Custom Search

Monday, September 30, 2013

Suspected Bot List [2013-09-29]

detection period: 2013-09-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 200

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
CA174.142.186.121Canada
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.239.29.114India
IN117.240.239.120India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
IQ109.224.20.138Iraq
MX187.174.173.18Mexico
MX189.204.49.66Mexico
MX200.92.57.205Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PK115.186.59.70Pakistan
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TR82.222.189.43Turkey
US204.144.184.11United States

List from greylisting:

Botnet Statistics [2013-09-29]

detection period: 2013-09-29 00:00-23:59 UTC
total number of suspected botnet IPs: 2074
number of botnet IPs notified to network operators: 1874
number of spam blocked: 85554
recipient count of spam blocked: 3005339

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET880
2CHINANET-GD151
3CTTNET123
4UNICOM-GD119
5CHINANET-FJ36
6CRTC27
7UNICOM-LN26
8KORNET-KR16
9PE-TPSA-LACNIC12
10TELEKOM-BB-NET11

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan887
2China636
3Brazil43
4United States39
5South Korea37
6Russian Federation35
7India27
8Iran23
9Peru21
10Ukraine20

Sunday, September 29, 2013

Suspected Bot List [2013-09-28]

detection period: 2013-09-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 435

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.14.170.249Argentina
AR190.15.201.202Argentina
AR190.181.113.2Argentina
CA174.142.186.121Canada
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.240.239.120India
IN122.160.239.39India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
MX187.174.173.18Mexico
MX189.204.49.66Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PK115.186.59.70Pakistan
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TR82.222.189.43Turkey
US69.24.192.18United States

List from greylisting:

Botnet Statistics [2013-09-28]

detection period: 2013-09-28 00:00-23:59 UTC
total number of suspected botnet IPs: 2692
number of botnet IPs notified to network operators: 2257
number of spam blocked: 91236
recipient count of spam blocked: 3095974

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET890
2UNICOM-GD182
3CHINANET-GD103
4CTTNET94
5CHINANET-FJ38
6PE-TPSA-LACNIC31
7UNICOM-LN27
8CRTC24
9AR-CASA10-LACNIC24
10BSNLNET20

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan904
2China683
3United States81
4Argentina73
5Iran68
6Peru63
7India63
8Spain58
9Brazil57
10Russian Federation48

Saturday, September 28, 2013

Suspected Bot List [2013-09-27]

detection period: 2013-09-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 395

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
CA174.142.186.121Canada
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.239.29.114India
IN117.240.239.120India
IN122.160.239.39India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
LB213.175.188.158Lebanon
MX187.174.173.18Mexico
MX189.204.49.66Mexico
MX200.92.57.205Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
PK124.109.47.66Pakistan
RO89.120.75.51Romania
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TR82.222.189.43Turkey
UA178.213.110.115Ukraine
US69.24.192.18United States

List from greylisting:

Botnet Statistics [2013-09-27]

detection period: 2013-09-27 00:00-23:59 UTC
total number of suspected botnet IPs: 2574
number of botnet IPs notified to network operators: 2179
number of spam blocked: 93006
recipient count of spam blocked: 3143633

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET902
2UNICOM-GD178
3CHINANET-GD95
4CTTNET71
5UNICOM-LN27
6PE-TPSA-LACNIC27
7CRTC24
8PE-PETD2-LACNIC20
9AR-CASA10-LACNIC19
10CO-ACSA-LACNIC17

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan914
2China614
3United States122
4Peru74
5Argentina66
6India55
7Brazil55
8Colombia49
9Italy38
10United Kingdom38

Friday, September 27, 2013

Suspected Bot List [2013-09-26]

detection period: 2013-09-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 508

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.15.201.202Argentina
AR190.181.113.2Argentina
CA174.142.186.121Canada
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.239.29.114India
IN117.240.239.120India
IN122.160.239.39India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
KZ176.98.192.143Kazakhstan
LB213.175.188.158Lebanon
MX187.174.173.18Mexico
MX189.204.49.66Mexico
MX200.92.57.205Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
PK124.109.47.66Pakistan
RO89.120.75.51Romania
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TR82.222.189.43Turkey
UA178.213.110.115Ukraine
US69.24.192.18United States

List from greylisting:

Botnet Statistics [2013-09-26]

detection period: 2013-09-26 00:00-23:59 UTC
total number of suspected botnet IPs: 3175
number of botnet IPs notified to network operators: 2668
number of spam blocked: 106762
recipient count of spam blocked: 3684361

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET908
2UNICOM-GD194
3CHINANET-GD108
4CTTNET66
5CHINASKYNET35
6UNICOM-LN25
7PE-TPSA-LACNIC25
8CHINANET-FJ23
9BSNLNET21
10AR-CASA10-LACNIC21

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan926
2China723
3United States277
4United Kingdom103
5Brazil81
6India69
7Spain60
8Colombia56
9Peru54
10Argentina54

Thursday, September 26, 2013

Suspected Bot List [2013-09-25]

detection period: 2013-09-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 459

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.15.201.202Argentina
AR190.181.113.2Argentina
GB77.246.20.2United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.239.29.114India
IN117.240.239.120India
IN122.160.239.39India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
IR82.99.246.10Iran
IR91.98.117.30Iran
LB213.175.188.158Lebanon
MX187.174.173.18Mexico
MX189.204.49.66Mexico
MX200.92.57.205Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TR82.222.189.43Turkey
UA178.213.110.115Ukraine
US69.24.192.18United States

List from greylisting:

Botnet Statistics [2013-09-25]

detection period: 2013-09-25 00:00-23:59 UTC
total number of suspected botnet IPs: 2900
number of botnet IPs notified to network operators: 2442
number of spam blocked: 106767
recipient count of spam blocked: 3645525

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET858
2UNICOM-GD178
3CHINANET-GD117
4CTTNET56
5ZTWL33
6CHINANET-FJ32
7UNICOM-LN25
8AR-CASA10-LACNIC24
9CHINANET-JS19
10PE-TPSA-LACNIC15

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan872
2China700
3United States239
4United Kingdom87
5Brazil81
6Argentina64
7Iran54
8India51
9Italy50
10Spain46

Wednesday, September 25, 2013

Suspected Bot List [2013-09-24]

detection period: 2013-09-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 469

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
GB77.246.20.2United Kingdom
GB109.104.104.122United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.240.239.120India
IN122.160.239.39India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
IR82.99.246.10Iran
IR91.98.117.30Iran
LB213.175.188.158Lebanon
MX187.174.173.18Mexico
MX189.204.49.66Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PH122.54.171.253Philippines
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
TR82.222.189.43Turkey
UA178.213.110.115Ukraine
US69.24.192.18United States

List from greylisting:

Botnet Statistics [2013-09-24]

detection period: 2013-09-24 00:00-23:59 UTC
total number of suspected botnet IPs: 2891
number of botnet IPs notified to network operators: 2422
number of spam blocked: 129760
recipient count of spam blocked: 4631934

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET839
2UNICOM-GD184
3CTTNET117
4CHINANET-GD105
5CHINANET-HE49
6KORNET-KR38
7CHINANET-FJ35
8UNICOM-LN24
9CRTC24
10PE-PETD2-LACNIC22

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan859
2China745
3United States196
4Brazil70
5India66
6Peru58
7South Korea58
8Iran55
9United Kingdom54
10Argentina52

Tuesday, September 24, 2013

Suspected Bot List [2013-09-23]

detection period: 2013-09-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 415

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.15.201.202Argentina
AR190.181.113.2Argentina
GB77.246.20.2United Kingdom
GB109.104.104.122United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.240.239.120India
IN122.160.239.39India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
IR82.99.246.10Iran
LB213.175.188.158Lebanon
MX187.174.173.18Mexico
MX189.204.49.66Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PH122.54.171.253Philippines
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TR82.222.189.43Turkey
UA178.213.110.115Ukraine
US69.24.192.18United States

List from greylisting:

Botnet Statistics [2013-09-23]

detection period: 2013-09-23 00:00-23:59 UTC
total number of suspected botnet IPs: 2732
number of botnet IPs notified to network operators: 2317
number of spam blocked: 87186
recipient count of spam blocked: 2988543

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET871
2UNICOM-GD148
3CHINANET-GD104
4CTTNET99
5CHINANET-HE66
6CHINANET-FJ40
7UNICOM-LN24
8CRTC24
9AR-CASA10-LACNIC20
10PE-TPSA-LACNIC15

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan885
2China686
3United States191
4Italy59
5United Kingdom58
6Brazil56
7Argentina56
8Spain54
9India47
10Peru43

Monday, September 23, 2013

Suspected Bot List [2013-09-22]

detection period: 2013-09-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 262

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.15.201.202Argentina
AR190.181.113.2Argentina
GB77.246.20.2United Kingdom
GB109.104.104.122United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.240.239.120India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
IR82.99.246.10Iran
LB213.175.188.158Lebanon
MX187.174.173.18Mexico
MX189.204.49.66Mexico
MX200.92.57.205Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PH122.54.171.253Philippines
PK111.68.104.132Pakistan
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TR82.222.189.43Turkey

List from greylisting:

Botnet Statistics [2013-09-22]

detection period: 2013-09-22 00:00-23:59 UTC
total number of suspected botnet IPs: 2324
number of botnet IPs notified to network operators: 2062
number of spam blocked: 81131
recipient count of spam blocked: 2711069

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET864
2UNICOM-GD165
3CTTNET141
4CHINANET-GD84
5CHINANET-HE68
6CHINANET-FJ45
7CRTC28
8UNICOM-LN22
9AR-CASA10-LACNIC19
10CHINANET-JS17

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan872
2China754
3United States59
4Argentina50
5Iran47
6Brazil45
7Spain33
8Russian Federation30
9Peru28
10Italy24

Sunday, September 22, 2013

Suspected Bot List [2013-09-21]

detection period: 2013-09-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 290

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.181.113.2Argentina
GB77.246.20.2United Kingdom
GB109.104.104.122United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.240.239.120India
IN122.160.239.39India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
IR82.99.246.10Iran
IR91.98.117.30Iran
LB213.175.188.158Lebanon
MX187.174.173.18Mexico
MX189.204.49.66Mexico
MX200.92.57.205Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PH122.54.171.253Philippines
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
RO89.120.75.51Romania
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TR82.222.189.43Turkey
US69.24.192.18United States

List from greylisting:

Botnet Statistics [2013-09-21]

detection period: 2013-09-21 00:00-23:59 UTC
total number of suspected botnet IPs: 2181
number of botnet IPs notified to network operators: 1891
number of spam blocked: 83653
recipient count of spam blocked: 2839389

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET843
2UNICOM-GD122
3CHINANET-GD105
4CTTNET71
5CHINANET-FJ37
6CHINANET-HE31
7UNICOM-LN26
8AR-CASA10-LACNIC18
9KORNET-KR15
10AR-TEAR7-LACNIC15

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan850
2China561
3United States67
4Iran54
5Brazil50
6Argentina48
7Russian Federation32
8South Korea32
9Colombia32
10Peru26

Saturday, September 21, 2013

Suspected Bots' IP List for September 2013

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here (as shown below) 10 days after its respective botnet statistics gets published.

You are free to use them to create more effective defenses, discover latest trends in cyber attacks, etc.

Suspected Bots IP [2013-09-01]
Suspected Bots IP [2013-09-02]
Suspected Bots IP [2013-09-03]
Suspected Bots IP [2013-09-04]
Suspected Bots IP [2013-09-05]
Suspected Bots IP [2013-09-06]
Suspected Bots IP [2013-09-07]
Suspected Bots IP [2013-09-08]
Suspected Bots IP [2013-09-09]
Suspected Bots IP [2013-09-10]
Suspected Bots IP [2013-09-11]
Suspected Bots IP [2013-09-12]
Suspected Bots IP [2013-09-13]
Suspected Bots IP [2013-09-14]
Suspected Bots IP [2013-09-15]
Suspected Bots IP [2013-09-16]
Suspected Bots IP [2013-09-17]
Suspected Bots IP [2013-09-18]
Suspected Bots IP [2013-09-19]
Suspected Bots IP [2013-09-20]
Suspected Bots IP [2013-09-21]
Suspected Bots IP [2013-09-22]
Suspected Bots IP [2013-09-23]
Suspected Bots IP [2013-09-24]
Suspected Bots IP [2013-09-25]
Suspected Bots IP [2013-09-26]
Suspected Bots IP [2013-09-27]
Suspected Bots IP [2013-09-28]
Suspected Bots IP [2013-09-29]
Suspected Bots IP [2013-09-30]

Suspected Bot List [2013-09-20]

detection period: 2013-09-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 260

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
GB77.246.20.2United Kingdom
GB109.104.104.122United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.218.129.170India
IN117.239.29.114India
IN117.240.239.120India
IN122.160.239.39India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
IR82.99.246.10Iran
IR91.98.117.30Iran
LB213.175.188.158Lebanon
MX187.174.173.18Mexico
MX189.204.49.66Mexico
MX200.92.57.205Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
RO89.120.75.51Romania
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
US69.24.192.18United States

List from greylisting:

Botnet Statistics [2013-09-20]

detection period: 2013-09-20 00:00-23:59 UTC
total number of suspected botnet IPs: 2334
number of botnet IPs notified to network operators: 2074
number of spam blocked: 83715
recipient count of spam blocked: 2766319

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET850
2UNICOM-GD184
3CTTNET113
4CHINANET-GD101
5CHINASKYNET61
6CHINANET-FJ42
7AR-CASA10-LACNIC22
8UNICOM-LN21
9CRTC19
10PE-TPSA-LACNIC18

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan858
2China681
3United States86
4Brazil52
5Argentina52
6Peru42
7Colombia34
8Mexico32
9Italy30
10Russian Federation29

Friday, September 20, 2013

Suspected Bot List [2013-09-19]

detection period: 2013-09-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 339

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
GB77.246.20.2United Kingdom
GB109.104.104.122United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.240.239.120India
IN122.160.239.39India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
IR82.99.246.10Iran
MX187.174.173.18Mexico
MX189.204.49.66Mexico
PE200.37.197.148Peru
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
RO89.120.75.51Romania
SA94.77.199.148Saudi Arabia
SK93.184.71.66Slovakia
US69.24.192.18United States

List from greylisting:

Botnet Statistics [2013-09-19]

detection period: 2013-09-19 00:00-23:59 UTC
total number of suspected botnet IPs: 2606
number of botnet IPs notified to network operators: 2267
number of spam blocked: 87180
recipient count of spam blocked: 2937507

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET861
2UNICOM-GD164
3CHINANET-GD105
4CHINASKYNET89
5CTTNET78
6CHINANET-FJ43
7ZTWL27
8UNICOM-LN19
9AR-CASA10-LACNIC18
10PE-TPSA-LACNIC17

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan868
2China679
3United States160
4Spain62
5Brazil55
6United Kingdom50
7Italy48
8India48
9Colombia44
10Argentina43

Thursday, September 19, 2013

Suspected Bot List [2013-09-18]

detection period: 2013-09-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 430

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.181.113.2Argentina
CA174.142.186.121Canada
GB77.246.20.2United Kingdom
GB109.104.104.122United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.239.29.114India
IN117.240.239.120India
IN122.160.239.39India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
IR82.99.246.10Iran
IR91.98.117.30Iran
MX187.174.173.18Mexico
MX189.204.49.66Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
RO89.120.75.51Romania
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TR82.222.189.43Turkey

List from greylisting:

Botnet Statistics [2013-09-18]

detection period: 2013-09-18 00:00-23:59 UTC
total number of suspected botnet IPs: 2901
number of botnet IPs notified to network operators: 2471
number of spam blocked: 94578
recipient count of spam blocked: 3217547

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET814
2UNICOM-GD185
3CHINASKYNET141
4CHINANET-GD124
5CTTNET69
6ZTWL40
7CHINANET-FJ25
8CBC-CM-423
9UNICOM-LN22
10CCCH3-417

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan829
2China779
3United States297
4Brazil72
5Argentina55
6United Kingdom53
7Italy51
8Spain50
9Peru46
10Iran44

Wednesday, September 18, 2013

Suspected Bot List [2013-09-17]

detection period: 2013-09-17 00:00-23:59 UTC
number of suspected bots' IPs listed here: 317

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.181.113.2Argentina
AR200.55.57.214Argentina
BO200.87.98.235Bolivia
CA174.142.186.121Canada
CN150.255.225.129China
GB77.246.20.2United Kingdom
GB109.104.104.122United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN111.93.6.198India
IN117.239.29.114India
IN117.240.239.120India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
IR82.99.246.10Iran
IR91.98.117.30Iran
LB213.175.188.158Lebanon
MX187.174.173.18Mexico
MX189.204.49.66Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PK115.186.59.70Pakistan
RO89.120.75.51Romania
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TN196.203.198.130Tunisia
TR82.222.189.43Turkey
TW202.154.192.28Taiwan
UA178.213.110.115Ukraine
US98.126.249.106United States

List from greylisting:

Botnet Statistics [2013-09-17]

detection period: 2013-09-17 00:00-23:59 UTC
total number of suspected botnet IPs: 2927
number of botnet IPs notified to network operators: 2610
number of spam blocked: 95880
recipient count of spam blocked: 3236627

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET812
2UNICOM-GD172
3CHINANET-GD137
4CMNET84
5CHINASKYNET83
6CTTNET81
7CHINANET-FJ63
8CRTC36
9UNICOM-LN30
10ZTWL26

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1099
2Taiwan826
3United States228
4United Kingdom63
5Brazil56
6Italy39
7Argentina39
8Spain38
9India37
10Russian Federation30

Tuesday, September 17, 2013

Suspected Bot List [2013-09-16]

detection period: 2013-09-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 375

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.14.170.249Argentina
AR190.181.113.2Argentina
AR200.55.57.214Argentina
BO200.87.98.235Bolivia
CO190.7.128.44Colombia
GB109.104.104.122United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN111.93.6.198India
IN117.240.239.120India
IN122.183.99.146India
IN202.63.105.226India
IR82.99.246.10Iran
IR89.165.113.118Iran
IR91.98.117.30Iran
IS79.134.233.195Iceland
KZ109.229.189.175Kazakhstan
LB213.175.188.158Lebanon
MO60.246.207.126Macau
MX187.174.173.18Mexico
MX200.92.57.205Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PE200.110.35.150Peru
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
RO89.120.75.51Romania
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TN196.203.198.130Tunisia
TR82.222.189.43Turkey
TW202.154.192.28Taiwan
UA178.213.110.115Ukraine
US69.24.192.18United States
US98.126.249.106United States

List from greylisting:

Botnet Statistics [2013-09-16]

detection period: 2013-09-16 00:00-23:59 UTC
total number of suspected botnet IPs: 3351
number of botnet IPs notified to network operators: 2980
number of spam blocked: 108893
recipient count of spam blocked: 3704628

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET831
2CHINANET-GD170
3UNICOM-GD165
4CMNET115
5CHINANET-FJ66
6CRTC54
7CTTNET52
8UNICOM-LN42
9UNICOM-HE39
10CHINANET-JS38

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1269
2Taiwan849
3United States232
4United Kingdom67
5Brazil66
6Spain61
7Iran52
8Argentina52
9Italy51
10Russian Federation46

Monday, September 16, 2013

Suspected Bot List [2013-09-15]

detection period: 2013-09-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 239

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
CO190.7.128.44Colombia
GB77.246.20.2United Kingdom
GB109.104.104.122United Kingdom
GB193.164.207.16United Kingdom
HN190.107.140.77Honduras
IN117.240.239.120India
IN122.183.99.146India
IN202.63.105.226India
IR82.99.246.10Iran
IR89.165.113.118Iran
KZ109.229.189.175Kazakhstan
MX187.174.173.18Mexico
MX200.92.57.205Mexico
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PE200.110.35.150Peru
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
RO89.120.75.51Romania
RU87.103.170.65Russian Federation
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TR82.222.189.43Turkey
TW202.154.192.28Taiwan
UA46.164.139.27Ukraine
US69.24.192.18United States
US98.126.249.106United States

List from greylisting:

Botnet Statistics [2013-09-15]

detection period: 2013-09-15 00:00-23:59 UTC
total number of suspected botnet IPs: 2676
number of botnet IPs notified to network operators: 2439
number of spam blocked: 63135
recipient count of spam blocked: 1966077

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET805
2CHINANET-GD211
3UNICOM-GD177
4CMNET135
5CTTNET57
6CRTC57
7CHINANET-FJ57
8UNICOM-LN33
9CHINANET-JS33
10UNICOM-SD26

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1158
2Taiwan819
3United States71
4Brazil46
5Argentina44
6Spain38
7Russian Federation33
8Peru33
9Iran33
10Mexico25

Sunday, September 15, 2013

Suspected Bot List [2013-09-14]

detection period: 2013-09-14 00:00-23:59 UTC
number of suspected bots' IPs listed here: 134

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
CO200.73.31.157Colombia
IN111.93.9.67India
IQ86.111.144.194Iraq
IR93.126.2.130Iran
IT150.145.38.60Italy
MX201.116.83.230Mexico
MX201.151.142.39Mexico
PH119.92.60.115Philippines
TR193.255.143.62Turkey
US69.64.52.154United States
ZW41.220.28.138Zimbabwe

List from greylisting:

Botnet Statistics [2013-09-14]

detection period: 2013-09-14 00:00-23:59 UTC
total number of suspected botnet IPs: 2109
number of botnet IPs notified to network operators: 1977
number of spam blocked: 44243
recipient count of spam blocked: 1102959

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET822
2CHINANET-GD221
3UNICOM-GD197
4CHINANET-FJ58
5CTTNET39
6CMNET39
7ZTWL22
8CHINANET-JS15
9CRTC11
10CHINANET-JX10

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan826
2China763
3United States92
4Russian Federation33
5Argentina30
6Brazil28
7Spain25
8Colombia19
9Peru17
10United Kingdom17

Saturday, September 14, 2013

Suspected Bot List [2013-09-13]

detection period: 2013-09-13 00:00-23:59 UTC
number of suspected bots' IPs listed here: 401

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
GB77.246.20.2United Kingdom
GB109.104.104.122United Kingdom
GB193.164.207.16United Kingdom
IL85.64.57.22Israel
IN59.90.134.181India
IN59.95.165.58India
IN59.97.149.93India
IN117.240.239.120India
IN122.183.99.146India
IN182.72.149.50India
IN202.63.105.226India
IR89.165.113.118Iran
IR91.98.117.30Iran
LU83.99.46.118Luxembourg
MO60.246.144.199Macau
MO202.175.66.29Macau
MX177.227.90.49Mexico
MX187.174.173.18Mexico
PE190.12.65.146Peru
PE190.81.5.134Peru
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.179.92Peru
PE200.37.197.148Peru
PK115.186.59.70Pakistan
RO89.120.75.51Romania
RU87.242.77.115Russian Federation
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
TR82.222.189.43Turkey
TW202.154.192.28Taiwan
UA178.213.110.115Ukraine
US69.24.192.18United States
US98.137.201.177United States
US100.44.250.4United States

List from greylisting:

Botnet Statistics [2013-09-13]

detection period: 2013-09-13 00:00-23:59 UTC
total number of suspected botnet IPs: 3386
number of botnet IPs notified to network operators: 2986
number of spam blocked: 68855
recipient count of spam blocked: 2090371

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET891
2CHINANET-GD239
3UNICOM-GD181
4CMNET139
5CTTNET70
6CRTC59
7CHINANET-FJ41
8BSNLNET30
9UNICOM-LN28
10CBC-CM-427

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1177
2Taiwan915
3United States352
4United Kingdom88
5India78
6Brazil68
7South Korea48
8Russian Federation38
9Italy37
10Argentina35

Friday, September 13, 2013

Suspected Bot List [2013-09-12]

detection period: 2013-09-12 00:00-23:59 UTC
number of suspected bots' IPs listed here: 371

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BO190.129.58.250Bolivia
BO190.129.203.74Bolivia
CA64.15.152.137Canada
CO200.73.31.157Colombia
GB109.104.104.122United Kingdom
GB193.164.207.16United Kingdom
IL85.64.57.22Israel
IN117.240.239.120India
IN117.254.234.54India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
IN202.134.156.39India
IR82.99.246.10Iran
IR89.165.113.118Iran
IR91.98.117.30Iran
IR212.33.205.180Iran
IT88.41.204.171Italy
MX187.174.173.18Mexico
PE190.12.65.146Peru
PE190.81.5.134Peru
PE190.81.193.8Peru
PE190.116.50.12Peru
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.179.92Peru
PE200.37.197.148Peru
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
RO89.120.75.51Romania
RU91.204.228.59Russian Federation
RU91.211.209.137Russian Federation
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
TH118.175.28.3Thailand
TR82.222.189.43Turkey
TW202.154.192.28Taiwan
UA178.213.110.115Ukraine
US69.24.192.18United States
US98.126.249.106United States
US98.137.201.177United States
US173.254.233.237United States

List from greylisting:

Botnet Statistics [2013-09-12]

detection period: 2013-09-12 00:00-23:59 UTC
total number of suspected botnet IPs: 2846
number of botnet IPs notified to network operators: 2477
number of spam blocked: 72133
recipient count of spam blocked: 2369457

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET863
2CHINANET-GD219
3CTTNET75
4CMNET52
5UNICOM-GD46
6CHINANET-FJ39
7CHINANET-GX28
8PE-TPSA-LACNIC24
9UNICOM-LN23
10CHINANET-JX17

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan874
2China718
3United States211
4Brazil66
5United Kingdom63
6India61
7Peru53
8Spain50
9Argentina47
10Italy46

Thursday, September 12, 2013

Suspected Bot List [2013-09-11]

detection period: 2013-09-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 480

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BG95.111.38.156Bulgaria
BO190.129.58.250Bolivia
BO200.87.98.235Bolivia
CA64.15.152.137Canada
CO190.90.2.30Colombia
CU200.55.159.122Cuba
ES213.97.71.246Spain
GB109.104.104.122United Kingdom
GB193.164.207.16United Kingdom
ID27.131.2.210Indonesia
IL85.64.57.22Israel
IN27.5.183.11India
IN27.6.19.140India
IN59.90.81.251India
IN59.92.3.10India
IN59.93.55.59India
IN59.93.212.130India
IN59.94.222.27India
IN111.93.6.198India
IN117.195.95.193India
IN117.240.239.120India
IN117.254.10.18India
IN117.254.234.54India
IN122.183.99.146India
IN182.73.111.162India
IN202.63.105.226India
IN202.134.156.242India
IR82.99.246.10Iran
IR91.98.89.206Iran
IR91.98.117.30Iran
IT88.41.204.171Italy
MX187.174.173.18Mexico
PE190.81.193.8Peru
PE190.81.196.147Peru
PE190.116.50.12Peru
PE190.187.168.186Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
RO89.120.75.51Romania
RS88.150.226.132Serbia
RS91.232.107.59Serbia
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
TN196.203.198.130Tunisia
TR82.222.189.43Turkey
TW202.154.192.28Taiwan
US72.34.181.170United States
US98.126.249.106United States
US98.137.201.177United States

List from greylisting:

Botnet Statistics [2013-09-11]

detection period: 2013-09-11 00:00-23:59 UTC
total number of suspected botnet IPs: 3549
number of botnet IPs notified to network operators: 3069
number of spam blocked: 71051
recipient count of spam blocked: 2164301

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET886
2CHINANET-GD235
3UNICOM-GD208
4CTTNET134
5CMNET40
6CHINANET-FJ37
7CBC-CM-429
8ZTWL27
9CHINANET-JX22
10UNICOM-LN21

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China964
2Taiwan904
3United States398
4United Kingdom111
5India94
6Brazil61
7Italy60
8Argentina55
9Peru54
10Russian Federation46

Wednesday, September 11, 2013

Suspected Bot List [2013-09-10]

detection period: 2013-09-10 00:00-23:59 UTC
number of suspected bots' IPs listed here: 285

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BO200.87.98.235Bolivia
CA174.142.75.243Canada
GB109.104.104.122United Kingdom
GB193.164.207.16United Kingdom
GQ41.222.115.225Equatorial Guinea
ID27.131.2.210Indonesia
IN14.96.139.16India
IN14.96.182.174India
IN14.98.96.85India
IN14.98.213.43India
IN27.0.55.135India
IN59.89.9.30India
IN59.93.201.186India
IN59.94.210.39India
IN59.96.243.71India
IN116.73.211.147India
IN117.199.151.231India
IN117.240.239.120India
IN117.242.81.137India
IN122.183.99.146India
IN202.63.105.226India
IN202.78.235.226India
IN202.134.157.28India
IN210.212.209.150India
IR91.98.89.206Iran
IR91.98.117.30Iran
IR212.33.205.180Iran
IT88.41.204.171Italy
KZ109.229.189.175Kazakhstan
LB212.36.193.187Lebanon
MX187.174.173.18Mexico
MX200.92.57.205Mexico
PE190.81.193.8Peru
PE190.81.196.147Peru
PE190.187.168.186Peru
PE200.37.197.148Peru
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
RO89.120.75.51Romania
RU88.151.89.108Russian Federation
RU91.149.98.50Russian Federation
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
TN196.203.198.130Tunisia
TR82.222.189.43Turkey
TW202.154.192.28Taiwan
UA178.213.110.115Ukraine
US69.24.192.18United States
US72.34.181.170United States
US98.137.201.177United States

List from greylisting:

Botnet Statistics [2013-09-10]

detection period: 2013-09-10 00:00-23:59 UTC
total number of suspected botnet IPs: 6439
number of botnet IPs notified to network operators: 6155
number of spam blocked: 106362
recipient count of spam blocked: 3552742

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-JS3025
2HINET-NET892
3CHINANET-GD336
4CTTNET202
5UNICOM-GD176
6CRTC147
7CMNET64
8CHINANET-FJ49
9CHINANET-GX45
10UNICOM-LN24

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China4288
2Taiwan907
3United States281
4United Kingdom79
5India61
6Brazil54
7Russian Federation49
8Spain45
9Germany40
10Argentina39

Tuesday, September 10, 2013

Suspected Bot List [2013-09-09]

detection period: 2013-09-09 00:00-23:59 UTC
number of suspected bots' IPs listed here: 154

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
GB193.164.207.16United Kingdom
GQ41.222.115.225Equatorial Guinea
HN190.107.140.77Honduras
IN117.240.239.120India
IN122.183.99.146India
IN202.63.105.226India
IN210.212.224.197India
IR89.165.113.118Iran
IR91.98.117.30Iran
IT88.41.204.171Italy
MX177.227.90.49Mexico
MX187.174.173.18Mexico
MX200.92.57.205Mexico
PE190.187.168.186Peru
PE190.232.218.6Peru
PE190.235.148.90Peru
PE200.31.105.172Peru
PE200.37.197.148Peru
PK111.68.104.132Pakistan
PK115.186.59.70Pakistan
RO89.120.75.51Romania
RS89.216.113.127Serbia
SA94.77.199.148Saudi Arabia
SK62.197.209.93Slovakia
SK93.184.71.66Slovakia
TR82.222.189.43Turkey
TR193.255.143.62Turkey
UA178.213.110.115Ukraine
US69.24.192.18United States
US98.137.201.177United States
US174.140.163.107United States
ZW41.220.28.138Zimbabwe

List from greylisting:

Botnet Statistics [2013-09-09]

detection period: 2013-09-09 00:00-23:59 UTC
total number of suspected botnet IPs: 5903
number of botnet IPs notified to network operators: 5749
number of spam blocked: 120672
recipient count of spam blocked: 3984474

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-JS2916
2HINET-NET898
3CHINANET-GD308
4CRTC230
5UNICOM-GD210
6CTTNET183
7CMNET64
8CHINANET-FJ46
9CHINASKYNET35
10ZTWL27

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China4250
2Taiwan907
3United States241
4Brazil47
5United Kingdom46
6Russian Federation33
7India25
8Iran20
9Canada20
10Peru15