58.48.141Pakistan
PK121.52.154.230Pakistan
PK202.69.45.52Pakistan
PK210.2.171.13Pakistan
RO78.97.216.93Romania
RO91.220.26.4Romania
RS84.22.61.190Serbia
RS89.216.30.165Serbia
RS178.149.182.28Serbia
RS194.106.178.161Serbia
RU178.213.33.95Russian Federation
RU178.237.184.222Russian Federation
RU213.21.31.194Russian Federation
SE37.46.166.66Sweden
SE89.160.116.194Sweden
SK195.168.85.26Slovakia
SN196.207.216.131Senegal
SV190.86.180.193El Salvador
TJ217.11.177.26Tajikistan
TN41.230.10.190Tunisia
TN193.95.90.194Tunisia
TR82.222.171.203Turkey
TR82.222.189.43Turkey
TR85.105.126.140Turkey
TR89.145.185.42Turkey
TR188.132.237.61Turkey
UA82.207.51.92Ukraine
UA91.212.124.153Ukraine
UA188.191.238.205Ukraine
US50.156.91.52United States
US50.194.150.131United States
US64.33.143.164United States
US67.20.29.147United States
US67.236.113.226United States
US108.163.195.37United States
US192.30.84.133United States
US192.30.84.153United States
US192.81.249.4United States
US192.184.3.251United States
US198.143.188.10United States
US199.101.48.123United States
US199.188.194.208United States
US205.208.148.104United States
US206.190.158.235United States
US207.157.71.132United States
US207.182.133.221United States
US208.89.209.81United States
US216.224.166.223United States

List from greylisting:

Botnet Statistics [2013-04-21]

detection period: 2013-04-21 00:00-23:59 UTC
total number of suspected botnet IPs: 4460
number of botnet IPs notified to network operators: 3982
number of spam blocked: 138211
recipient count of spam blocked: 4071347

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here 10 days after its respective botnet statistics gets published.

Suspected Bots IP [2013-04-21]

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-JS1069
2CHINANET-HE252
3BY-BELPAK-20091210235
4CRTC159
5CHINANET-GD153
6UNICOM-GD132
7BY-BELPAK-2012033089
8TimeNet49
9HINET-NET48
10BY-BELPAK-2008021348

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2376
2Belarus456
3United States195
4Ukraine195
5Kazakhstan141
6Russian Federation88
7Brazil87
8Taiwan69
9India59
10Iran49

Sunday, April 21, 2013

Suspected Bot List [2013-04-20]

detection period: 2013-04-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 484

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE194.170.149.21Arab Emirates
AL82.114.70.102Albania
AL213.207.41.34Albania
AM141.136.65.119Armenia
AO41.63.166.3Angola
AO196.223.13.230Angola
BA87.250.99.210Bosnia And Herzegovina
BD180.211.179.30Bangladesh
BG77.85.175.82Bulgaria
BR150.161.30.7Brazil
BR177.137.0.123Brazil
BY212.98.187.147Belarus
CA70.38.37.207Canada
CN202.107.222.50China
CO190.0.60.238Colombia
CZ77.104.244.69Czech Republic
DE62.113.213.202Germany
DE62.141.36.188Germany
DE77.23.13.20Germany
DE80.241.212.224Germany
DE84.11.89.66Germany
DE85.195.73.98Germany
DE87.106.91.124Germany
DE185.10.71.188Germany
DZ41.221.30.242Algeria
DZ193.194.87.59Algeria
EE5.34.241.93Estonia
EG196.218.229.14Egypt
ES87.216.240.245Spain
ES149.126.34.213Spain
EU84.40.11.180European Union
GB37.220.1.55United Kingdom
GB77.246.20.2United Kingdom
GB83.218.130.114United Kingdom
GB89.105.3.212United Kingdom
GB93.93.129.119United Kingdom
GB95.154.243.37United Kingdom
GB109.200.12.166United Kingdom
GB109.203.112.236United Kingdom
GB146.185.31.170United Kingdom
GB188.227.161.40United Kingdom
GB188.227.161.46United Kingdom
GB193.164.207.16United Kingdom
GH212.96.12.199Ghana
GR78.87.9.40Greece
GT186.151.253.186Guatemala
HN190.107.140.77Honduras
IL82.102.153.250Israel
IN14.139.191.193India
IN59.96.66.2India
IN61.1.33.177India
IN117.211.91.147India
IN117.240.124.68India
IN117.240.239.120India
IN122.180.96.110India
IN122.183.99.146India
IN122.252.237.34India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IN203.153.39.18India
IR77.237.185.33Iran
IR82.99.246.10Iran
IR89.165.109.165Iran
IR93.126.25.35Iran
IR185.2.12.98Iran
IT213.149.213.37Italy
JO87.236.232.231Jordan
KE41.89.96.20Kenya
KE41.139.206.178Kenya
KW62.150.12.46Kuwait
KW213.132.241.7Kuwait
LV94.30.129.199Latvia
MA41.214.129.22Morocco
MD77.89.251.70Republic Of Moldova
MD95.65.86.236Republic Of Moldova
MN180.149.96.169Mongolia
MV202.21.182.26Republic of Maldives
MX177.227.88.125Mexico
MX177.228.74.54Mexico
MX187.141.185.118Mexico
MX187.162.207.98Mexico
MX187.174.173.18Mexico
MX189.198.198.35Mexico
MX189.198.207.148Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX200.57.144.81Mexico
MX200.76.63.75Mexico
MX201.159.106.90Mexico
NI186.1.10.154Nicaragua
NO80.202.250.41Norway
NO212.4.34.78Norway
NZ121.73.60.67New Zealand
NZ202.169.192.130New Zealand
PA190.33.184.107Panama
PH121.97.26.86Philippines
PH124.104.141.204Philippines
PH202.124.193.11Philippines
PH210.16.60.5Philippines
PK61.5.156.195Pakistan
PK116.58.48.141Pakistan
PK121.52.154.230Pakistan
PK202.69.45.52Pakistan
PK210.2.171.13Pakistan
PS213.244.123.205Occupied Palestinian Territory
RO78.97.216.93Romania
RO91.220.26.4Romania
RS84.22.61.190Serbia
RS89.216.30.165Serbia
RS178.149.182.28Serbia
RS194.106.178.161Serbia
RU94.154.74.145Russian Federation
RU178.213.33.95Russian Federation
RU213.21.31.194Russian Federation
SE89.160.116.194Sweden
SE91.95.40.3Sweden
SG58.185.103.222Singapore
SK93.184.71.66Slovakia
SK195.168.85.26Slovakia
SN196.207.216.131Senegal
TJ217.11.177.26Tajikistan
TN41.230.10.190Tunisia
TN193.95.90.194Tunisia
TR85.105.126.140Turkey
TR89.145.185.42Turkey
TR188.132.237.61Turkey
UA82.207.51.92Ukraine
UA91.212.124.153Ukraine
UA188.191.238.205Ukraine
US50.156.91.52United States
US50.194.150.131United States
US66.109.21.60United States
US67.20.29.147United States
US67.236.113.226United States
US108.163.195.37United States
US108.178.57.120United States
US174.123.154.98United States
US184.82.117.7United States
US184.82.120.190United States
US192.30.84.133United States
US192.30.84.153United States
US192.81.249.4United States
US192.184.3.251United States
US199.87.232.226United States
US199.188.194.208United States
US199.195.128.219United States
US205.208.148.104United States
US206.190.158.235United States
US207.157.71.132United States
US207.182.133.221United States
US208.89.209.81United States
US209.239.112.104United States

List from greylisting:

Botnet Statistics [2013-04-20]

detection period: 2013-04-20 00:00-23:59 UTC
total number of suspected botnet IPs: 3546
number of botnet IPs notified to network operators: 3067
number of spam blocked: 118840
recipient count of spam blocked: 3958871

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here 10 days after its respective botnet statistics gets published.

Suspected Bots IP [2013-04-20]

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-JS392
2BY-BELPAK-20091210200
3CHINANET-GD154
4UNICOM-GD93
5BY-BELPAK-2012033061
6CHINASKYNET55
7CHINANET-HE52
8CRTC51
9BY-BELPAK-2008021345
10BY-BELPAK-2012010643

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1356
2Belarus375
3United States218
4Ukraine175
5Kazakhstan150
6Russian Federation94
7Brazil94
8India84
9Peru67
10Taiwan64