Custom Search

Sunday, August 31, 2014

Suspected Bot List [2014-08-30]

detection period: 2014-08-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 579

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN27.5.182.53India
IN202.62.67.254India
IN203.90.114.228India
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PK221.120.222.69Pakistan
RU95.188.112.11Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
US50.201.42.106United States
UZ89.236.219.106Uzbekistan

List from greylisting:

Botnet Statistics [2014-08-30]

detection period: 2014-08-30 00:00-23:59 UTC
total number of suspected botnet IPs: 4231
number of botnet IPs notified to network operators: 3652
number of spam blocked: 107152
recipient count of spam blocked: 3313259

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1169
2VNPT-VNNIC-VN408
3CRTC146
4CHINANET-GD130
5VIETEL-VNNIC-VN126
6Wotone124
7KORNET-KR98
8FPT-VN87
9PE-TPSA-LACNIC64
10AR-TEAR7-LACNIC64

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1198
2Viet Nam746
3China619
4South Korea223
5Peru136
6Argentina132
7India122
8Brazil98
9Colombia91
10Mexico52

Saturday, August 30, 2014

Suspected Bot List [2014-08-29]

detection period: 2014-08-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 435

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN117.245.95.252India
IN202.62.67.254India
IN203.90.114.228India
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
RU95.188.112.11Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
US50.201.42.106United States
UZ89.236.219.106Uzbekistan

List from greylisting:

Botnet Statistics [2014-08-29]

detection period: 2014-08-29 00:00-23:59 UTC
total number of suspected botnet IPs: 2955
number of botnet IPs notified to network operators: 2520
number of spam blocked: 105542
recipient count of spam blocked: 3237381

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1107
2CRTC145
3Wotone122
4CHINANET-GD74
5VNPT-VNNIC-VN56
6PE-TPSA-LACNIC52
7AR-TEAR7-LACNIC40
8KORNET-KR30
9CHINANET-HB30
10PE-PETD2-LACNIC23

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1125
2China535
3Viet Nam112
4Peru106
5Argentina92
6Brazil78
7South Korea74
8Colombia68
9United States51
10Mexico48

Friday, August 29, 2014

Suspected Bot List [2014-08-28]

detection period: 2014-08-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 206

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
EG62.117.58.109Egypt
IN27.5.182.53India
IN117.245.95.252India
IN202.62.67.254India
IN203.90.114.228India
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
PE200.121.22.172Peru
PH58.69.100.234Philippines
PK221.120.222.69Pakistan
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-08-28]

detection period: 2014-08-28 00:00-23:59 UTC
total number of suspected botnet IPs: 2593
number of botnet IPs notified to network operators: 2387
number of spam blocked: 103265
recipient count of spam blocked: 3160085

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1092
2CRTC155
3Wotone134
4CHINANET-GD76
5VNPT-VNNIC-VN69
6KORNET-KR43
7CHINANET-HB37
8WASU-BB31
9WASU29
10UNICOM-BJ19

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1109
2China640
3Viet Nam120
4South Korea73
5India52
6Russian Federation49
7United States47
8Peru40
9Indonesia37
10Argentina33

Thursday, August 28, 2014

Suspected Bot List [2014-08-27]

detection period: 2014-08-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 132

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
EG62.117.58.109Egypt
IN117.245.95.252India
IN125.21.245.146India
IN202.62.67.254India
IN203.90.114.228India
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LV85.9.201.199Latvia
PH58.69.100.234Philippines
PK221.120.222.69Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
US50.201.42.106United States
US67.229.128.124United States

List from greylisting:

Botnet Statistics [2014-08-27]

detection period: 2014-08-27 00:00-23:59 UTC
total number of suspected botnet IPs: 2354
number of botnet IPs notified to network operators: 2222
number of spam blocked: 107421
recipient count of spam blocked: 3214745

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1098
2CRTC148
3Wotone119
4WASU117
5WASU-BB52
6CHINANET-GD44
7CHINANET-HB32
8UNICOM-FJ23
9VNPT-VNNIC-VN18
10CHINANET-AH15

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1109
2China708
3United States59
4India35
5Viet Nam30
6Russian Federation30
7Indonesia26
8Brazil25
9South Korea24
10Argentina21

Wednesday, August 27, 2014

Suspected Bot List [2014-08-26]

detection period: 2014-08-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 86

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN27.5.182.53India
IN117.211.42.82India
IN117.245.95.252India
IN125.21.245.146India
IN202.62.67.254India
IN203.90.114.228India
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
PH58.69.100.234Philippines
PH124.107.165.60Philippines
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
US50.201.42.106United States
US67.229.128.124United States

List from greylisting:

Botnet Statistics [2014-08-26]

detection period: 2014-08-26 00:00-23:59 UTC
total number of suspected botnet IPs: 2053
number of botnet IPs notified to network operators: 1967
number of spam blocked: 98526
recipient count of spam blocked: 2940256

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1034
2CRTC121
3Wotone117
4CHINANET-GD70
5WASU50
6WASU-BB42
7CHINANET-HB17
8UNICOM-HA14
9UNICOM-BJ13
10CHINANET-JX13

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1039
2China589
3United States55
4Russian Federation42
5Indonesia29
6Brazil26
7Turkey16
8India16
9Viet Nam15
10Italy12

Tuesday, August 26, 2014

Suspected Bot List [2014-08-25]

detection period: 2014-08-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 69

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN27.5.182.53India
IN117.211.42.82India
IN117.218.50.134India
IN202.62.67.254India
IN203.90.114.228India
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
PH58.69.100.234Philippines
PH124.107.165.60Philippines
PK103.4.92.88Pakistan
PK125.209.116.29Pakistan
PK221.120.222.69Pakistan
RU95.188.112.11Russian Federation
SA94.77.199.148Saudi Arabia
SE80.78.31.131Sweden
TR88.247.164.136Turkey
US50.201.42.106United States
US67.229.128.124United States
US174.140.166.38United States

List from greylisting:

Botnet Statistics [2014-08-25]

detection period: 2014-08-25 00:00-23:59 UTC
total number of suspected botnet IPs: 1951
number of botnet IPs notified to network operators: 1882
number of spam blocked: 69445
recipient count of spam blocked: 2390179

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET912
2CRTC146
3Wotone92
4WASU71
5CHINANET-GD52
6CMNET46
7WASU-BB38
8CHINANET-HB29
9UNICOM-FJ22
10UNICOM-BJ17

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan915
2China651
3United States49
4Russian Federation41
5Indonesia25
6Brazil24
7India21
8Viet Nam16
9Hong Kong14
10Italy13

Monday, August 25, 2014

Suspected Bot List [2014-08-24]

detection period: 2014-08-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 45

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN202.62.67.254India
IN203.90.114.228India
IT31.199.192.20Italy
IT95.227.105.203Italy
PH58.69.100.234Philippines
PH124.107.165.60Philippines
PK103.4.92.88Pakistan
PK125.209.116.29Pakistan
PK221.120.222.69Pakistan
RU95.188.112.11Russian Federation
SA94.77.199.148Saudi Arabia
SE80.78.31.131Sweden
TR88.247.164.136Turkey
US50.201.42.106United States
US67.229.128.124United States

List from greylisting:

Botnet Statistics [2014-08-24]

detection period: 2014-08-24 00:00-23:59 UTC
total number of suspected botnet IPs: 1780
number of botnet IPs notified to network operators: 1735
number of spam blocked: 116625
recipient count of spam blocked: 3012084

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET996
2CRTC129
3CHINANET-GD85
4CMNET69
5Wotone67
6WASU22
7CHINANET-HB22
8WASU-BB16
9UNICOM-BJ13
10HICHINA9

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan999
2China508
3Russian Federation43
4United States33
5India19
6Indonesia19
7Brazil12
8Hong Kong10
9Iran8
10Kazakhstan7

Sunday, August 24, 2014

Suspected Bot List [2014-08-23]

detection period: 2014-08-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 113

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN117.218.50.134India
IN202.62.67.254India
IN203.90.114.228India
IT31.199.192.20Italy
IT95.227.105.203Italy
PH58.69.100.234Philippines
PH124.107.165.60Philippines
PK103.4.92.88Pakistan
PK221.120.222.69Pakistan
RU95.188.112.11Russian Federation
SA94.77.199.148Saudi Arabia
SE80.78.31.131Sweden
US50.201.42.106United States
US67.229.128.124United States

List from greylisting:

Botnet Statistics [2014-08-23]

detection period: 2014-08-23 00:00-23:59 UTC
total number of suspected botnet IPs: 2304
number of botnet IPs notified to network operators: 2191
number of spam blocked: 120130
recipient count of spam blocked: 3199025

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1214
2CHINANET-GD161
3CRTC140
4Wotone67
5CMNET61
6CHINANET-HB29
7UNICOM-GD18
8UNICOM-BJ15
9BHARTI-IN11
10HICHINA10

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1219
2China593
3Russian Federation67
4India49
5United States42
6Brazil24
7Indonesia23
8Argentina22
9Italy16
10Colombia14

Saturday, August 23, 2014

Suspected Bot List [2014-08-22]

detection period: 2014-08-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 110

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR200.117.247.99Argentina
CL190.196.146.42Chile
ES80.24.10.99Spain
IN27.5.182.53India
IN117.218.21.96India
IN117.218.50.134India
IN117.245.95.252India
IN182.71.167.62India
IN182.72.199.118India
IN202.62.67.250India
IN202.62.67.254India
IN203.90.114.228India
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
PH58.69.100.234Philippines
PH124.107.165.60Philippines
PK103.4.92.88Pakistan
PK221.120.222.69Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SE80.78.31.131Sweden
US50.193.161.9United States
US50.201.42.106United States
US67.229.128.124United States
US68.119.62.62United States
US174.139.94.82United States
US174.139.94.84United States
ZA196.28.31.245South Africa

List from greylisting:

Botnet Statistics [2014-08-22]

detection period: 2014-08-22 00:00-23:59 UTC
total number of suspected botnet IPs: 2341
number of botnet IPs notified to network operators: 2231
number of spam blocked: 90189
recipient count of spam blocked: 2979203

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1191
2CRTC146
3Wotone110
4CHINANET-GD105
5WASU48
6WASU-BB30
7CHINANET-HB25
8CMNET17
9BSNLNET14
10UNICOM-HA13

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1196
2China626
3United States78
4India50
5Russian Federation35
6Brazil29
7Indonesia27
8South Korea19
9Hong Kong18
10Viet Nam17

Wednesday, August 20, 2014

Suspected Bot List [2014-08-19]

detection period: 2014-08-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 151

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
HN190.107.140.77Honduras
IN117.245.95.252India
IN202.62.67.250India
IN203.90.114.228India
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
MX201.132.203.42Mexico
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PK221.120.222.69Pakistan
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
US50.201.42.106United States
US67.229.128.124United States
US68.189.162.167United States
US174.139.94.82United States
US174.139.94.83United States

List from greylisting:

Botnet Statistics [2014-08-19]

detection period: 2014-08-19 00:00-23:59 UTC
total number of suspected botnet IPs: 2493
number of botnet IPs notified to network operators: 2342
number of spam blocked: 118528
recipient count of spam blocked: 3352280

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1211
2CRTC136
3Wotone110
4CHINANET-HB48
5CHINANET-GD45
6WASU35
7WASU-BB21
8UNICOM-ZJ20
9BSNLNET18
10KORNET-KR17

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1218
2China565
3United States107
4Russian Federation65
5India57
6Indonesia32
7South Korea26
8Viet Nam25
9Brazil22
10Argentina22

Tuesday, August 19, 2014

Suspected Bot List [2014-08-18]

detection period: 2014-08-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 156

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
EG62.117.58.109Egypt
HN190.107.140.77Honduras
IN27.5.182.53India
IN202.62.67.250India
IR91.98.147.62Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PK221.120.222.69Pakistan
RU95.188.112.11Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SG116.251.209.131Singapore
TR88.247.164.136Turkey
US50.201.42.106United States
US67.229.128.124United States
US174.139.94.82United States

List from greylisting:

Botnet Statistics [2014-08-18]

detection period: 2014-08-18 00:00-23:59 UTC
total number of suspected botnet IPs: 2616
number of botnet IPs notified to network operators: 2460
number of spam blocked: 92091
recipient count of spam blocked: 3081317

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1214
2CRTC150
3Wotone109
4VNPT-VNNIC-VN63
5WASU49
6UNICOM-ZJ43
7CHINANET-GD41
8CHINANET-HB36
9KORNET-KR23
10WASU-BB22

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1229
2China593
3Viet Nam108
4India77
5United States73
6Russian Federation50
7South Korea34
8Indonesia34
9Brazil29
10Hong Kong22

Monday, August 18, 2014

Suspected Bot List [2014-08-17]

detection period: 2014-08-17 00:00-23:59 UTC
number of suspected bots' IPs listed here: 50

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
EG62.117.58.109Egypt
HN190.107.140.77Honduras
IN27.5.182.53India
IN202.62.67.250India
IR91.98.147.62Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
PK103.4.92.88Pakistan
PK221.120.222.69Pakistan
RU95.188.112.11Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SG116.251.209.131Singapore
US50.201.42.106United States
US67.229.128.124United States
US68.119.62.62United States
US174.139.94.82United States

List from greylisting:

Botnet Statistics [2014-08-17]

detection period: 2014-08-17 00:00-23:59 UTC
total number of suspected botnet IPs: 2125
number of botnet IPs notified to network operators: 2075
number of spam blocked: 118601
recipient count of spam blocked: 3331581

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1222
2CRTC147
3WASU80
4UNICOM-ZJ64
5Wotone62
6CHINANET-GD53
7WASU-BB36
8CHINANET-HB25
9UNICOM-BJ9
10HICHINA9

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1225
2China588
3United States41
4Russian Federation29
5Indonesia23
6Hong Kong17
7Brazil16
8India14
9South Korea10
10Iran10

Sunday, August 17, 2014

Suspected Bot List [2014-08-16]

detection period: 2014-08-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 153

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN202.62.67.250India
IR91.98.147.62Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
PK103.4.92.88Pakistan
PK221.120.222.69Pakistan
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
US50.201.42.106United States
US68.119.62.62United States

List from greylisting:

Botnet Statistics [2014-08-16]

detection period: 2014-08-16 00:00-23:59 UTC
total number of suspected botnet IPs: 2464
number of botnet IPs notified to network operators: 2311
number of spam blocked: 116946
recipient count of spam blocked: 3327861

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1187
2CRTC136
3CHINANET-GD87
4UNICOM-ZJ53
5WASU50
6VNPT-VNNIC-VN42
7Wotone30
8WASU-BB30
9KORNET-KR25
10CHINANET-HB21

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1195
2China523
3Russian Federation105
4Viet Nam86
5India54
6South Korea51
7United States48
8Indonesia31
9Brazil28
10Peru22

Saturday, August 16, 2014

Suspected Bot List [2014-08-15]

detection period: 2014-08-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 158

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN27.5.182.53India
IN125.21.245.146India
IN202.62.67.250India
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PK221.120.222.69Pakistan
SA94.77.199.148Saudi Arabia
SE80.78.31.131Sweden
SG116.251.209.131Singapore
UA109.251.56.82Ukraine
US50.201.42.106United States
US67.229.128.125United States
US68.119.62.62United States
US174.139.94.82United States
US174.139.94.83United States

List from greylisting:

Botnet Statistics [2014-08-15]

detection period: 2014-08-15 00:00-23:59 UTC
total number of suspected botnet IPs: 2544
number of botnet IPs notified to network operators: 2386
number of spam blocked: 108529
recipient count of spam blocked: 3219293

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1182
2CRTC142
3WASU90
4Wotone56
5CHINANET-GD55
6WASU-BB42
7UNICOM-ZJ33
8VNPT-VNNIC-VN31
9UNICOM-GD16
10KORNET-KR16

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1196
2China579
3United States83
4Viet Nam63
5Russian Federation55
6South Korea43
7India37
8Indonesia32
9Brazil32
10Argentina28

Friday, August 15, 2014

Suspected Bot List [2014-08-14]

detection period: 2014-08-14 00:00-23:59 UTC
number of suspected bots' IPs listed here: 171

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AL217.24.253.251Albania
CO190.60.39.186Colombia
HN190.107.140.77Honduras
IN117.245.95.252India
IN125.21.245.146India
IN202.62.67.250India
IR91.98.147.62Iran
IR194.33.124.77Iran
IT95.227.105.203Italy
LB194.126.140.247Lebanon
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PK221.120.222.69Pakistan
SA94.77.199.148Saudi Arabia
SE80.78.31.131Sweden
SG116.251.209.131Singapore
TR88.247.164.136Turkey
UA109.251.56.82Ukraine
US50.201.42.106United States
US67.229.128.125United States
US68.119.62.62United States
US174.139.94.83United States
US204.195.104.31United States

List from greylisting:

Botnet Statistics [2014-08-14]

detection period: 2014-08-14 00:00-23:59 UTC
total number of suspected botnet IPs: 2580
number of botnet IPs notified to network operators: 2409
number of spam blocked: 111746
recipient count of spam blocked: 3278188

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1177
2CRTC149
3WASU73
4Wotone70
5CHINANET-GD70
6WASU-BB38
7UNICOM-ZJ33
8VNPT-VNNIC-VN27
9CHINANET-JX27
10CHINANET-HB27

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1187
2China667
3India79
4Russian Federation54
5United States53
6Viet Nam47
7Indonesia35
8Brazil33
9South Korea24
10United Kingdom24

Thursday, August 14, 2014

Suspected Bot List [2014-08-13]

detection period: 2014-08-13 00:00-23:59 UTC
number of suspected bots' IPs listed here: 277

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AL217.24.253.251Albania
HN190.107.140.77Honduras
IN27.5.182.53India
IN117.218.50.134India
IN117.245.95.252India
IN202.62.67.250India
IN203.90.114.228India
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
MO27.109.145.158Macau
PK103.4.92.88Pakistan
PK221.120.222.69Pakistan
SA94.77.199.148Saudi Arabia
SE80.78.31.131Sweden
SG116.251.209.131Singapore
TR193.255.143.62Turkey
UA109.251.56.82Ukraine
US50.201.42.106United States
US67.229.128.125United States
US174.139.94.82United States

List from greylisting:

Botnet Statistics [2014-08-13]

detection period: 2014-08-13 00:00-23:59 UTC
total number of suspected botnet IPs: 2903
number of botnet IPs notified to network operators: 2626
number of spam blocked: 106083
recipient count of spam blocked: 3127839

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1153
2CRTC147
3VNPT-VNNIC-VN95
4WASU60
5Wotone59
6CHINANET-GD48
7WASU-BB37
8BSNLNET35
9KORNET-KR33
10UNICOM-ZJ31

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1167
2China576
3Viet Nam176
4India120
5Russian Federation85
6South Korea77
7United States74
8Indonesia43
9Brazil42
10Argentina36

Wednesday, August 13, 2014

Suspected Bot List [2014-08-12]

detection period: 2014-08-12 00:00-23:59 UTC
number of suspected bots' IPs listed here: 283

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AL217.24.253.251Albania
IN27.5.182.53India
IN117.218.50.134India
IN117.245.95.252India
IN202.62.67.250India
IN203.90.114.228India
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PK221.120.222.69Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SE80.78.31.131Sweden
SG116.251.209.131Singapore
US50.201.42.106United States
US67.229.128.125United States
US174.139.94.82United States

List from greylisting:

Botnet Statistics [2014-08-12]

detection period: 2014-08-12 00:00-23:59 UTC
total number of suspected botnet IPs: 2946
number of botnet IPs notified to network operators: 2663
number of spam blocked: 104610
recipient count of spam blocked: 3140669

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1148
2CRTC133
3VNPT-VNNIC-VN116
4WASU85
5CHINANET-GD67
6Wotone55
7CHINANET-HB49
8KORNET-KR45
9WASU-BB43
10UNICOM-ZJ28

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1165
2China624
3Viet Nam183
4India92
5South Korea90
6United States54
7Peru51
8Brazil47
9Russian Federation41
10Colombia41

Tuesday, August 12, 2014

Suspected Bots' IP List for August 2014

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here (as shown below) 10 days after its respective botnet statistics gets published.

New data will be added here daily. You are free to use them to create more effective defenses, discover latest trends in cyber attacks, etc.

Suspected Bots IP [2014-08-31]
Suspected Bots IP [2014-08-30]
Suspected Bots IP [2014-08-29]
Suspected Bots IP [2014-08-28]
Suspected Bots IP [2014-08-27]
Suspected Bots IP [2014-08-26]
Suspected Bots IP [2014-08-25]
Suspected Bots IP [2014-08-24]
Suspected Bots IP [2014-08-23]
Suspected Bots IP [2014-08-22]
Suspected Bots IP [2014-08-19]
Suspected Bots IP [2014-08-18]
Suspected Bots IP [2014-08-17]
Suspected Bots IP [2014-08-16]
Suspected Bots IP [2014-08-15]
Suspected Bots IP [2014-08-14]
Suspected Bots IP [2014-08-13]
Suspected Bots IP [2014-08-12]
Suspected Bots IP [2014-08-11]
Suspected Bots IP [2014-08-10]
Suspected Bots IP [2014-08-09]
Suspected Bots IP [2014-08-08]
Suspected Bots IP [2014-08-07]
Suspected Bots IP [2014-08-06]
Suspected Bots IP [2014-08-05]
Suspected Bots IP [2014-08-04]
Suspected Bots IP [2014-08-03]
Suspected Bots IP [2014-08-02]
Suspected Bots IP [2014-08-01]

Suspected Bot List [2014-08-11]

detection period: 2014-08-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 297

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AL217.24.253.251Albania
IN117.218.50.134India
IN117.218.165.135India
IN117.245.95.252India
IN117.247.241.27India
IN202.62.67.250India
IN203.90.114.228India
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
PH58.69.100.234Philippines
PH124.107.165.60Philippines
PK103.4.92.88Pakistan
PK221.120.222.69Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SE80.78.31.131Sweden
SG116.251.209.131Singapore
US50.201.42.106United States
US174.139.94.83United States

List from greylisting:

Botnet Statistics [2014-08-11]

detection period: 2014-08-11 00:00-23:59 UTC
total number of suspected botnet IPs: 2963
number of botnet IPs notified to network operators: 2666
number of spam blocked: 70186
recipient count of spam blocked: 2293942

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1208
2CRTC120
3VNPT-VNNIC-VN77
4Wotone75
5WASU74
6CHINANET-GD65
7WASU-BB42
8KORNET-KR42
9CHINANET-HB37
10UNICOM-ZJ28

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1222
2China587
3Viet Nam128
4Russian Federation123
5South Korea97
6India88
7Peru55
8Argentina49
9United States47
10Brazil45

Monday, August 11, 2014

Suspected Bot List [2014-08-10]

detection period: 2014-08-10 00:00-23:59 UTC
number of suspected bots' IPs listed here: 187

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AL217.24.253.251Albania
IN117.245.95.252India
IN117.247.241.27India
IN202.62.67.250India
IN203.90.114.228India
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
PH58.69.100.234Philippines
PK221.120.222.69Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
US50.201.42.106United States
US174.139.94.83United States

List from greylisting:

Botnet Statistics [2014-08-10]

detection period: 2014-08-10 00:00-23:59 UTC
total number of suspected botnet IPs: 2580
number of botnet IPs notified to network operators: 2393
number of spam blocked: 96293
recipient count of spam blocked: 2752075

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1223
2CRTC113
3WASU101
4CHINANET-GD78
5VNPT-VNNIC-VN75
6Wotone55
7WASU-BB43
8UNICOM-ZJ33
9CHINANET-HB32
10KORNET-KR25

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1228
2China590
3Viet Nam126
4South Korea67
5Russian Federation54
6Peru43
7United States38
8Argentina35
9India29
10Poland22

Sunday, August 10, 2014

Suspected Bot List [2014-08-09]

detection period: 2014-08-09 00:00-23:59 UTC
number of suspected bots' IPs listed here: 221

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AL217.24.253.251Albania
IN117.218.165.135India
IN117.245.95.252India
IN117.247.241.27India
IN202.62.67.250India
IN203.90.114.228India
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
PH58.69.100.234Philippines
PK221.120.222.69Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
US50.201.42.106United States
US174.139.94.83United States

List from greylisting:

Botnet Statistics [2014-08-09]

detection period: 2014-08-09 00:00-23:59 UTC
total number of suspected botnet IPs: 2210
number of botnet IPs notified to network operators: 1989
number of spam blocked: 100675
recipient count of spam blocked: 2730488

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET926
2CRTC119
3WASU68
4VNPT-VNNIC-VN64
5Wotone58
6WASU-BB50
7CHINANET-GD48
8UNICOM-ZJ31
9CHINANET-HB28
10UNICOM-GD27

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan940
2China505
3Viet Nam112
4India66
5South Korea53
6Russian Federation45
7Argentina44
8United States39
9Peru39
10Brazil28

Saturday, August 9, 2014

Suspected Bot List [2014-08-08]

detection period: 2014-08-08 00:00-23:59 UTC
number of suspected bots' IPs listed here: 317

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AL217.24.253.251Albania
GR89.210.13.196Greece
IN117.218.165.135India
IN117.245.95.252India
IN117.247.241.27India
IN202.62.67.250India
IN203.90.114.228India
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
PH58.69.100.234Philippines
PK221.120.222.69Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
US50.201.42.106United States
US174.139.94.83United States

List from greylisting:

Botnet Statistics [2014-08-08]

detection period: 2014-08-08 00:00-23:59 UTC
total number of suspected botnet IPs: 2546
number of botnet IPs notified to network operators: 2229
number of spam blocked: 96384
recipient count of spam blocked: 2626463

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET831
2CRTC150
3VNPT-VNNIC-VN78
4Wotone58
5WASU56
6CHINANET-GD49
7PE-TPSA-LACNIC31
8UNICOM-ZJ29
9WASU-BB28
10KORNET-KR28

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan849
2China522
3Viet Nam155
4India106
5Russian Federation85
6South Korea78
7United States62
8Peru60
9Argentina54
10Brazil39

Friday, August 8, 2014

Suspected Bot List [2014-08-07]

detection period: 2014-08-07 00:00-23:59 UTC
number of suspected bots' IPs listed here: 308

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AL217.24.253.251Albania
GR89.210.13.196Greece
HN190.107.140.77Honduras
IN117.218.165.135India
IN117.245.95.252India
IN202.62.67.250India
IN203.90.114.228India
IR82.99.220.219Iran
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
PH58.69.100.234Philippines
PK221.120.222.69Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SE80.78.31.131Sweden
US50.201.42.106United States
US174.139.94.83United States
US208.67.21.47United States

List from greylisting:

Botnet Statistics [2014-08-07]

detection period: 2014-08-07 00:00-23:59 UTC
total number of suspected botnet IPs: 2663
number of botnet IPs notified to network operators: 2355
number of spam blocked: 94823
recipient count of spam blocked: 2741748

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET975
2CRTC145
3VNPT-VNNIC-VN79
4WASU68
5Wotone67
6CHINANET-GD41
7KORNET-KR35
8UNICOM-ZJ33
9WASU-BB30
10BSNLNET30

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan988
2China541
3Viet Nam132
4India89
5South Korea81
6Russian Federation77
7Argentina58
8United States51
9Peru51
10Indonesia40

Thursday, August 7, 2014

Suspected Bot List [2014-08-06]

detection period: 2014-08-06 00:00-23:59 UTC
number of suspected bots' IPs listed here: 146

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AL217.24.253.251Albania
BD180.211.180.18Bangladesh
GR89.210.13.196Greece
HN190.107.140.77Honduras
IN27.5.182.53India
IN117.218.165.135India
IN117.245.95.252India
IN125.21.245.146India
IN202.62.67.250India
IN203.90.114.228India
IR82.99.220.219Iran
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT31.199.192.150Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
PH58.69.100.234Philippines
PK221.120.222.69Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SE80.78.31.131Sweden
SG116.251.209.131Singapore
UA109.251.56.82Ukraine
US50.201.42.106United States
US174.139.94.82United States
US174.139.94.83United States
US208.67.21.47United States

List from greylisting:

Botnet Statistics [2014-08-06]

detection period: 2014-08-06 00:00-23:59 UTC
total number of suspected botnet IPs: 2425
number of botnet IPs notified to network operators: 2279
number of spam blocked: 97771
recipient count of spam blocked: 2818835

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET969
2CRTC146
3SPEEDVM-NETWORK-GROUP118
4WASU85
5Wotone75
6CHINANET-GD62
7UNICOM-ZJ57
8WASU-BB48
9VNPT-VNNIC-VN46
10CHINANET-HB33

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan976
2China642
3United States207
4Viet Nam72
5Russian Federation56
6India50
7Brazil28
8Italy27
9South Korea22
10Indonesia21

Wednesday, August 6, 2014

Suspected Bot List [2014-08-05]

detection period: 2014-08-05 00:00-23:59 UTC
number of suspected bots' IPs listed here: 244

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AL217.24.253.251Albania
BD180.211.180.18Bangladesh
GR89.210.13.196Greece
HN190.107.140.77Honduras
IN27.5.182.53India
IN117.218.165.135India
IN117.245.95.252India
IN125.21.245.146India
IN202.62.67.250India
IN203.90.114.228India
IR82.99.220.219Iran
IR91.98.147.62Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT31.199.192.150Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
LV85.9.201.199Latvia
PH58.69.100.234Philippines
PH122.54.80.66Philippines
PK221.120.222.69Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SE80.78.31.131Sweden
SG116.251.209.131Singapore
TR193.255.143.62Turkey
UA109.251.56.82Ukraine
US50.201.42.106United States
US174.139.94.82United States

List from greylisting:

Botnet Statistics [2014-08-05]

detection period: 2014-08-05 00:00-23:59 UTC
total number of suspected botnet IPs: 2494
number of botnet IPs notified to network operators: 2250
number of spam blocked: 61390
recipient count of spam blocked: 1981802

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET973
2CRTC134
3CHINANET-GD78
4UNICOM-ZJ64
5Wotone51
6VNPT-VNNIC-VN36
7WASU34
8SPEEDVM-NETWORK-GROUP24
9CHINANET-HB24
10UNICOM-SD22

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan980
2China551
3United States168
4India97
5Viet Nam71
6Brazil47
7United Kingdom40
8Russian Federation34
9Italy34
10Argentina34