Custom Search

Tuesday, September 30, 2014

Suspected Bot List [2014-09-29]

detection period: 2014-09-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 127

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.16.161.35Argentina
AR186.22.193.175Argentina
AR186.22.241.100Argentina
AR186.23.11.128Argentina
AR190.120.59.156Argentina
AR190.124.155.72Argentina
AU192.94.208.254Australia
BD203.76.147.70Bangladesh
BG78.128.22.134Bulgaria
CA64.39.165.52Canada
CL186.36.104.201Chile
CL190.120.169.196Chile
CL190.208.228.186Chile
CL190.209.183.181Chile
CO200.80.43.248Colombia
DE89.14.252.144Germany
EC181.112.33.69Ecuador
EC181.112.150.242Ecuador
EC186.47.232.178Ecuador
IN59.185.241.3India
IN106.197.33.10India
IN117.96.22.90India
IN117.218.50.134India
IN117.230.166.148India
IN117.249.218.48India
IN210.212.85.35India
IR91.98.147.62Iran
IR91.98.234.195Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT79.10.134.101Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
LK220.247.216.242Sri Lanka
MX201.161.130.76Mexico
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PL87.101.22.140Poland
PL95.160.12.231Poland
PL95.160.42.93Poland
PL95.160.68.142Poland
PL95.160.136.95Poland
PL95.160.177.29Poland
PT62.169.103.57Portugal
RU95.188.45.141Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
SE83.209.204.114Sweden
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US24.112.13.173United States
US24.112.18.252United States
US24.112.188.73United States
US24.154.236.162United States
US24.171.26.226United States
US24.183.164.80United States
US24.183.203.94United States
US24.207.213.64United States
US24.217.91.251United States
US24.217.156.57United States
US50.201.42.106United States
US65.184.46.166United States
US65.184.203.46United States
US65.185.104.25United States
US66.168.218.87United States
US66.190.171.102United States
US66.227.227.215United States
US68.114.255.8United States
US68.117.101.115United States
US68.184.61.35United States
US69.163.37.119United States
US71.8.124.217United States
US71.82.59.32United States
US71.83.75.47United States
US71.91.110.198United States
US71.95.211.121United States
US75.128.69.144United States
US75.130.192.33United States
US75.131.17.141United States
US75.135.3.237United States
US75.137.29.184United States
US75.137.69.178United States
US75.139.220.50United States
US75.141.103.25United States
US75.141.202.20United States
US96.39.187.235United States
US97.92.219.138United States
US97.92.221.89United States
US174.139.8.82United States
US204.116.60.250United States
UZ89.236.219.106Uzbekistan
VE186.24.43.3Venezuela
VE190.202.116.101Venezuela

List from greylisting:

Botnet Statistics [2014-09-29]

detection period: 2014-09-29 00:00-23:59 UTC
total number of suspected botnet IPs: 2778
number of botnet IPs notified to network operators: 2651
number of spam blocked: 162112
recipient count of spam blocked: 4515876

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1199
2CHINANET-JS225
3CHINANET-GD208
4CRTC81
5CHINANET-SN79
6CHINANET-LN68
7CHINANET-HB31
8CHINANET-HL30
9CHINANET-FJ30
10UNICOM-GD28

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1207
2China928
3United States163
4Brazil56
5Poland49
6Russian Federation36
7Germany34
8Indonesia22
9India18
10Ukraine17

Monday, September 29, 2014

Suspected Bot List [2014-09-28]

detection period: 2014-09-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 125

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AM178.78.184.66Armenia
AR181.16.178.73Argentina
AR181.177.16.75Argentina
AR186.22.83.14Argentina
AR186.22.104.45Argentina
AR186.22.109.44Argentina
AR186.22.193.175Argentina
AR186.23.40.87Argentina
AR186.23.89.47Argentina
AR190.6.214.160Argentina
AR190.11.121.53Argentina
AR190.13.115.240Argentina
AR190.106.82.139Argentina
AR190.115.124.30Argentina
AR190.221.104.213Argentina
AR200.50.186.43Argentina
BD203.76.147.70Bangladesh
CL181.73.75.223Chile
CL181.73.108.87Chile
CL181.74.240.93Chile
CL186.36.34.163Chile
CL186.36.118.184Chile
CL190.208.112.31Chile
CL190.209.57.20Chile
CL190.209.85.239Chile
CL190.209.141.29Chile
CO190.60.39.188Colombia
CO200.80.43.248Colombia
DE89.13.253.55Germany
EG62.117.58.109Egypt
ES87.111.171.16Spain
ES89.29.222.160Spain
IN59.93.122.243India
IN117.252.3.251India
IN117.254.182.167India
IN210.212.85.35India
IR91.98.147.62Iran
IR91.98.234.195Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT62.18.60.8Italy
IT62.18.141.73Italy
IT79.10.5.185Italy
IT79.47.24.99Italy
IT79.47.211.126Italy
IT82.61.124.179Italy
IT95.227.105.203Italy
LB194.126.140.247Lebanon
LK220.247.216.242Sri Lanka
MX187.240.97.111Mexico
PE181.65.183.42Peru
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
PL95.160.68.142Poland
PL95.160.90.193Poland
PL95.160.137.41Poland
PL95.160.177.29Poland
PL95.160.208.113Poland
PL95.160.220.125Poland
PL95.160.249.96Poland
PL213.92.170.104Poland
PL213.92.184.164Poland
PR196.42.50.102Puerto Rico
PT78.130.9.45Portugal
PT78.130.20.250Portugal
PT78.130.75.91Portugal
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US24.177.206.168United States
US24.207.213.64United States
US24.217.110.206United States
US24.231.226.69United States
US50.201.42.106United States
US65.28.87.9United States
US65.184.203.46United States
US65.191.250.21United States
US66.190.216.29United States
US68.114.254.192United States
US68.117.73.252United States
US68.117.101.115United States
US68.119.11.220United States
US68.184.59.98United States
US69.163.37.119United States
US71.83.75.47United States
US71.84.110.118United States
US71.91.110.198United States
US74.129.192.123United States
US74.132.159.99United States
US75.128.69.144United States
US75.131.17.141United States
US75.131.124.62United States
US75.135.3.237United States
US75.135.224.106United States
US75.139.220.50United States
US75.141.251.121United States
US75.142.145.240United States
US96.32.72.12United States
US96.39.187.235United States
UZ89.236.219.106Uzbekistan
VE190.202.116.101Venezuela

List from greylisting:

Botnet Statistics [2014-09-28]

detection period: 2014-09-28 00:00-23:59 UTC
total number of suspected botnet IPs: 2862
number of botnet IPs notified to network operators: 2737
number of spam blocked: 148256
recipient count of spam blocked: 4146595

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1055
2CHINANET-JS274
3CHINANET-GD237
4CRTC139
5CHINANET-SN118
6CHINANET-LN77
7CHINANET-FJ37
8CHINANET-HB34
9CHINANET-HL30
10sxtypdsn26

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1132
2Taiwan1061
3United States137
4Brazil61
5Poland57
6Germany46
7Russian Federation37
8Ukraine28
9Portugal27
10Indonesia24

Friday, September 26, 2014

Suspected Bot List [2014-09-25]

detection period: 2014-09-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 120

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.16.161.39Argentina
AR181.177.15.97Argentina
AR186.22.83.14Argentina
AR190.13.115.240Argentina
AR190.55.211.151Argentina
AR190.106.81.87Argentina
AR190.106.82.139Argentina
AR190.110.239.79Argentina
AR190.120.149.213Argentina
AR190.220.47.252Argentina
AR200.41.129.112Argentina
AR201.250.113.116Argentina
BD203.76.147.70Bangladesh
CA64.39.165.234Canada
CL186.34.70.114Chile
CL186.37.78.148Chile
IN27.251.59.46India
IN59.93.127.102India
IN117.224.93.215India
IN117.230.230.162India
IN117.247.231.3India
IN210.212.85.35India
IR91.98.234.195Iran
IR194.33.124.77Iran
IT5.168.121.71Italy
IT31.199.192.17Italy
IT31.199.192.20Italy
IT79.10.110.222Italy
IT79.46.91.137Italy
IT79.52.197.210Italy
IT95.227.105.203Italy
IT176.200.174.228Italy
IT176.200.194.225Italy
LK220.247.216.242Sri Lanka
MX187.240.97.111Mexico
PE200.110.35.150Peru
PH58.69.100.234Philippines
PL213.92.184.164Poland
PT78.130.2.12Portugal
PT78.130.115.163Portugal
RS24.135.192.39Serbia
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
SE83.209.146.170Sweden
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US24.159.123.174United States
US50.201.42.106United States
US65.28.87.9United States
US74.132.159.99United States
US174.139.8.82United States
US216.119.40.38United States
VE186.24.34.179Venezuela
VE190.202.116.101Venezuela

List from greylisting:

Botnet Statistics [2014-09-25]

detection period: 2014-09-25 00:00-23:59 UTC
total number of suspected botnet IPs: 3406
number of botnet IPs notified to network operators: 3286
number of spam blocked: 250545
recipient count of spam blocked: 4759741

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1227
2CHINANET-GD288
3UNICOM-ZJ227
4CHINANET-JS128
5CRTC121
6CHINANET-SN98
7CHINANET-LN96
8ZJU-CN93
9CMNET70
10CHINANET-HB52

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1492
2Taiwan1236
3United States135
4Brazil66
5Russian Federation48
6Poland31
7Indonesia31
8Viet Nam28
9Germany26
10India22

Thursday, September 25, 2014

Suspected Bot List [2014-09-24]

detection period: 2014-09-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 175

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.116.73.173Argentina
AR186.22.90.184Argentina
AR186.22.109.44Argentina
AR186.23.40.87Argentina
AR190.0.103.69Argentina
AR190.15.92.79Argentina
AR190.103.194.96Argentina
AR190.106.81.57Argentina
AR190.106.82.139Argentina
AR190.107.117.252Argentina
AR190.110.239.79Argentina
AR190.120.154.213Argentina
AR190.221.104.213Argentina
AR200.41.129.112Argentina
BD203.76.147.70Bangladesh
CA76.9.41.161Canada
CL181.43.1.65Chile
CL181.75.144.56Chile
CL190.208.245.179Chile
CL190.209.172.7Chile
EC186.47.232.178Ecuador
IR91.98.43.36Iran
IR91.98.234.195Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT79.10.149.87Italy
IT95.227.105.203Italy
LK220.247.216.242Sri Lanka
MX201.161.130.152Mexico
PE190.41.51.210Peru
PE200.37.62.62Peru
PE200.110.35.150Peru
PH58.69.100.234Philippines
PR196.42.50.102Puerto Rico
PT62.169.126.218Portugal
PT88.210.86.104Portugal
RO194.102.73.103Romania
RS24.135.192.39Serbia
RU95.71.21.55Russian Federation
RU95.188.112.11Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SD196.202.153.146Sudan
SE83.209.172.46Sweden
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US24.217.110.206United States
US24.247.147.181United States
US50.201.42.106United States
US66.168.149.193United States
US66.168.171.247United States
US68.119.11.220United States
US68.190.146.82United States
US71.14.60.66United States
US75.131.17.141United States
US75.135.3.237United States
US75.137.197.232United States
US75.141.251.121United States
US96.32.9.42United States
US96.37.64.29United States

List from greylisting:

Botnet Statistics [2014-09-24]

detection period: 2014-09-24 00:00-23:59 UTC
total number of suspected botnet IPs: 2925
number of botnet IPs notified to network operators: 2750
number of spam blocked: 228088
recipient count of spam blocked: 4854435

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1225
2CHINANET-GD194
3UNICOM-ZJ163
4CRTC130
5CMNET73
6CHINANET-HB51
7ZJU-CN50
8CHINANET-JS42
9UNICOM-FJ30
10CRISSIC20

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1237
2China920
3United States129
4Brazil73
5India48
6Russian Federation46
7Poland36
8Germany36
9Viet Nam33
10Argentina25

Wednesday, September 24, 2014

Suspected Bot List [2014-09-23]

detection period: 2014-09-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 104

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
BO190.129.58.252Bolivia
IR91.98.43.36Iran
IR91.98.234.195Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LK220.247.216.242Sri Lanka
PE200.110.35.150Peru
PH58.69.100.234Philippines
RU95.188.112.11Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-09-23]

detection period: 2014-09-23 00:00-23:59 UTC
total number of suspected botnet IPs: 2464
number of botnet IPs notified to network operators: 2360
number of spam blocked: 246818
recipient count of spam blocked: 4893669

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1239
2CMNET165
3CRTC134
4UNICOM-ZJ126
5CHINANET-GD121
6ZJU-CN58
7CHINANET-HB38
8UNICOM-GD19
9UNICOM-BJ14
10CLOUDRADIUM-512

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1248
2China785
3Russian Federation48
4United States44
5India33
6Brazil25
7Indonesia22
8Viet Nam18
9Italy15
10South Korea14

Tuesday, September 23, 2014

Suspected Bot List [2014-09-22]

detection period: 2014-09-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 61

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
BO190.129.58.252Bolivia
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LK220.247.216.242Sri Lanka
PE200.110.35.150Peru
PH58.69.100.234Philippines
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-09-22]

detection period: 2014-09-22 00:00-23:59 UTC
total number of suspected botnet IPs: 2297
number of botnet IPs notified to network operators: 2236
number of spam blocked: 216819
recipient count of spam blocked: 4547123

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1211
2CRTC148
3CMNET137
4CHINANET-GD112
5UNICOM-ZJ104
6CHINANET-HB44
7ZJU-CN42
8UNICOM-BJ17
9WASU16
10UNICOM-SD16

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1219
2China745
3United States49
4Russian Federation40
5Brazil21
6Italy19
7Indonesia14
8Viet Nam13
9Iran13
10Hong Kong10

Monday, September 22, 2014

Suspected Bot List [2014-09-21]

detection period: 2014-09-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 60

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
IR91.98.234.195Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LK220.247.216.242Sri Lanka
PE200.110.35.150Peru
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-09-21]

detection period: 2014-09-21 00:00-23:59 UTC
total number of suspected botnet IPs: 2035
number of botnet IPs notified to network operators: 1975
number of spam blocked: 147843
recipient count of spam blocked: 4224206

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1195
2CHINANET-GD125
3CRTC68
4CMNET67
5UNICOM-ZJ57
6CHINANET-HB43
7WASU41
8WASU-BB40
9UNICOM-BJ12
10UNICOM-GD11

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1204
2China534
3Russian Federation40
4United States31
5Indonesia19
6Brazil18
7Argentina13
8Iran12
9Viet Nam11
10Colombia11

Sunday, September 21, 2014

Suspected Bot List [2014-09-20]

detection period: 2014-09-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 56

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
EG62.117.58.109Egypt
IR91.98.234.195Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LK220.247.216.242Sri Lanka
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-09-20]

detection period: 2014-09-20 00:00-23:59 UTC
total number of suspected botnet IPs: 1838
number of botnet IPs notified to network operators: 1782
number of spam blocked: 150630
recipient count of spam blocked: 4277065

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1168
2CHINANET-GD91
3CRTC74
4CHINANET-HB48
5CMNET46
6WASU24
7WASU-BB14
8UNICOM-BJ13
9CLOUDRADIUM-510
10UNICOM-SD6

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1174
2China387
3United States36
4Russian Federation33
5Indonesia16
6Brazil15
7India12
8Viet Nam10
9Iran10
10Argentina10

Saturday, September 20, 2014

Suspected Bot List [2014-09-19]

detection period: 2014-09-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 68

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
IR91.98.234.195Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LK220.247.216.242Sri Lanka
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-09-19]

detection period: 2014-09-19 00:00-23:59 UTC
total number of suspected botnet IPs: 2143
number of botnet IPs notified to network operators: 2075
number of spam blocked: 162996
recipient count of spam blocked: 4558293

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1195
2CRTC139
3CMNET127
4CHINANET-GD109
5UNICOM-ZJ87
6CHINANET-HB43
7UNICOM-BJ13
8UNICOM-GD9
9HICHINA7
10UNICOM-SD6

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1202
2China617
3United States34
4Russian Federation31
5Brazil29
6India27
7Indonesia20
8Italy11
9Spain11
10Viet Nam10

Friday, September 19, 2014

Suspected Bot List [2014-09-18]

detection period: 2014-09-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 93

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
EG62.117.58.109Egypt
IR91.98.234.195Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LK220.247.216.242Sri Lanka
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-09-18]

detection period: 2014-09-18 00:00-23:59 UTC
total number of suspected botnet IPs: 2259
number of botnet IPs notified to network operators: 2166
number of spam blocked: 129307
recipient count of spam blocked: 3799067

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1146
2CMNET166
3UNICOM-ZJ131
4CRTC123
5CHINANET-GD90
6UNICOM-FJ39
7CHINANET-HB31
8VNPT-VNNIC-VN16
9BSNLNET15
10UNICOM-SD10

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1153
2China698
3United States62
4India43
5Viet Nam34
6Russian Federation30
7Brazil22
8Indonesia20
9Italy16
10Iran15

Thursday, September 18, 2014

Suspected Bot List [2014-09-17]

detection period: 2014-09-17 00:00-23:59 UTC
number of suspected bots' IPs listed here: 88

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
EG62.117.58.109Egypt
IR91.98.234.195Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LK220.247.216.242Sri Lanka
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-09-17]

detection period: 2014-09-17 00:00-23:59 UTC
total number of suspected botnet IPs: 2228
number of botnet IPs notified to network operators: 2140
number of spam blocked: 110723
recipient count of spam blocked: 3292126

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1165
2CRTC117
3CHINANET-GD116
4CMNET110
5UNICOM-ZJ86
6CHINANET-HB33
7VNPT-VNNIC-VN24
8UNICOM-SD12
9UNICOM-GD12
10UNICOM-BJ8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1174
2China594
3United States66
4Russian Federation60
5Viet Nam36
6Indonesia28
7Brazil25
8India24
9Italy14
10Iran14

Wednesday, September 17, 2014

Suspected Bot List [2014-09-16]

detection period: 2014-09-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 99

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
BO190.129.58.252Bolivia
EG62.117.58.109Egypt
IR91.98.234.195Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LK220.247.216.242Sri Lanka
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
TW180.218.34.210Taiwan
UA178.150.53.133Ukraine
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-09-16]

detection period: 2014-09-16 00:00-23:59 UTC
total number of suspected botnet IPs: 2127
number of botnet IPs notified to network operators: 2028
number of spam blocked: 254589
recipient count of spam blocked: 3830372

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1170
2CRTC117
3UNICOM-ZJ93
4CHINANET-GD47
5CHINANET-HB23
6UNICOM-HA10
7WEBSTREAM9
8UNICOM-GD9
9UNICOM-BJ9
10CHINANET-AH9

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1179
2China417
3Russian Federation108
4United States50
5Brazil29
6India27
7Indonesia25
8Viet Nam15
9Iran15
10Ukraine13

Tuesday, September 16, 2014

Suspected Bot List [2014-09-15]

detection period: 2014-09-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 70

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
BO190.129.58.252Bolivia
IN117.247.241.27India
IN202.56.203.62India
IR91.98.234.195Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
LK220.247.216.242Sri Lanka
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
SA94.77.199.148Saudi Arabia
TR85.105.50.233Turkey
TR88.247.164.136Turkey
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-09-15]

detection period: 2014-09-15 00:00-23:59 UTC
total number of suspected botnet IPs: 2066
number of botnet IPs notified to network operators: 1996
number of spam blocked: 276458
recipient count of spam blocked: 4329997

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1190
2CRTC124
3CHINANET-GD118
4UNICOM-ZJ84
5UNICOM-HA19
6CHINANET-HB18
7UNICOM-SD9
8UNICOM-BJ9
9CHINANET-JS9
10CHINANET-AH8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1196
2China480
3Russian Federation63
4United States37
5Indonesia21
6Brazil20
7India17
8Viet Nam14
9Iran12
10Spain12

Monday, September 15, 2014

Suspected Bot List [2014-09-14]

detection period: 2014-09-14 00:00-23:59 UTC
number of suspected bots' IPs listed here: 43

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
IN202.56.203.62India
IR91.98.234.195Iran
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR85.105.50.233Turkey
TR88.247.164.136Turkey
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-09-14]

detection period: 2014-09-14 00:00-23:59 UTC
total number of suspected botnet IPs: 1794
number of botnet IPs notified to network operators: 1760
number of spam blocked: 273545
recipient count of spam blocked: 4542782

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1140
2CHINANET-GD87
3CRTC72
4UNICOM-ZJ71
5CHINANET-HB24
6WASU19
7WASU-BB18
8CHINANET-AH15
9UNICOM-HA12
10UNICOM-BJ9

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1147
2China432
3United States28
4Russian Federation28
5Indonesia15
6Brazil13
7Iran10
8Hong Kong9
9South Korea8
10Poland6

Sunday, September 14, 2014

Suspected Bot List [2014-09-13]

detection period: 2014-09-13 00:00-23:59 UTC
number of suspected bots' IPs listed here: 43

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
BO190.129.58.252Bolivia
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-09-13]

detection period: 2014-09-13 00:00-23:59 UTC
total number of suspected botnet IPs: 1794
number of botnet IPs notified to network operators: 1751
number of spam blocked: 255250
recipient count of spam blocked: 3978366

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1164
2CHINANET-GD135
3CHINANET-HB40
4WASU36
5WASU-BB33
6CHINANET-ZJ27
7CHINANET-AH26
8UNICOM-BJ12
9UNICOM-SD10
10UNICOM-GD6

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1170
2China391
3Russian Federation37
4United States28
5Brazil21
6Indonesia15
7Iran10
8Viet Nam9
9Argentina9
10Hong Kong7

Saturday, September 13, 2014

Suspected Bot List [2014-09-12]

detection period: 2014-09-12 00:00-23:59 UTC
number of suspected bots' IPs listed here: 98

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
BO190.129.58.252Bolivia
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-09-12]

detection period: 2014-09-12 00:00-23:59 UTC
total number of suspected botnet IPs: 2205
number of botnet IPs notified to network operators: 2107
number of spam blocked: 261819
recipient count of spam blocked: 4187482

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1196
2CHINANET-GD104
3UNICOM-ZJ78
4CRTC67
5CHINANET-HB43
6UNICOM-SD30
7VNPT-VNNIC-VN28
8CHINANET-ZJ24
9CHINANET-AH21
10WASU18

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1207
2China528
3United States55
4Viet Nam48
5India39
6Indonesia23
7Russian Federation21
8South Korea21
9France20
10Brazil18

Friday, September 12, 2014

Suspected Bots' IP List for September 2014

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here (as shown below) 10 days after its respective botnet statistics gets published.

New data will be added here daily. You are free to use them to create more effective defenses, discover latest trends in cyber attacks, etc.

Suspected Bots IP [2014-09-30]
Suspected Bots IP [2014-09-29]
Suspected Bots IP [2014-09-28]
Suspected Bots IP [2014-09-25]
Suspected Bots IP [2014-09-24]
Suspected Bots IP [2014-09-23]
Suspected Bots IP [2014-09-22]
Suspected Bots IP [2014-09-21]
Suspected Bots IP [2014-09-20]
Suspected Bots IP [2014-09-19]
Suspected Bots IP [2014-09-18]
Suspected Bots IP [2014-09-17]
Suspected Bots IP [2014-09-16]
Suspected Bots IP [2014-09-15]
Suspected Bots IP [2014-09-14]
Suspected Bots IP [2014-09-13]
Suspected Bots IP [2014-09-12]
Suspected Bots IP [2014-09-11]
Suspected Bots IP [2014-09-10]
Suspected Bots IP [2014-09-09]
Suspected Bots IP [2014-09-08]
Suspected Bots IP [2014-09-07]
Suspected Bots IP [2014-09-06]
Suspected Bots IP [2014-09-05]
Suspected Bots IP [2014-09-04]
Suspected Bots IP [2014-09-03]
Suspected Bots IP [2014-09-02]
Suspected Bots IP [2014-09-01]

Suspected Bot List [2014-09-11]

detection period: 2014-09-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 97

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
BO190.129.58.252Bolivia
CL186.106.16.4Chile
EG41.33.169.36Egypt
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
RU95.188.112.11Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
SD41.202.160.14Sudan
TR88.247.164.136Turkey
US50.201.42.106United States
UZ89.236.219.220Uzbekistan

List from greylisting:

Botnet Statistics [2014-09-11]

detection period: 2014-09-11 00:00-23:59 UTC
total number of suspected botnet IPs: 2251
number of botnet IPs notified to network operators: 2154
number of spam blocked: 330000
recipient count of spam blocked: 5162886

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1178
2CRTC145
3CHINANET-GD138
4UNICOM-ZJ76
5UNICOM-FJ43
6CHINANET-HB34
7UNICOM-BJ24
8CHINANET-AH15
9UNICOM-GD11
10CHINANET-ZJ10

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1186
2China619
3United States75
4India38
5Russian Federation22
6Indonesia20
7Brazil20
8Viet Nam19
9United Kingdom18
10Hong Kong17

Thursday, September 11, 2014

Suspected Bot List [2014-09-10]

detection period: 2014-09-10 00:00-23:59 UTC
number of suspected bots' IPs listed here: 102

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
EC181.112.45.2Ecuador
EG41.33.169.36Egypt
IN203.122.58.93India
IR194.33.124.77Iran
IT31.199.192.17Italy
IT31.199.192.20Italy
IT95.227.105.203Italy
LV85.9.201.199Latvia
PE200.110.35.150Peru
PE201.230.238.3Peru
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
RU95.188.112.11Russian Federation
RU109.167.201.26Russian Federation
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
US50.201.42.106United States
UY190.135.202.2Uruguay

List from greylisting:

Botnet Statistics [2014-09-10]

detection period: 2014-09-10 00:00-23:59 UTC
total number of suspected botnet IPs: 2071
number of botnet IPs notified to network operators: 1969
number of spam blocked: 173100
recipient count of spam blocked: 3192304

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1194
2CRTC131
3UNICOM-ZJ57
4CHINANET-GD33
5CHINANET-HB24
6UNICOM-BJ19
7VNPT-VNNIC-VN18
8UNICOM-GD16
9UNICOM-SD14
10UNICOM-HA12

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1201
2China407
3India59
4United States49
5Viet Nam30
6Russian Federation29
7Indonesia24
8Brazil24
9United Kingdom15
10South Africa13

Wednesday, September 10, 2014

Suspected Bot List [2014-09-09]

detection period: 2014-09-09 00:00-23:59 UTC
number of suspected bots' IPs listed here: 79

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2014-09-09]

detection period: 2014-09-09 00:00-23:59 UTC
total number of suspected botnet IPs: 1672
number of botnet IPs notified to network operators: 1593
number of spam blocked: 61923
recipient count of spam blocked: 1354928

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1080
2CRTC145
3UNICOM-ZJ42
4CHINANET-GD19
5UNICOM-BJ18
6VNPT-VNNIC-VN12
7UNICOM-GD12
8BSNLNET11
9BHARTI-IN11
10UNICOM-HA10

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1085
2China300
3India52
4United States38
5United Kingdom18
6Viet Nam17
7Spain9
8Singapore8
9France8
10Russian Federation7

Tuesday, September 9, 2014

Suspected Bot List [2014-09-08]

detection period: 2014-09-08 00:00-23:59 UTC
number of suspected bots' IPs listed here: 75

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
CA184.107.73.239Canada
IR194.33.124.77Iran
IT31.199.192.20Italy
IT95.227.105.203Italy
PE200.110.35.150Peru
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-09-08]

detection period: 2014-09-08 00:00-23:59 UTC
total number of suspected botnet IPs: 1835
number of botnet IPs notified to network operators: 1760
number of spam blocked: 137292
recipient count of spam blocked: 2409124

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1156
2CRTC76
3UNICOM-FJ38
4WASU34
5WASU-BB32
6UNICOM-BJ17
7CHINANET-GD17
8VNPT-VNNIC-VN8
9UNICOM-HA8
10HICHINA7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1162
2China306
3India41
4Russian Federation39
5United States37
6Viet Nam21
7Hong Kong18
8Brazil15
9Indonesia14
10Malaysia12

Monday, September 8, 2014

Suspected Bot List [2014-09-07]

detection period: 2014-09-07 00:00-23:59 UTC
number of suspected bots' IPs listed here: 47

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
CA184.107.73.239Canada
EG62.117.58.109Egypt
IR194.33.124.77Iran
IT31.199.192.20Italy
PE200.110.35.150Peru
PH58.69.100.234Philippines
PK103.4.92.88Pakistan
SA94.77.199.148Saudi Arabia
TR88.247.164.136Turkey
US50.201.42.106United States

List from greylisting:

Botnet Statistics [2014-09-07]

detection period: 2014-09-07 00:00-23:59 UTC
total number of suspected botnet IPs: 1685
number of botnet IPs notified to network operators: 1638
number of spam blocked: 180277
recipient count of spam blocked: 3209500

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1179
2VNPT-VNNIC-VN38
3CHINANET-GD35
4WASU26
5WASU-BB19
6VIETEL-VNNIC-VN10
7FPT-VN10
8UNICOM-GD8
9KORNET-KR7
10UNICOM-BJ6

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1188
2China164
3Viet Nam77
4Russian Federation27
5United States23
6Brazil16
7South Korea12
8Indonesia11
9Hong Kong11
10Poland9

Sunday, September 7, 2014

Botnet Statistics for August 2014

detection period: 2014-08-01 00:00 - 2014-08-31 23:59 UTC
total number of suspected botnet IPs: 49092
number of blocked spams: 2345123
recipient count of blocked spams: 79214540

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan21708
2China9905
3Viet Nam3119
4India1573
5Russian Federation1200
6United States1059
7South Korea904
8Peru868
9Argentina814
10Brazil498
11Colombia418
12Chile377
13United Kingdom358
14Indonesia356
15Italy290
16Mexico249
17Iran238
18Tunisia230
19Saudi Arabia225
20Poland219
21Israel219
22South Africa197
23Turkey194
24Spain194
25Romania153

The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:

RankCountry# of blocked spams
1Taiwan1268145
2China389112
3United States72185
4Indonesia68660
5Brazil49003
6Hong Kong45863
7Russian Federation45326
8Iran31976
9Poland28537
10Italy23110
11Turkey22789
12India19138
13Ukraine18346
14Philippines17725
15Saudi Arabia16768
16Viet Nam16056
17Ivory Coast15953
18Malaysia15758
19France15363
20Pakistan14907
21South Korea13095
22Singapore10211
23South Africa9088
24Serbia8429
25Thailand7294

The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are: