Custom Search

Friday, May 31, 2013

Suspected Bot List [2013-05-30]

detection period: 2013-05-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 495

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE80.227.253.203Arab Emirates
AE83.111.92.120Arab Emirates
AL82.114.70.102Albania
AM46.162.230.50Armenia
AO41.63.166.3Angola
BO200.119.200.131Bolivia
BO201.222.117.26Bolivia
BR150.161.30.7Brazil
CI213.136.105.210Ivory Coast
CN112.0.170.4China
CR186.32.216.14Costa Rica
CU190.15.155.170Cuba
DE84.11.89.66Germany
DZ41.106.3.246Algeria
ES212.49.133.10Spain
ES212.49.136.26Spain
ES213.96.188.89Spain
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
GT200.30.165.178Guatemala
IN112.133.201.70India
IN114.143.188.178India
IN117.239.29.114India
IN117.240.239.120India
IN118.94.179.98India
IN122.180.71.10India
IN122.180.96.110India
IN122.183.99.146India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IQ95.159.105.2Iraq
IR82.99.246.10Iran
IR89.165.109.165Iran
IR94.183.138.253Iran
IR194.33.126.10Iran
IT77.93.245.2Italy
JO87.236.232.231Jordan
JO109.107.132.172Jordan
KH202.131.81.248Cambodia
KW62.150.12.46Kuwait
KW213.132.241.7Kuwait
LB212.36.193.188Lebanon
LB213.175.188.158Lebanon
MO180.94.150.60Macau
MV202.21.182.26Republic of Maldives
MX148.208.224.251Mexico
MX177.227.64.151Mexico
MX177.228.74.25Mexico
MX187.162.207.98Mexico
MX187.163.96.59Mexico
MX187.240.73.166Mexico
MX187.247.92.77Mexico
MX189.198.200.228Mexico
MX200.53.147.250Mexico
MX201.132.167.105Mexico
MX201.159.106.90Mexico
MX201.164.163.184Mexico
NI186.1.10.154Nicaragua
PH121.97.26.86Philippines
PH202.86.204.202Philippines
PH210.16.60.5Philippines
PK61.5.156.196Pakistan
PK111.68.104.132Pakistan
PK124.109.47.66Pakistan
PK202.69.44.194Pakistan
PK202.69.45.52Pakistan
RO89.120.75.51Romania
RO91.220.26.4Romania
RS178.148.147.249Serbia
RS178.149.182.28Serbia
SA94.77.199.148Saudi Arabia
SE46.246.28.47Sweden
SV190.86.180.193El Salvador
TN41.230.10.190Tunisia
TR82.222.189.43Turkey
TW61.228.0.198Taiwan
TW180.218.233.132Taiwan
UA91.212.124.153Ukraine
UA178.151.68.210Ukraine
UA178.151.86.1Ukraine
UA195.189.46.2Ukraine
US50.194.150.131United States
US66.55.76.185United States
US173.184.189.237United States
US192.161.54.12United States
US192.211.58.108United States
US206.217.198.12United States
US207.157.71.132United States
UY186.54.53.230Uruguay
VE190.93.44.76Venezuela
ZA196.46.136.117South Africa
ZW41.57.125.190Zimbabwe
ZW41.57.127.4Zimbabwe

List from greylisting:

Botnet Statistics [2013-05-30]

detection period: 2013-05-30 00:00-23:59 UTC
total number of suspected botnet IPs: 11092
number of botnet IPs notified to network operators: 10603
number of spam blocked: 60444
recipient count of spam blocked: 2131505

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-HB2027
2UNICOM-HA1585
3UNICOM-HB1542
4CHINANET-JS1414
5CHINANET-HE836
6UNICOM-HN448
7HINET-NET350
8CTTNET270
9CHINANET-HA201
10CHINANET-GD181

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China9090
2United States414
3Taiwan377
4Brazil88
5Peru66
6Russian Federation63
7Iran60
8India60
9Argentina58
10Mexico52

Thursday, May 30, 2013

Suspected Bot List [2013-05-29]

detection period: 2013-05-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 423

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE80.227.253.203Arab Emirates
AE83.111.92.120Arab Emirates
AL82.114.70.102Albania
AM46.162.230.50Armenia
AO41.63.166.3Angola
BG46.233.23.111Bulgaria
BO200.119.200.131Bolivia
BO201.222.117.26Bolivia
BR150.161.30.7Brazil
CI213.136.105.210Ivory Coast
CN112.0.170.4China
CR186.32.216.14Costa Rica
CR190.10.122.121Costa Rica
CU190.15.155.170Cuba
CZ77.104.244.69Czech Republic
CZ109.75.151.179Czech Republic
DE84.11.89.66Germany
DE88.152.29.67Germany
EC186.101.122.213Ecuador
ES212.49.133.10Spain
ES212.49.136.26Spain
GB77.246.20.2United Kingdom
GB94.12.60.60United Kingdom
GB109.204.5.228United Kingdom
GB193.164.207.16United Kingdom
GT200.30.165.178Guatemala
ID202.162.35.162Indonesia
IN115.115.142.54India
IN117.240.239.120India
IN118.94.179.98India
IN122.180.71.10India
IN122.180.96.110India
IN122.183.99.146India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IQ95.159.105.2Iraq
IR79.175.166.235Iran
IR82.99.246.10Iran
IR89.165.109.165Iran
IR94.183.138.253Iran
IT77.93.245.2Italy
JO87.236.232.231Jordan
JO109.107.132.172Jordan
KG212.97.24.134Kyrgyzstan
KW213.132.241.7Kuwait
LB212.36.193.188Lebanon
LB213.175.188.158Lebanon
LU94.242.204.74Luxembourg
MO180.94.150.60Macau
MV202.21.182.26Republic of Maldives
MX148.204.14.253Mexico
MX148.208.224.251Mexico
MX177.228.74.25Mexico
MX187.162.207.98Mexico
MX187.163.96.59Mexico
MX187.240.73.166Mexico
MX187.247.92.77Mexico
MX187.247.158.110Mexico
MX189.198.200.228Mexico
MX200.53.147.250Mexico
MX201.132.167.105Mexico
MX201.159.106.90Mexico
MX201.164.163.184Mexico
NG41.223.65.101Nigeria
NI186.1.10.154Nicaragua
NO212.4.34.78Norway
PG180.150.252.66New Guinea
PH120.28.8.194Philippines
PH121.97.26.86Philippines
PH202.86.204.202Philippines
PH210.16.60.5Philippines
PK61.5.156.196Pakistan
PK111.68.104.132Pakistan
PK124.109.47.66Pakistan
PK202.69.44.194Pakistan
PK202.69.45.52Pakistan
RO89.120.75.51Romania
RO91.220.26.4Romania
RS95.180.76.81Serbia
RS178.149.182.28Serbia
SA94.77.199.148Saudi Arabia
SE46.246.28.47Sweden
SV190.150.101.13El Salvador
SV201.247.103.161El Salvador
TN41.230.10.190Tunisia
TR82.222.189.43Turkey
TW36.226.0.10Taiwan
TW36.226.0.21Taiwan
TW36.226.0.43Taiwan
TW36.226.0.46Taiwan
TW36.226.0.79Taiwan
TW36.226.0.111Taiwan
TW36.226.0.130Taiwan
TW36.226.0.160Taiwan
TW61.228.0.198Taiwan
TW180.218.233.132Taiwan
TW220.137.0.50Taiwan
TW220.137.0.157Taiwan
TW220.137.0.236Taiwan
UA178.151.68.210Ukraine
UA178.151.86.1Ukraine
UA195.189.46.2Ukraine
UNKNOWN190.52.205.5UNKNOWN
US50.194.150.131United States
US66.55.76.185United States
US173.45.79.38United States
US173.184.189.237United States
US192.161.54.12United States
US192.211.58.108United States
US198.154.60.221United States
US199.193.66.161United States
US205.208.148.104United States
US206.217.198.12United States
VE190.93.44.76Venezuela
ZA196.46.136.117South Africa
ZW41.57.125.190Zimbabwe
ZW41.57.127.4Zimbabwe

List from greylisting:

Botnet Statistics [2013-05-29]

detection period: 2013-05-29 00:00-23:59 UTC
total number of suspected botnet IPs: 10868
number of botnet IPs notified to network operators: 10458
number of spam blocked: 91589
recipient count of spam blocked: 3169641

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-HB1757
2UNICOM-HA1419
3CHINANET-JS1274
4UNICOM-HB1107
5CHINANET-HE1071
6HINET-NET863
7UNICOM-HN420
8CRTC178
9CHINANET-HA177
10CTTNET172

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China8418
2Taiwan877
3United States340
4Brazil93
5Spain64
6Argentina60
7Russian Federation58
8Colombia58
9Peru55
10Mexico54

Wednesday, May 29, 2013

Suspected Bot List [2013-05-28]

detection period: 2013-05-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 335

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE194.170.149.22Arab Emirates
AL82.114.70.102Albania
AM46.162.230.50Armenia
AO41.63.166.3Angola
BG46.233.23.111Bulgaria
BO200.119.200.131Bolivia
BO201.222.117.26Bolivia
BR150.161.30.7Brazil
CI213.136.105.210Ivory Coast
CN112.0.170.4China
CO190.6.160.146Colombia
CR186.32.216.14Costa Rica
CR190.10.122.121Costa Rica
CU190.15.155.170Cuba
CZ77.104.244.69Czech Republic
DE84.11.89.66Germany
DE212.87.141.94Germany
EC181.112.224.130Ecuador
ES212.49.136.26Spain
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
GQ41.222.115.225Equatorial Guinea
GT200.30.165.178Guatemala
HN190.107.140.77Honduras
IN117.218.129.170India
IN117.240.239.120India
IN118.94.179.98India
IN122.180.71.10India
IN122.180.96.110India
IN122.183.99.146India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IQ95.159.105.2Iraq
IR79.175.166.235Iran
IR89.165.109.165Iran
IR91.98.117.30Iran
IR94.183.138.253Iran
IT149.139.10.132Italy
IT213.149.209.82Italy
JO87.236.232.231Jordan
JO109.107.132.172Jordan
KE41.89.96.20Kenya
KG212.97.24.134Kyrgyzstan
KW62.150.12.46Kuwait
KW213.132.241.7Kuwait
LB212.36.193.188Lebanon
LB213.175.188.158Lebanon
LU94.242.204.74Luxembourg
MV202.21.182.26Republic of Maldives
MX148.204.14.253Mexico
MX148.208.224.251Mexico
MX177.227.64.151Mexico
MX177.228.74.25Mexico
MX187.162.207.98Mexico
MX187.240.73.166Mexico
MX187.247.92.77Mexico
MX189.194.170.198Mexico
MX189.198.200.228Mexico
MX200.53.147.250Mexico
MX201.132.167.105Mexico
MX201.159.106.90Mexico
MX201.164.163.184Mexico
NG41.223.65.101Nigeria
NI186.1.10.154Nicaragua
PA190.33.184.107Panama
PG180.150.252.66New Guinea
PH121.97.26.86Philippines
PH202.86.204.202Philippines
PH210.16.60.5Philippines
PK61.5.156.196Pakistan
PK111.68.104.132Pakistan
PK121.52.154.230Pakistan
PK124.109.47.66Pakistan
PK202.69.45.52Pakistan
RO91.220.26.4Romania
RO188.240.22.164Romania
RS95.180.76.81Serbia
RS178.149.182.28Serbia
RS194.106.178.161Serbia
RU109.227.240.23Russian Federation
SA94.77.199.148Saudi Arabia
SV201.247.103.161El Salvador
TN41.230.10.190Tunisia
TR82.222.189.43Turkey
TW36.226.0.62Taiwan
TW61.228.0.94Taiwan
UA91.212.124.153Ukraine
UA178.151.68.210Ukraine
UA178.151.86.1Ukraine
UNKNOWN190.52.205.5UNKNOWN
US50.194.150.131United States
US66.55.76.185United States
US66.212.17.105United States
US67.20.29.147United States
US173.184.189.237United States
US192.161.54.12United States
US192.211.58.108United States
US198.154.60.221United States
US199.89.53.45United States
US199.193.66.161United States
US205.208.148.104United States
US207.157.71.132United States
VE190.93.44.76Venezuela
ZA196.46.136.117South Africa
ZW41.57.125.190Zimbabwe
ZW41.57.127.4Zimbabwe

List from greylisting:

Botnet Statistics [2013-05-28]

detection period: 2013-05-28 00:00-23:59 UTC
total number of suspected botnet IPs: 9593
number of botnet IPs notified to network operators: 9261
number of spam blocked: 85516
recipient count of spam blocked: 2968254

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-HB1591
2UNICOM-HA1532
3UNICOM-HB1174
4CHINANET-HE1090
5CHINANET-JS1052
6HINET-NET468
7UNICOM-HN276
8CHINANET-HA217
9CHINANET-GD150
10CTTNET98

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China7922
2Taiwan481
3United States226
4Brazil97
5India55
6Peru54
7Iran50
8Russian Federation49
9Kazakhstan44
10Mexico42

Tuesday, May 28, 2013

Suspected Bot List [2013-05-27]

detection period: 2013-05-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 489

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE194.170.149.22Arab Emirates
AL80.78.67.98Albania
AL80.78.75.158Albania
AL82.114.70.102Albania
AM46.162.230.50Armenia
AO41.63.166.3Angola
BO200.119.200.131Bolivia
BO201.222.117.26Bolivia
BR150.161.30.7Brazil
CI213.136.105.210Ivory Coast
CN112.0.170.4China
CR190.10.122.121Costa Rica
CU190.15.155.170Cuba
CZ80.188.2.54Czech Republic
DE84.11.89.66Germany
EC181.112.224.130Ecuador
ES212.49.136.26Spain
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
GQ41.222.115.225Equatorial Guinea
GT200.30.165.178Guatemala
HN190.107.140.77Honduras
IN117.218.129.170India
IN117.240.239.120India
IN118.94.179.98India
IN122.180.71.10India
IN122.180.96.110India
IN122.183.99.146India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IQ95.159.105.2Iraq
IR89.165.109.165Iran
IR91.98.117.30Iran
IR94.183.138.253Iran
IT149.139.10.132Italy
IT178.248.177.98Italy
IT213.149.209.82Italy
JO87.236.232.231Jordan
JO109.107.132.172Jordan
KE41.89.96.20Kenya
KW213.132.241.7Kuwait
LB212.36.193.188Lebanon
LB213.175.188.158Lebanon
LU94.242.204.74Luxembourg
MV202.21.182.26Republic of Maldives
MX148.204.14.253Mexico
MX148.208.224.251Mexico
MX177.227.64.151Mexico
MX177.228.74.25Mexico
MX177.228.75.63Mexico
MX187.162.207.98Mexico
MX187.240.73.166Mexico
MX187.247.92.77Mexico
MX189.194.170.198Mexico
MX189.198.200.228Mexico
MX200.53.147.250Mexico
MX200.57.144.81Mexico
MX201.132.167.105Mexico
MX201.159.106.90Mexico
MX201.164.163.184Mexico
NG41.223.65.101Nigeria
NI186.1.10.154Nicaragua
PH121.97.26.86Philippines
PH202.86.204.202Philippines
PH210.16.60.5Philippines
PK61.5.156.196Pakistan
PK111.68.104.132Pakistan
PK121.52.154.230Pakistan
PK124.109.47.66Pakistan
RO89.120.75.51Romania
RO91.220.26.4Romania
RS178.149.182.28Serbia
SA94.77.199.148Saudi Arabia
SE46.246.28.47Sweden
TN41.230.10.190Tunisia
TR82.222.189.43Turkey
TW36.226.0.33Taiwan
TW61.228.0.16Taiwan
TW61.228.0.93Taiwan
TW61.228.0.108Taiwan
TW61.228.0.195Taiwan
TW61.228.0.214Taiwan
TW61.228.0.226Taiwan
TW180.218.233.132Taiwan
TW220.137.0.42Taiwan
UA91.212.124.153Ukraine
UA178.151.68.210Ukraine
UNKNOWN190.52.205.5UNKNOWN
US50.194.150.131United States
US173.184.189.237United States
US192.161.54.12United States
US192.211.58.108United States
US198.154.60.221United States
US199.89.53.45United States
US206.217.198.12United States
VE190.93.44.76Venezuela
ZA196.46.136.117South Africa
ZW41.57.125.190Zimbabwe
ZW41.57.127.4Zimbabwe

List from greylisting:

Botnet Statistics [2013-05-27]

detection period: 2013-05-27 00:00-23:59 UTC
total number of suspected botnet IPs: 11540
number of botnet IPs notified to network operators: 11064
number of spam blocked: 83844
recipient count of spam blocked: 2845040

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-HA2142
2CHINANET-JS1929
3CHINANET-HB1821
4UNICOM-HB1130
5CHINANET-HE804
6HINET-NET615
7CHINANET-HA374
8UNICOM-HN250
9CHINANET-GD200
10CTTNET187

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China9487
2Taiwan638
3United States259
4India120
5Brazil96
6Russian Federation69
7Peru49
8Ukraine46
9Mexico42
10Kazakhstan42

Monday, May 27, 2013

Suspected Bot List [2013-05-26]

detection period: 2013-05-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 179

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE194.170.149.22Arab Emirates
AL80.78.67.98Albania
AL80.78.75.158Albania
AL82.114.70.102Albania
AM46.162.230.50Armenia
AO41.63.166.3Angola
BD123.200.15.158Bangladesh
BD180.211.179.30Bangladesh
BD180.211.191.250Bangladesh
BO200.119.200.131Bolivia
BR150.161.30.7Brazil
CI213.136.105.210Ivory Coast
CM41.211.125.123Cameroon
CN112.0.170.4China
CO190.6.160.146Colombia
CU190.15.155.170Cuba
CZ77.104.244.69Czech Republic
CZ80.188.2.54Czech Republic
DE84.11.89.66Germany
DE212.87.141.94Germany
DZ193.194.87.59Algeria
EC181.112.224.130Ecuador
EC186.101.122.213Ecuador
ES212.49.136.26Spain
ES213.0.89.6Spain
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
GE92.51.109.182Republic Of Georgia
GR150.140.141.198Greece
GT200.30.165.178Guatemala
HN190.107.140.77Honduras
IN117.218.58.152India
IN117.218.70.103India
IN117.218.129.170India
IN117.240.239.120India
IN118.94.179.98India
IN122.180.71.10India
IN122.180.96.110India
IN122.183.99.146India
IN182.72.118.131India
IN182.72.221.98India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IQ95.159.105.2Iraq
IR79.175.166.235Iran
IR89.165.109.165Iran
IR94.183.138.253Iran
IR109.125.173.226Iran
IR212.16.76.162Iran
IS213.190.104.150Iceland
IT93.88.37.10Italy
IT149.139.10.132Italy
IT213.149.209.82Italy
JO87.236.232.231Jordan
JO109.107.132.172Jordan
KE41.89.96.20Kenya
KG212.97.24.134Kyrgyzstan
KW62.150.12.46Kuwait
KW213.132.241.7Kuwait
LB212.36.193.188Lebanon
LB213.175.188.158Lebanon
LU94.242.204.74Luxembourg
MD95.65.86.236Republic Of Moldova
MV202.21.182.26Republic of Maldives
MX177.228.74.25Mexico
MX177.228.75.63Mexico
MX187.162.207.98Mexico
MX187.247.92.77Mexico
MX189.194.170.198Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX200.57.144.81Mexico
MX201.132.167.105Mexico
MX201.159.106.90Mexico
MX201.164.163.184Mexico
NI186.1.10.154Nicaragua
NZ121.73.60.67New Zealand
PH121.97.26.86Philippines
PH202.86.204.202Philippines
PH210.16.60.5Philippines
PK61.5.156.196Pakistan
PK111.68.104.132Pakistan
PK115.186.58.131Pakistan
PK121.52.154.230Pakistan
PK124.109.47.66Pakistan
PK202.69.45.52Pakistan
RO89.120.75.51Romania
RO91.220.26.4Romania
RO188.240.22.164Romania
RS194.106.178.161Serbia
SA94.77.199.148Saudi Arabia
SE46.246.28.47Sweden
SV190.150.101.13El Salvador
TN41.230.10.190Tunisia
TR82.222.189.43Turkey
TR193.255.143.62Turkey
TW61.228.0.175Taiwan
TW61.228.0.195Taiwan
TW114.36.0.234Taiwan
TW220.137.0.56Taiwan
UA91.212.124.153Ukraine
UA178.151.68.210Ukraine
UA178.151.86.1Ukraine
US50.194.150.131United States
US66.212.17.105United States
US67.20.29.147United States
US96.32.107.166United States
US173.184.189.237United States
US192.161.54.12United States
US192.211.58.108United States
US198.154.60.221United States
US199.193.66.161United States
US205.208.148.104United States
US206.217.198.12United States
US207.157.71.132United States
US209.190.27.211United States
UY201.217.154.74Uruguay
VE190.93.44.76Venezuela
ZA196.46.136.117South Africa
ZW41.57.125.190Zimbabwe
ZW41.57.127.4Zimbabwe

List from greylisting:

Botnet Statistics [2013-05-26]

detection period: 2013-05-26 00:00-23:59 UTC
total number of suspected botnet IPs: 9281
number of botnet IPs notified to network operators: 9108
number of spam blocked: 86120
recipient count of spam blocked: 2998589

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-HA1873
2CHINANET-HB1847
3CHINANET-JS883
4UNICOM-HB804
5HINET-NET713
6CHINANET-HE694
7CHINANET-HA341
8CRTC247
9UNICOM-HN245
10CHINANET-GD212

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China7694
2Taiwan720
3United States173
4Brazil87
5Russian Federation63
6Iran47
7France33
8Colombia26
9South Korea25
10Germany24

Sunday, May 26, 2013

Suspected Bot List [2013-05-25]

detection period: 2013-05-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 440

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE194.170.149.22Arab Emirates
AL80.78.67.98Albania
AL82.114.70.102Albania
AM46.162.230.50Armenia
AO41.63.166.3Angola
BO200.119.200.131Bolivia
BO201.222.117.26Bolivia
BR150.161.30.7Brazil
CI213.136.105.210Ivory Coast
CO190.6.160.146Colombia
CR190.10.122.121Costa Rica
CU190.15.155.170Cuba
CZ77.104.244.69Czech Republic
CZ80.188.2.54Czech Republic
DE84.11.89.66Germany
DE212.87.141.94Germany
DZ193.194.87.59Algeria
ES212.49.136.26Spain
ES213.0.89.6Spain
GB62.133.24.182United Kingdom
GB77.246.20.2United Kingdom
GB83.218.130.114United Kingdom
GB193.164.207.16United Kingdom
GE92.51.109.182Republic Of Georgia
GT200.30.165.178Guatemala
HN190.107.140.77Honduras
ID202.162.35.162Indonesia
IN49.128.162.50India
IN103.5.185.19India
IN111.93.108.194India
IN117.218.129.170India
IN117.240.239.120India
IN118.94.179.98India
IN122.180.71.10India
IN122.180.96.110India
IN122.183.99.146India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IQ95.159.105.2Iraq
IQ109.224.20.138Iraq
IR85.9.75.215Iran
IR89.165.109.165Iran
IR109.125.173.226Iran
IR194.33.126.10Iran
IR212.16.76.162Iran
IS213.190.104.150Iceland
IT93.88.37.10Italy
IT149.139.10.132Italy
JO87.236.232.231Jordan
KG212.97.24.134Kyrgyzstan
KW213.132.241.7Kuwait
LB212.36.193.188Lebanon
LB213.175.188.158Lebanon
LU94.242.204.74Luxembourg
MD95.65.86.236Republic Of Moldova
MD178.168.43.130Republic Of Moldova
MV202.21.182.26Republic of Maldives
MX148.204.14.253Mexico
MX148.208.224.251Mexico
MX177.228.74.25Mexico
MX187.162.207.98Mexico
MX187.247.92.77Mexico
MX189.194.170.198Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX201.132.167.105Mexico
MX201.159.106.90Mexico
MX201.164.163.184Mexico
NI186.1.10.154Nicaragua
PH121.97.26.86Philippines
PH202.86.204.202Philippines
PH210.16.60.5Philippines
PK61.5.156.196Pakistan
PK110.93.215.186Pakistan
PK111.68.104.132Pakistan
PK115.186.58.131Pakistan
PK121.52.154.230Pakistan
PK124.109.47.66Pakistan
PK202.69.40.170Pakistan
PK202.69.45.52Pakistan
RO89.120.75.51Romania
RO91.220.26.4Romania
RS95.180.120.97Serbia
RU95.78.57.97Russian Federation
SA94.77.199.148Saudi Arabia
SE46.246.28.47Sweden
SK93.184.71.66Slovakia
SV201.247.174.177El Salvador
TN41.230.10.190Tunisia
TR82.222.189.43Turkey
TR193.255.143.62Turkey
TW61.228.0.188Taiwan
TW61.228.0.199Taiwan
TW61.228.0.237Taiwan
TW220.137.0.225Taiwan
UA178.151.68.210Ukraine
UA178.151.86.1Ukraine
US24.182.136.146United States
US50.194.150.131United States
US66.190.188.60United States
US173.184.189.237United States
US192.161.54.12United States
US192.211.58.108United States
US198.154.60.221United States
US205.208.148.104United States
US206.217.198.12United States
US209.239.112.104United States
US216.176.131.99United States
UY201.217.154.74Uruguay
UZ185.8.212.82Uzbekistan
VE190.93.44.76Venezuela
ZA196.46.136.117South Africa
ZW41.57.125.190Zimbabwe
ZW41.57.127.4Zimbabwe

List from greylisting:

Botnet Statistics [2013-05-25]

detection period: 2013-05-25 00:00-23:59 UTC
total number of suspected botnet IPs: 7013
number of botnet IPs notified to network operators: 6583
number of spam blocked: 97295
recipient count of spam blocked: 2632828

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-HA1430
2CHINANET-HB1212
3UNICOM-HB739
4HINET-NET443
5CHINANET-HA300
6UNICOM-HN248
7CHINANET-GD186
8UNICOM-GD116
9CTTNET95
10CRTC69

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China5154
2Taiwan458
3United States189
4Brazil94
5India76
6Russian Federation75
7Viet Nam57
8South Korea57
9Iran52
10Colombia51

Saturday, May 25, 2013

Suspected Bot List [2013-05-24]

detection period: 2013-05-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 437

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE194.170.149.22Arab Emirates
AL82.114.70.102Albania
AM46.162.230.50Armenia
AO41.63.166.3Angola
BD180.211.179.30Bangladesh
BO200.119.200.131Bolivia
BR150.161.30.7Brazil
BR177.137.0.123Brazil
BY213.184.241.88Belarus
CI213.136.105.210Ivory Coast
CR190.10.122.121Costa Rica
CZ80.188.2.54Czech Republic
DE84.11.89.66Germany
ES212.49.136.26Spain
ES213.0.89.6Spain
ES217.16.255.159Spain
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IL82.102.158.5Israel
IN49.128.162.50India
IN111.93.108.194India
IN115.115.142.54India
IN117.218.129.170India
IN117.240.239.120India
IN118.94.179.98India
IN122.180.71.10India
IN122.180.96.110India
IN122.183.99.146India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IQ95.159.105.2Iraq
IQ109.224.20.138Iraq
IR82.99.246.10Iran
IR89.165.109.165Iran
IR194.33.126.10Iran
IR212.16.76.162Iran
IT93.88.37.10Italy
IT149.139.10.132Italy
JO87.236.232.231Jordan
JO109.107.132.172Jordan
KW62.150.12.46Kuwait
KW213.132.241.7Kuwait
LB212.36.193.188Lebanon
LB213.175.188.158Lebanon
MV202.21.182.26Republic of Maldives
MX148.204.14.253Mexico
MX148.208.224.251Mexico
MX177.224.19.159Mexico
MX177.224.245.64Mexico
MX177.228.74.25Mexico
MX177.228.75.63Mexico
MX187.162.207.98Mexico
MX189.194.170.198Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX201.132.167.105Mexico
MX201.159.106.90Mexico
NG41.223.65.101Nigeria
NI186.1.10.154Nicaragua
PA190.33.184.107Panama
PG180.150.252.66New Guinea
PH112.199.89.158Philippines
PH121.97.26.86Philippines
PH202.86.204.202Philippines
PK61.5.156.196Pakistan
PK111.68.104.132Pakistan
PK124.109.47.66Pakistan
PK202.69.40.170Pakistan
PK202.69.45.52Pakistan
RO89.120.75.51Romania
RO91.220.26.4Romania
RS178.149.63.175Serbia
RS178.149.182.28Serbia
RU81.24.85.98Russian Federation
SA94.77.199.148Saudi Arabia
SE46.246.28.47Sweden
SK93.184.71.66Slovakia
TN41.230.10.190Tunisia
TR82.222.189.43Turkey
TR193.255.143.63Turkey
TW36.226.0.6Taiwan
TW36.226.0.174Taiwan
TW36.226.0.232Taiwan
TW61.228.0.192Taiwan
TW180.218.233.132Taiwan
TW220.137.0.122Taiwan
UA91.212.124.153Ukraine
UA178.151.68.210Ukraine
UA178.151.86.1Ukraine
US50.192.170.241United States
US50.194.150.131United States
US66.190.188.60United States
US96.32.107.166United States
US108.163.195.37United States
US192.161.54.12United States
US192.211.58.108United States
US198.154.60.221United States
US199.193.66.161United States
US206.217.198.12United States
US209.239.112.104United States
VE190.93.44.76Venezuela
ZW41.57.125.190Zimbabwe
ZW41.57.127.4Zimbabwe

List from greylisting:

Botnet Statistics [2013-05-24]

detection period: 2013-05-24 00:00-23:59 UTC
total number of suspected botnet IPs: 9216
number of botnet IPs notified to network operators: 8790
number of spam blocked: 102589
recipient count of spam blocked: 3086617

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-HA1819
2CHINANET-HB1486
3UNICOM-HB1225
4CHINANET-HE921
5HINET-NET461
6UNICOM-HN243
7CHINANET-HA223
8CHINANET-GD219
9CTTNET123
10CRTC94

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China7107
2Taiwan483
3United States434
4Brazil100
5Russian Federation85
6India73
7Spain55
8Argentina48
9Germany45
10Iran44

Suspected Bot List [2013-05-23]

detection period: 2013-05-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 355

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE194.170.149.22Arab Emirates
AL82.114.70.102Albania
AM46.162.230.50Armenia
AO196.223.13.230Angola
BG212.73.156.197Bulgaria
BO200.119.200.131Bolivia
BO201.222.117.26Bolivia
BR150.161.30.7Brazil
BR177.137.0.123Brazil
BY213.184.241.88Belarus
CA198.50.166.144Canada
CI213.136.105.210Ivory Coast
CO190.0.60.238Colombia
DE84.11.89.66Germany
ES212.49.136.26Spain
ES213.0.89.6Spain
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
GT200.30.165.178Guatemala
HN190.107.140.77Honduras
IL82.102.158.5Israel
IN27.49.107.83India
IN59.96.66.2India
IN117.239.29.114India
IN117.240.239.120India
IN117.244.15.245India
IN118.94.179.98India
IN122.180.71.10India
IN122.180.96.110India
IN122.183.99.146India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IQ95.159.105.2Iraq
IQ109.224.20.138Iraq
IR89.165.109.165Iran
IR94.183.138.253Iran
IR212.16.76.162Iran
IT91.214.62.59Italy
IT149.139.10.132Italy
JO87.236.232.231Jordan
JO109.107.132.172Jordan
KW213.132.241.7Kuwait
KZ91.185.21.34Kazakhstan
LB212.36.193.188Lebanon
LB213.175.188.158Lebanon
MV202.21.182.26Republic of Maldives
MX148.204.14.253Mexico
MX177.224.19.159Mexico
MX177.228.74.25Mexico
MX177.228.75.63Mexico
MX187.162.207.98Mexico
MX187.247.92.77Mexico
MX189.194.170.198Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX200.57.144.81Mexico
MX201.132.167.105Mexico
MX201.159.106.90Mexico
MX201.164.163.184Mexico
NG41.223.65.101Nigeria
NI186.1.10.154Nicaragua
PG180.150.252.66New Guinea
PH121.97.26.86Philippines
PH202.86.204.202Philippines
PH202.124.193.11Philippines
PK61.5.156.196Pakistan
PK111.68.104.132Pakistan
PK124.109.47.66Pakistan
PK125.209.67.38Pakistan
PK202.69.40.170Pakistan
PK202.69.45.52Pakistan
PK202.142.158.122Pakistan
RO89.120.75.51Romania
RO91.220.26.4Romania
RS178.149.63.175Serbia
RS178.149.182.28Serbia
RU81.24.85.98Russian Federation
RU194.24.241.235Russian Federation
SA94.77.199.148Saudi Arabia
SA212.138.144.5Saudi Arabia
SV190.150.101.13El Salvador
TN41.230.10.190Tunisia
TR82.222.189.43Turkey
TR193.255.143.62Turkey
TW61.228.0.228Taiwan
UA91.212.124.153Ukraine
UA178.151.68.210Ukraine
UA178.151.86.1Ukraine
UNKNOWN190.52.205.5UNKNOWN
US50.194.150.131United States
US66.190.188.60United States
US108.163.195.37United States
US173.184.189.237United States
US192.161.54.12United States
US192.211.58.108United States
US198.154.60.221United States
US199.193.66.161United States
US207.157.71.132United States
US209.239.112.104United States
VE190.93.44.76Venezuela
ZW41.57.125.190Zimbabwe
ZW41.57.127.4Zimbabwe

List from greylisting:

Botnet Statistics [2013-05-23]

detection period: 2013-05-23 00:00-23:59 UTC
total number of suspected botnet IPs: 9245
number of botnet IPs notified to network operators: 8901
number of spam blocked: 67220
recipient count of spam blocked: 2440923

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-HB1755
2UNICOM-HA1585
3UNICOM-HB1171
4CHINANET-HE855
5CRTC496
6CHINANET-JS358
7CTTNET285
8CHINANET-HA259
9UNICOM-HN242
10CHINANET-GD198

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China7710
2United States303
3Russian Federation96
4Brazil96
5Taiwan49
6Iran49
7Colombia48
8India47
9Germany46
10Peru44

Thursday, May 23, 2013

Suspected Bot List [2013-05-22]

detection period: 2013-05-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 599

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE194.170.149.22Arab Emirates
AL82.114.70.102Albania
AM46.162.230.50Armenia
AO41.63.166.3Angola
AO196.223.13.230Angola
BD180.211.170.86Bangladesh
BG212.73.156.197Bulgaria
BO200.119.200.131Bolivia
BO201.222.117.26Bolivia
BR150.161.30.7Brazil
BY213.184.241.88Belarus
CA198.50.166.144Canada
CI213.136.105.210Ivory Coast
CR190.10.122.121Costa Rica
CZ77.104.244.69Czech Republic
DE84.11.89.66Germany
ES212.49.136.26Spain
ES217.16.255.159Spain
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
GE92.51.109.182Republic Of Georgia
GT200.30.165.178Guatemala
HN190.107.140.77Honduras
IL82.102.158.5Israel
IN27.49.105.80India
IN27.49.107.83India
IN59.96.66.2India
IN117.240.239.120India
IN117.244.15.245India
IN118.94.179.98India
IN122.180.71.10India
IN122.180.96.110India
IN122.183.99.146India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IQ95.159.105.2Iraq
IR89.165.109.165Iran
IR91.98.117.30Iran
IR94.183.138.253Iran
IR212.16.76.162Iran
IS213.190.104.150Iceland
IT91.214.62.59Italy
IT149.139.10.132Italy
JO87.236.232.231Jordan
JO109.107.132.172Jordan
KW213.132.241.7Kuwait
KW213.132.241.50Kuwait
KW213.132.241.232Kuwait
KZ91.185.21.34Kazakhstan
LB212.36.193.188Lebanon
LB213.175.188.158Lebanon
MV202.21.182.26Republic of Maldives
MX148.204.14.253Mexico
MX177.228.74.25Mexico
MX177.228.75.63Mexico
MX187.162.207.98Mexico
MX187.247.92.77Mexico
MX189.194.170.198Mexico
MX200.33.20.40Mexico
MX201.132.167.105Mexico
MX201.159.106.90Mexico
MX201.164.163.184Mexico
NG41.223.65.101Nigeria
NI186.1.10.154Nicaragua
NL159.253.147.195Netherlands
PE186.64.125.98Peru
PG180.150.252.66New Guinea
PH121.97.26.86Philippines
PH202.86.204.202Philippines
PH202.124.193.11Philippines
PK61.5.156.196Pakistan
PK124.109.47.66Pakistan
PK202.69.40.170Pakistan
PK202.69.45.52Pakistan
PK202.142.158.122Pakistan
RO89.120.75.51Romania
RO91.220.26.4Romania
RS178.149.182.28Serbia
RU81.24.85.98Russian Federation
RU109.229.55.211Russian Federation
RU194.24.241.235Russian Federation
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
SV201.247.174.177El Salvador
TN41.230.10.190Tunisia
TR82.222.189.43Turkey
TR193.255.143.62Turkey
TW36.226.0.155Taiwan
TW61.228.0.172Taiwan
TW61.228.0.214Taiwan
TW61.228.0.228Taiwan
UA91.212.124.153Ukraine
UA178.151.68.210Ukraine
UA178.151.86.1Ukraine
UNKNOWN190.52.205.5UNKNOWN
US24.178.82.50United States
US50.194.150.131United States
US66.190.188.60United States
US69.18.205.139United States
US108.163.195.37United States
US173.184.189.237United States
US192.161.54.12United States
US192.211.58.108United States
US198.154.60.221United States
US199.87.232.107United States
US205.208.148.104United States
US207.157.71.132United States
VE190.93.44.76Venezuela
ZW41.57.125.190Zimbabwe
ZW41.57.127.4Zimbabwe

List from greylisting:

Botnet Statistics [2013-05-22]

detection period: 2013-05-22 00:00-23:59 UTC
total number of suspected botnet IPs: 12418
number of botnet IPs notified to network operators: 11832
number of spam blocked: 87180
recipient count of spam blocked: 2667282

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-JS2112
2CHINANET-HB1779
3UNICOM-HA1728
4UNICOM-HB1346
5HINET-NET852
6CHINANET-HE713
7CRTC447
8CHINANET-HA252
9UNICOM-HN239
10CTTNET221

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China9620
2Taiwan860
3United States508
4Brazil113
5South Korea107
6Russian Federation85
7India72
8Argentina71
9United Kingdom61
10Mexico53

Wednesday, May 22, 2013

Suspected Bot List [2013-05-21]

detection period: 2013-05-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 324

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE194.170.149.22Arab Emirates
AL82.114.70.102Albania
AM46.162.230.50Armenia
AO41.63.166.3Angola
BD180.211.170.86Bangladesh
BG212.73.156.197Bulgaria
BO200.119.200.131Bolivia
BO201.222.117.26Bolivia
BR150.161.30.7Brazil
BY213.184.241.88Belarus
CA198.50.166.144Canada
CI213.136.105.210Ivory Coast
CR190.10.122.121Costa Rica
CR201.191.179.42Costa Rica
CU190.15.155.170Cuba
DE84.11.89.66Germany
GB83.136.126.153United Kingdom
GT200.30.165.178Guatemala
HN190.107.140.77Honduras
IL82.102.158.5Israel
IN27.49.105.80India
IN117.239.29.114India
IN117.240.239.120India
IN118.94.179.98India
IN122.180.71.10India
IN122.180.96.110India
IN122.183.99.146India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IQ95.159.105.2Iraq
IR89.165.109.165Iran
IR91.98.117.30Iran
IR94.183.138.253Iran
IR212.16.76.162Iran
IT149.139.10.132Italy
JO87.236.232.231Jordan
JO109.107.132.172Jordan
KW213.132.241.7Kuwait
LB212.36.193.188Lebanon
LB213.175.188.158Lebanon
MV202.21.182.26Republic of Maldives
MX177.228.74.25Mexico
MX177.228.75.63Mexico
MX187.162.207.98Mexico
MX187.247.92.77Mexico
MX189.194.170.198Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX201.132.167.105Mexico
MX201.159.106.90Mexico
MX201.164.163.184Mexico
NG41.223.65.101Nigeria
NI186.1.10.154Nicaragua
PA190.33.184.107Panama
PE186.64.125.98Peru
PG180.150.252.66New Guinea
PH202.124.193.11Philippines
PK61.5.156.196Pakistan
PK124.109.47.66Pakistan
PK202.69.45.52Pakistan
RO89.120.75.51Romania
RO91.220.26.4Romania
RS178.149.182.28Serbia
RU79.134.4.241Russian Federation
RU81.24.85.98Russian Federation
RU194.24.241.235Russian Federation
SA94.77.199.148Saudi Arabia
TN41.230.10.190Tunisia
TR82.222.189.43Turkey
TW36.226.0.129Taiwan
TW61.228.0.95Taiwan
UA91.212.124.153Ukraine
UA178.151.68.210Ukraine
UA178.151.86.1Ukraine
UA195.138.82.74Ukraine
UNKNOWN190.52.205.5UNKNOWN
US24.178.82.50United States
US50.194.150.131United States
US69.18.205.139United States
US108.163.195.37United States
US173.184.189.237United States
US192.161.54.12United States
US192.211.58.108United States
US198.154.60.221United States
US206.217.198.12United States
US207.157.71.132United States
VE190.93.44.76Venezuela
ZW41.57.125.190Zimbabwe
ZW41.57.127.4Zimbabwe

List from greylisting:

Botnet Statistics [2013-05-21]

detection period: 2013-05-21 00:00-23:59 UTC
total number of suspected botnet IPs: 10808
number of botnet IPs notified to network operators: 10490
number of spam blocked: 146976
recipient count of spam blocked: 3280722

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-JS2185
2CHINANET-HB1720
3UNICOM-HA1583
4UNICOM-HB1061
5CHINANET-HE941
6HINET-NET539
7CRTC326
8CTTNET214
9UNICOM-HN188
10CHINANET-GD138

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China8935
2Taiwan546
3United States381
4Brazil95
5Russian Federation65
6India52
7Spain51
8Iran43
9United Kingdom43
10Mexico39

Tuesday, May 21, 2013

Suspected Bot List [2013-05-20]

detection period: 2013-05-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 439

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.111.92.120Arab Emirates
AE194.170.149.22Arab Emirates
AL82.114.70.102Albania
AM46.162.230.50Armenia
AO41.63.166.3Angola
AT37.235.52.59Austria
BG212.73.156.197Bulgaria
BR150.161.30.7Brazil
BY213.184.241.88Belarus
CA70.38.37.207Canada
CA198.50.166.144Canada
CI213.136.105.210Ivory Coast
CN27.106.170.0China
CR190.10.122.121Costa Rica
CR201.191.179.42Costa Rica
CZ77.104.244.69Czech Republic
DE78.31.71.139Germany
DE84.11.89.66Germany
GB77.246.20.2United Kingdom
GB83.136.126.153United Kingdom
GB193.164.207.16United Kingdom
GT186.151.253.188Guatemala
GT200.30.165.178Guatemala
ID202.6.225.84Indonesia
IL82.102.158.5Israel
IN117.240.239.120India
IN118.94.179.98India
IN122.180.71.10India
IN122.180.96.110India
IN122.183.99.146India
IN182.72.118.131India
IN182.73.111.162India
IN182.73.139.30India
IN202.63.105.226India
IQ95.159.105.2Iraq
IR89.165.109.165Iran
IR91.98.117.30Iran
IR94.183.138.253Iran
IR212.16.76.162Iran
IT91.214.62.59Italy
IT149.139.10.132Italy
JO87.236.232.231Jordan
JO109.107.132.172Jordan
KE41.89.96.20Kenya
KW62.150.12.46Kuwait
KW213.132.241.7Kuwait
LB212.36.193.188Lebanon
LB213.175.188.158Lebanon
MD95.65.86.236Republic Of Moldova
MV202.21.182.26Republic of Maldives
MX148.204.14.253Mexico
MX177.228.74.25Mexico
MX177.228.75.63Mexico
MX187.162.207.98Mexico
MX187.247.92.77Mexico
MX189.194.170.198Mexico
MX200.33.20.40Mexico
MX200.53.147.250Mexico
MX201.132.167.105Mexico
MX201.159.106.90Mexico
MX201.164.163.184Mexico
NG41.223.65.101Nigeria
NI186.1.10.154Nicaragua
NZ121.73.60.67New Zealand
PA190.33.184.107Panama
PE186.64.125.98Peru
PG180.150.252.66New Guinea
PH121.97.26.86Philippines
PH124.104.141.204Philippines
PH202.124.193.11Philippines
PK61.5.156.196Pakistan
PK111.68.104.133Pakistan
PK124.109.47.66Pakistan
PK202.69.45.52Pakistan
RO89.120.75.51Romania
RO91.220.26.4Romania
RO188.240.22.164Romania
RS178.149.182.28Serbia
RS194.106.178.161Serbia
RU194.24.241.235Russian Federation
SA94.77.199.148Saudi Arabia
SE46.246.28.47Sweden
SV190.150.101.13El Salvador
TJ217.11.177.26Tajikistan
TN41.224.168.104Tunisia
TN41.230.10.190Tunisia
TR82.222.189.43Turkey
TR188.132.237.61Turkey
TW36.226.0.43Taiwan
TW36.226.0.52Taiwan
TW36.226.0.139Taiwan
TW36.226.0.140Taiwan
TW36.226.0.148Taiwan
TW114.36.0.43Taiwan
TW220.137.0.224Taiwan
UA91.212.124.153Ukraine
UNKNOWN190.52.205.5UNKNOWN
US24.178.82.50United States
US50.194.150.131United States
US50.197.38.178United States
US67.20.29.147United States
US69.18.205.139United States
US173.184.189.237United States
US192.161.54.12United States
US192.211.58.108United States
US198.154.60.221United States
US205.208.148.104United States
US206.217.138.117United States
US206.217.198.12United States
US209.239.112.104United States

List from greylisting: