Custom Search

Monday, August 31, 2015

Suspected Bot List [2015-08-30]

detection period: 2015-08-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 36

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AM5.77.218.239Armenia
AR190.104.232.112Argentina
BO186.27.126.130Bolivia
EC181.112.150.242Ecuador
EG193.227.49.83Egypt
IN203.192.212.52India
MA41.137.19.3Morocco
MX201.116.227.163Mexico
PA181.178.238.209Panama
RU5.19.139.21Russian Federation
SV201.247.149.77El Salvador
US68.188.100.100United States
US69.144.223.99United States
US184.167.56.70United States

List from greylisting:

country codeIP addressCountry
AM46.241.215.190Armenia
AR186.134.166.41Argentina
AR190.17.148.78Argentina
AR190.104.232.112Argentina
AR190.246.138.110Argentina
AR201.212.216.23Argentina
EG193.227.49.83Egypt
IN59.97.37.107India
IN117.205.212.62India
IN117.247.120.243India
IN122.166.149.18India
IN203.115.68.84India
IT95.224.155.240Italy
MA41.137.19.3Morocco
ME46.161.82.201Montenegro
MX201.116.227.163Mexico
SV201.247.149.77El Salvador
UA81.95.181.238Ukraine
US68.188.100.100United States
US69.144.223.99United States
US142.4.9.32United States
US184.167.56.70United States

Botnet Statistics [2015-08-30]

detection period: 2015-08-30 00:00-23:59 UTC
total number of suspected botnet IPs: 2347
number of botnet IPs notified to network operators: 2319
number of spam blocked: 185422
recipient count of spam blocked: 3613204

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET999
2CHINANET-GD266
3WASU115
4UNICOM-ZJ114
5WASU-BB89
6CHINANET-JS86
7CHINANET-HN80
8CHINANET-SX52
9VNPT-VNNIC-VN42
10CHINANET-LN35

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1056
2Taiwan1002
3Viet Nam76
4Brazil35
5United States28
6Russian Federation17
7Ukraine15
8India14
9Indonesia10
10Kazakhstan7

Sunday, August 30, 2015

Suspected Bot List [2015-08-29]

detection period: 2015-08-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 38

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.3.84.104Argentina
AR190.104.232.112Argentina
BO186.27.127.129Bolivia
EG193.227.49.83Egypt
ES80.31.139.206Spain
IN122.170.105.219India
IN182.72.139.50India
IN203.192.212.52India
MA41.137.19.3Morocco
MX201.116.227.163Mexico
RU5.19.139.21Russian Federation
SV201.247.149.77El Salvador
US68.188.100.100United States
US69.144.223.99United States
US74.143.184.254United States
US184.167.56.70United States

List from greylisting:

country codeIP addressCountry
AR186.59.225.168Argentina
AR190.124.152.215Argentina
EG193.227.49.83Egypt
IN59.97.164.129India
IN120.62.200.250India
IN122.174.210.134India
IN182.72.168.122India
IN182.74.63.142India
IN203.192.212.52India
IN223.227.59.42India
MA41.137.19.3Morocco
MX189.254.172.30Mexico
MX201.145.208.12Mexico
MX201.167.160.203Mexico
RO109.99.9.8Romania
SV201.247.149.77El Salvador
UA176.121.229.229Ukraine
US68.188.100.100United States
US69.144.223.99United States
US142.4.9.32United States
US184.167.56.70United States
VN220.231.127.15Viet Nam

Botnet Statistics [2015-08-29]

detection period: 2015-08-29 00:00-23:59 UTC
total number of suspected botnet IPs: 1848
number of botnet IPs notified to network operators: 1817
number of spam blocked: 177685
recipient count of spam blocked: 3721686

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET977
2CHINANET-GD160
3CHINANET-JS60
4UNICOM-ZJ55
5WASU34
6VNPT-VNNIC-VN30
7CHINANET-HN30
8CHINANET-LN27
9WASU-BB20
10CHINANET-SX20

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan981
2China558
3Viet Nam54
4Brazil48
5United States31
6India20
7Russian Federation18
8Ukraine14
9Indonesia10
10Thailand7

Saturday, August 29, 2015

Suspected Bot List [2015-08-28]

detection period: 2015-08-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 25

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR190.104.232.112Argentina
AR190.190.3.174Argentina
AR190.191.98.161Argentina
AR190.221.118.47Argentina
CA184.107.204.82Canada
CO200.61.136.156Colombia
ES87.235.177.251Spain
ES92.59.73.47Spain
GR109.242.255.105Greece
IN116.73.52.79India
IN117.207.212.230India
IN117.248.69.151India
IN203.192.212.52India
MA41.137.8.47Morocco
MO122.100.153.234Macau
MX187.152.55.53Mexico
MX187.154.254.63Mexico
MX189.248.197.218Mexico
RS89.216.137.247Serbia
TW118.232.161.141Taiwan
US68.188.100.100United States
US69.144.223.99United States
US142.4.9.32United States
UY167.59.92.252Uruguay
UY179.24.67.56Uruguay

Botnet Statistics [2015-08-28]

detection period: 2015-08-28 00:00-23:59 UTC
total number of suspected botnet IPs: 1489
number of botnet IPs notified to network operators: 1464
number of spam blocked: 159778
recipient count of spam blocked: 3463729

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1045
2CHINANET-GD63
3UNICOM-ZJ41
4WASU30
5WASU-BB21
6CHINANET-JS21
7VNPT-VNNIC-VN18
8CHINANET-LN11
9CHINANET-HN11
10CHINANET-SX8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1047
2China268
3Viet Nam37
4Brazil27
5United States15
6Ukraine10
7India7
8Colombia6
9Turkey5
10Russian Federation5

Friday, August 28, 2015

Suspected Bot List [2015-08-27]

detection period: 2015-08-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 25

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR190.104.232.112Argentina
CO200.61.136.156Colombia
DK87.104.133.133Denmark
ES87.235.177.251Spain
IN59.96.230.200India
IN117.205.90.187India
IN117.239.209.6India
IN120.60.83.63India
IN120.63.48.47India
IN122.165.13.29India
IN122.169.10.117India
IN223.225.217.53India
ME178.175.63.95Montenegro
MX148.246.252.4Mexico
MX187.141.107.178Mexico
MX189.196.38.179Mexico
NL178.21.118.159Netherlands
PH124.106.91.6Philippines
RU109.167.136.199Russian Federation
TR46.2.24.236Turkey
TR46.2.43.84Turkey
US74.143.184.254United States
US142.4.9.32United States
US216.56.22.130United States
ZW41.220.28.138Zimbabwe

Botnet Statistics [2015-08-27]

detection period: 2015-08-27 00:00-23:59 UTC
total number of suspected botnet IPs: 1863
number of botnet IPs notified to network operators: 1838
number of spam blocked: 215295
recipient count of spam blocked: 4226018

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1050
2UNICOM-ZJ196
3WASU141
4WASU-BB137
5CHINANET-GD47
6VNPT-VNNIC-VN32
7UNICOM-BJ14
8FPT-VN10
9VIETEL-VNNIC-VN8
10CHINANET-SH8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1051
2China597
3Viet Nam72
4Russian Federation22
5United States20
6Brazil15
7India12
8South Korea7
9Turkey6
10Germany6

Thursday, August 27, 2015

Suspected Bot List [2015-08-26]

detection period: 2015-08-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 31

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.166.170.189Argentina
AR181.167.77.162Argentina
AR186.108.65.14Argentina
AR190.193.168.43Argentina
AR190.246.107.101Argentina
AR190.246.175.125Argentina
BG77.70.114.134Bulgaria
CM197.159.0.70Cameroon
CO200.61.136.156Colombia
DZ41.200.34.177Algeria
DZ197.118.111.215Algeria
EG62.193.78.199Egypt
EG193.227.49.2Egypt
ES87.235.177.251Spain
IN117.216.65.161India
IN117.239.209.6India
IN117.241.205.146India
IN203.192.212.52India
IQ130.193.153.138Iraq
MX177.225.16.236Mexico
MX187.138.11.144Mexico
MX201.164.231.180Mexico
NG41.76.81.150Nigeria
PH49.149.134.222Philippines
PH122.52.127.250Philippines
PH125.212.120.48Philippines
RS89.216.137.247Serbia
TR188.3.195.6Turkey
US142.4.9.32United States
US174.139.218.181United States
US198.1.119.164United States

Botnet Statistics [2015-08-26]

detection period: 2015-08-26 00:00-23:59 UTC
total number of suspected botnet IPs: 1646
number of botnet IPs notified to network operators: 1615
number of spam blocked: 275675
recipient count of spam blocked: 4946610

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1035
2UNICOM-ZJ106
3WASU75
4CHINANET-GD72
5WASU-BB51
6UNICOM-BJ27
7CHINANET-SH14
8VNPT-VNNIC-VN11
9CMNET10
10CHINANET-SC6

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1035
2China425
3Viet Nam27
4Brazil22
5United States19
6Ukraine11
7Russian Federation8
8Hong Kong8
9South Korea7
10India6

Wednesday, August 26, 2015

Suspected Bot List [2015-08-25]

detection period: 2015-08-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 29

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR186.61.63.54Argentina
AR186.137.30.59Argentina
AR190.189.96.103Argentina
BI196.2.15.50Burundi
CN118.67.124.10China
CZ95.46.242.241Czech Republic
EG62.193.78.199Egypt
ES87.235.177.251Spain
IN59.176.38.227India
IN106.192.144.43India
IN106.216.154.85India
IN117.192.248.167India
IN117.199.210.229India
IN117.200.12.230India
IN117.200.182.101India
IN117.205.214.103India
IN117.208.195.96India
IN117.220.32.100India
IN117.244.164.108India
IN122.176.150.174India
IN122.179.87.253India
IN182.68.123.116India
IN202.88.143.249India
MX187.141.107.178Mexico
PK182.186.198.26Pakistan
US63.241.90.5United States
US108.179.196.25United States
US142.4.9.32United States
US192.254.168.98United States

Botnet Statistics [2015-08-25]

detection period: 2015-08-25 00:00-23:59 UTC
total number of suspected botnet IPs: 1961
number of botnet IPs notified to network operators: 1932
number of spam blocked: 275254
recipient count of spam blocked: 4990158

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1042
2WASU209
3UNICOM-ZJ202
4WASU-BB152
5VNPT-VNNIC-VN47
6CHINANET-GD30
7CHINANET-SH12
8UNICOM-BJ11
9CHINANET-HN10
10VIETEL-VN8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1047
2China688
3Viet Nam86
4India19
5Brazil19
6United States17
7Indonesia7
8Turkey6
9South Korea6
10Russian Federation5

Tuesday, August 25, 2015

Suspected Bot List [2015-08-24]

detection period: 2015-08-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 33

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.15.90.37Argentina
AR190.2.36.165Argentina
AR190.18.64.221Argentina
AR190.18.216.130Argentina
AR190.55.90.200Argentina
AR190.138.200.82Argentina
AR190.178.202.43Argentina
AR190.185.134.117Argentina
AR190.189.96.103Argentina
AR190.191.23.11Argentina
AR201.212.66.197Argentina
CN116.228.70.205China
CN118.67.124.10China
DE84.59.235.86Germany
EC200.25.220.42Ecuador
GB94.15.118.153United Kingdom
HN201.190.8.194Honduras
IN59.88.251.73India
IN115.99.97.240India
IN117.208.61.89India
IN117.223.8.105India
IN120.57.194.42India
IN122.167.69.121India
IN180.87.255.225India
LK175.157.161.203Sri Lanka
PK182.185.38.126Pakistan
RS87.250.40.5Serbia
TR5.46.168.46Turkey
US71.81.171.135United States
US108.179.196.25United States
US142.4.9.32United States
US184.167.56.70United States
US192.254.168.98United States

Botnet Statistics [2015-08-24]

detection period: 2015-08-24 00:00-23:59 UTC
total number of suspected botnet IPs: 1937
number of botnet IPs notified to network operators: 1904
number of spam blocked: 233450
recipient count of spam blocked: 5125525

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1097
2UNICOM-ZJ178
3WASU125
4WASU-BB100
5VNPT-VNNIC-VN59
6CHINANET-GD30
7UNICOM-BJ14
8FPT-VN14
9CHINANET-SH11
10VIETEL-VNNIC-VN8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1106
2China528
3Viet Nam106
4Brazil27
5United States16
6Ukraine15
7Indonesia12
8Argentina12
9Kazakhstan10
10India10

Monday, August 24, 2015

Suspected Bot List [2015-08-23]

detection period: 2015-08-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 12

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR201.231.200.54Argentina
AR201.251.32.192Argentina
BG89.253.147.105Bulgaria
IN59.99.84.12India
IN59.182.88.156India
IN59.183.32.192India
IN117.240.80.203India
MX189.172.159.244Mexico
MX201.122.75.8Mexico
RO92.83.241.189Romania
SV201.247.149.77El Salvador
US142.4.9.32United States

Botnet Statistics [2015-08-23]

detection period: 2015-08-23 00:00-23:59 UTC
total number of suspected botnet IPs: 1434
number of botnet IPs notified to network operators: 1422
number of spam blocked: 127591
recipient count of spam blocked: 3667769

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1099
2WASU62
3WASU-BB39
4VNPT-VNNIC-VN26
5CHINANET-GD26
6CHINANET-ZJ-HZ13
7VIETEL-VN11
8FPT-VN11
9UNICOM-BJ10
10CMNET6

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1100
2China211
3Viet Nam57
4United States17
5Ukraine4
6India4
7Germany4
8Turkey3
9Russian Federation3
10United Kingdom3

Sunday, August 23, 2015

Suspected Bot List [2015-08-22]

detection period: 2015-08-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 29

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.116.199.182Argentina
AR181.166.208.96Argentina
AR190.193.37.220Argentina
AZ91.135.253.48Azerbaijan
CN58.18.133.102China
CZ88.101.126.86Czech Republic
EG62.193.78.199Egypt
IN61.3.72.185India
IN117.192.27.231India
IN117.208.97.50India
IN117.244.102.31India
IN117.247.121.206India
IN122.169.86.62India
IN122.170.58.30India
IN122.176.169.35India
IN182.64.36.142India
IN202.157.80.87India
IN223.176.29.98India
LK175.157.43.2Sri Lanka
MA41.137.19.3Morocco
MX187.154.93.237Mexico
MX189.174.66.186Mexico
SV201.247.149.77El Salvador
US108.167.184.103United States
US108.179.196.25United States
US148.73.106.17United States
US184.167.56.70United States
US192.254.168.98United States
US216.172.191.42United States

Botnet Statistics [2015-08-22]

detection period: 2015-08-22 00:00-23:59 UTC
total number of suspected botnet IPs: 1335
number of botnet IPs notified to network operators: 1306
number of spam blocked: 191172
recipient count of spam blocked: 3687606

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1048
2VNPT-VNNIC-VN29
3CHINANET-GD19
4UNICOM-BJ11
5CHINANET-SH9
6VIETEL-VNNIC-VN8
7VIETEL-VN7
8CHINANET-JS5
9BSNLNET5
10CHINANET-HB4

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1052
2China92
3Viet Nam51
4Brazil19
5United States17
6Russian Federation16
7India14
8Ukraine9
9Turkey5
10Tunisia3

Saturday, August 22, 2015

Suspected Bot List [2015-08-21]

detection period: 2015-08-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 21

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
JO212.35.67.169Jordan

List from greylisting:

country codeIP addressCountry
AR179.37.225.226Argentina
AR181.25.218.87Argentina
AR186.134.43.6Argentina
AR190.175.55.96Argentina
CM197.159.0.70Cameroon
CN116.228.70.205China
CN118.67.124.10China
DZ41.200.233.128Algeria
DZ105.104.16.178Algeria
ES88.23.116.14Spain
ID103.7.226.51Indonesia
IN59.93.5.43India
IN120.60.232.221India
IN120.63.224.105India
IN182.69.9.129India
IN203.192.212.52India
MX189.133.21.118Mexico
MX200.56.21.161Mexico
PH119.92.184.82Philippines
SV201.247.149.77El Salvador

Botnet Statistics [2015-08-21]

detection period: 2015-08-21 00:00-23:59 UTC
total number of suspected botnet IPs: 1481
number of botnet IPs notified to network operators: 1460
number of spam blocked: 137302
recipient count of spam blocked: 3608253

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1066
2WASU61
3WASU-BB55
4UNICOM-ZJ41
5CHINANET-GD30
6UNICOM-BJ14
7CMNET8
8CHINANET-HN8
9VNPT-VNNIC-VN7
10CHINANET-SH5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1071
2China279
3United States21
4Viet Nam16
5Brazil13
6Ukraine7
7Russian Federation7
8India7
9Argentina5
10Turkey4

Friday, August 21, 2015

Suspected Bot List [2015-08-20]

detection period: 2015-08-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 23

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.166.228.175Argentina
AR190.52.34.132Argentina
CM197.159.0.70Cameroon
DZ197.117.51.170Algeria
ES80.58.158.116Spain
IN117.194.136.190India
IN117.196.52.247India
IN117.196.189.118India
IN117.199.79.16India
IN117.203.241.116India
IN122.170.87.144India
IN122.170.110.14India
IN123.201.196.220India
IN182.72.139.50India
MX189.153.182.123Mexico
MX189.196.132.38Mexico
NL178.21.118.159Netherlands
PK39.55.166.204Pakistan
US71.85.233.108United States
US108.167.184.103United States
US108.179.196.25United States
US192.254.168.98United States
US216.172.191.42United States

Botnet Statistics [2015-08-20]

detection period: 2015-08-20 00:00-23:59 UTC
total number of suspected botnet IPs: 1681
number of botnet IPs notified to network operators: 1658
number of spam blocked: 124501
recipient count of spam blocked: 3592248

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1035
2WASU137
3WASU-BB108
4UNICOM-ZJ98
5CHINANET-GD35
6UNICOM-BJ28
7CHINANET-SH9
8CHINANET-HN8
9VNPT-VNNIC-VN7
10CMNET7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1038
2China488
3United States27
4Brazil23
5Viet Nam18
6India13
7South Korea6
8Hong Kong5
9Ukraine4
10Turkey4

Thursday, August 20, 2015

Suspected Bot List [2015-08-19]

detection period: 2015-08-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 10

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR190.104.232.112Argentina
CN58.18.133.102China
EC181.112.150.242Ecuador
MX187.178.135.66Mexico
NL178.21.118.159Netherlands
TR188.3.108.24Turkey
US142.4.14.6United States
US142.4.20.46United States
US162.144.104.214United States
US184.167.56.70United States

Botnet Statistics [2015-08-19]

detection period: 2015-08-19 00:00-23:59 UTC
total number of suspected botnet IPs: 1595
number of botnet IPs notified to network operators: 1585
number of spam blocked: 130151
recipient count of spam blocked: 3717691

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1063
2WASU110
3UNICOM-ZJ99
4WASU-BB82
5CHINANET-GD44
6UNICOM-BJ24
7CMNET9
8CHINANET-SH8
9CHINANET-HN8
10CHINANET-SC7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1064
2China454
3United States19
4Brazil9
5Hong Kong8
6Viet Nam4
7United Kingdom4
8Turkey3
9Russian Federation3
10Indonesia2

Wednesday, August 19, 2015

Suspected Bot List [2015-08-18]

detection period: 2015-08-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 11

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR200.41.235.117Argentina
CA184.107.204.82Canada
CO190.90.21.237Colombia
IN27.5.133.112India
IN116.75.21.18India
IN122.170.105.219India
MA41.137.19.3Morocco
NL178.21.118.159Netherlands
US142.4.20.46United States
US157.55.234.252United States
US184.167.56.70United States

Botnet Statistics [2015-08-18]

detection period: 2015-08-18 00:00-23:59 UTC
total number of suspected botnet IPs: 1717
number of botnet IPs notified to network operators: 1706
number of spam blocked: 108466
recipient count of spam blocked: 3184012

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1038
2UNICOM-ZJ221
3WASU170
4WASU-BB97
5CHINANET-GD24
6UNICOM-BJ7
7CMNET7
8CHINANET-SH5
9CHINANET-JX5
10CHINANET-JS5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1040
2China591
3United States18
4Brazil11
5Netherlands5
6India5
7Hong Kong5
8Viet Nam3
9Russian Federation3
10South Korea3

Tuesday, August 18, 2015

Suspected Bot List [2015-08-17]

detection period: 2015-08-17 00:00-23:59 UTC
number of suspected bots' IPs listed here: 13

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR186.39.252.174Argentina
AR186.134.154.236Argentina
AR190.172.20.120Argentina
AR200.50.187.57Argentina
AR200.123.137.253Argentina
EG193.227.49.83Egypt
IN117.197.69.157India
IN223.223.151.19India
MA41.137.19.3Morocco
NL178.21.118.159Netherlands
SV201.247.149.77El Salvador
TW118.232.161.141Taiwan
US69.144.223.99United States

Botnet Statistics [2015-08-17]

detection period: 2015-08-17 00:00-23:59 UTC
total number of suspected botnet IPs: 1886
number of botnet IPs notified to network operators: 1873
number of spam blocked: 105233
recipient count of spam blocked: 3090807

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1061
2UNICOM-ZJ296
3WASU172
4WASU-BB121
5CHINANET-GD25
6VNPT-VNNIC-VN21
7033.530.486/0001-297
8CMNET6
9CHINANET-SH6
10CHINANET-SC5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1063
2China671
3Viet Nam30
4Brazil23
5United States20
6Russian Federation13
7India6
8Indonesia6
9Argentina5
10Turkey4

Monday, August 17, 2015

Suspected Bot List [2015-08-16]

detection period: 2015-08-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 22

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR186.134.16.207Argentina
AR186.158.253.220Argentina
AR190.185.134.117Argentina
EC181.112.150.242Ecuador
IN117.211.21.254India
IN117.220.2.8India
IN125.16.12.146India
IN202.142.104.170India
IN203.192.212.52India
MX189.200.70.94Mexico
NL178.21.118.159Netherlands
PH119.93.84.146Philippines
RS79.175.81.151Serbia
SV201.247.149.77El Salvador
US65.55.169.250United States
US69.144.223.99United States
US157.56.110.253United States
US157.56.111.250United States
US162.144.104.214United States
US207.46.100.249United States
UY167.59.79.214Uruguay
VN220.231.127.15Viet Nam

Botnet Statistics [2015-08-16]

detection period: 2015-08-16 00:00-23:59 UTC
total number of suspected botnet IPs: 1631
number of botnet IPs notified to network operators: 1609
number of spam blocked: 118298
recipient count of spam blocked: 3386915

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1083
2UNICOM-ZJ125
3WASU83
4WASU-BB49
5VNPT-VNNIC-VN38
6CHINANET-GD24
7CMNET8
8VIETEL-VNNIC-VN7
9FPT-VN7
10ETC-VNNIC-VN7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1088
2China330
3Viet Nam70
4Brazil32
5United States18
6India10
7Indonesia10
8Russian Federation8
9Thailand5
10Ukraine4

Sunday, August 16, 2015

Suspected Bot List [2015-08-15]

detection period: 2015-08-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 20

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR24.232.83.179Argentina
AR190.182.141.143Argentina
AR190.188.188.50Argentina
AR200.50.187.57Argentina
AZ91.135.246.130Azerbaijan
BG89.253.150.31Bulgaria
CM197.159.0.70Cameroon
CZ88.101.126.86Czech Republic
DZ197.119.243.76Algeria
EC181.112.150.242Ecuador
IN117.199.218.123India
IN117.222.171.246India
IN202.157.80.87India
IN203.192.212.52India
IQ109.127.103.63Iraq
MA41.137.19.3Morocco
NL178.21.118.159Netherlands
US162.144.104.214United States
UY167.61.81.181Uruguay
VE200.47.79.209Venezuela

Botnet Statistics [2015-08-15]

detection period: 2015-08-15 00:00-23:59 UTC
total number of suspected botnet IPs: 1349
number of botnet IPs notified to network operators: 1329
number of spam blocked: 135116
recipient count of spam blocked: 3631598

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1057
2UNICOM-ZJ32
3VNPT-VNNIC-VN22
4CHINANET-GD21
5FPT-VN11
6ETC-VNNIC-VN8
7003.420.926/0002-057
8VIETEL-VN5
9UNICOM-GD4
10CHINANET-SH4

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1061
2China100
3Viet Nam53
4Brazil29
5United States15
6Russian Federation8
7Ukraine7
8India7
9Poland5
10South Korea5

Saturday, August 15, 2015

Suspected Bot List [2015-08-14]

detection period: 2015-08-14 00:00-23:59 UTC
number of suspected bots' IPs listed here: 18

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.166.133.77Argentina
AR200.50.187.57Argentina
AR200.69.195.58Argentina
AR201.235.198.21Argentina
CM197.159.0.70Cameroon
IN59.88.109.200India
IN117.200.167.242India
IN117.203.188.216India
IN117.212.155.43India
IN122.174.97.115India
IN202.62.65.161India
IN203.192.212.52India
KZ2.132.97.168Kazakhstan
MX189.204.110.93Mexico
RS89.216.117.65Serbia
US162.144.34.28United States
US162.144.104.214United States
ZA105.210.43.31South Africa

Botnet Statistics [2015-08-14]

detection period: 2015-08-14 00:00-23:59 UTC
total number of suspected botnet IPs: 1623
number of botnet IPs notified to network operators: 1605
number of spam blocked: 149338
recipient count of spam blocked: 3930598

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1020
2WASU99
3UNICOM-ZJ91
4WASU-BB77
5VNPT-VNNIC-VN56
6CHINANET-GD24
7VIETEL-VNNIC-VN15
8FPT-VN10
9VIETEL-VN9
10UNICOM-BJ9

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1025
2China338
3Viet Nam106
4United States25
5Brazil24
6India15
7Russian Federation12
8Ukraine9
9Kazakhstan7
10Indonesia7

Friday, August 14, 2015

Suspected Bot List [2015-08-13]

detection period: 2015-08-13 00:00-23:59 UTC
number of suspected bots' IPs listed here: 77

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2015-08-13]

detection period: 2015-08-13 00:00-23:59 UTC
total number of suspected botnet IPs: 2275
number of botnet IPs notified to network operators: 2198
number of spam blocked: 183880
recipient count of spam blocked: 4532992

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1083
2UNICOM-ZJ162
3WASU151
4WASU-BB136
5VNPT-VNNIC-VN115
6CHINANET-GD46
7ETC-VNNIC-VN25
8VIETEL-VN24
9FPT-VN22
10VIETEL-VNNIC-VN17

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1088
2China576
3Viet Nam239
4Brazil50
5India42
6United States34
7Ukraine32
8Russian Federation26
9Kazakhstan21
10Turkey20

Thursday, August 13, 2015

Suspected Bot List [2015-08-12]

detection period: 2015-08-12 00:00-23:59 UTC
number of suspected bots' IPs listed here: 24

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2015-08-12]

detection period: 2015-08-12 00:00-23:59 UTC
total number of suspected botnet IPs: 1737
number of botnet IPs notified to network operators: 1713
number of spam blocked: 115140
recipient count of spam blocked: 3420690

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1068
2UNICOM-ZJ167
3WASU92
4WASU-BB81
5CHINANET-GD39
6VNPT-VNNIC-VN18
7UNICOM-SD18
8CHINANET-JS17
9UNICOM-BJ14
10CMNET10

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1071
2China479
3Viet Nam41
4Brazil23
5United States18
6India11
7Russian Federation9
8Ukraine8
9Netherlands5
10Indonesia5

Wednesday, August 12, 2015

Suspected Bots' IP List for August 2015

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here (as shown below) 10 days after its respective botnet statistics gets published.

New data will be added here daily. You are free to use them to create more effective defenses, discover latest trends in cyber attacks, etc.

Suspected Bots IP [2015-08-31]
Suspected Bots IP [2015-08-30]
Suspected Bots IP [2015-08-29]
Suspected Bots IP [2015-08-28]
Suspected Bots IP [2015-08-27]
Suspected Bots IP [2015-08-26]
Suspected Bots IP [2015-08-25]
Suspected Bots IP [2015-08-24]
Suspected Bots IP [2015-08-23]
Suspected Bots IP [2015-08-22]
Suspected Bots IP [2015-08-21]
Suspected Bots IP [2015-08-20]
Suspected Bots IP [2015-08-19]
Suspected Bots IP [2015-08-18]
Suspected Bots IP [2015-08-17]
Suspected Bots IP [2015-08-16]
Suspected Bots IP [2015-08-15]
Suspected Bots IP [2015-08-14]
Suspected Bots IP [2015-08-13]
Suspected Bots IP [2015-08-12]
Suspected Bots IP [2015-08-11]
Suspected Bots IP [2015-08-10]
Suspected Bots IP [2015-08-09]
Suspected Bots IP [2015-08-08]
Suspected Bots IP [2015-08-06]
Suspected Bots IP [2015-08-05]
Suspected Bots IP [2015-08-04]
Suspected Bots IP [2015-08-03]
Suspected Bots IP [2015-08-02]
Suspected Bots IP [2015-08-01]

Suspected Bot List [2015-08-11]

detection period: 2015-08-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 39

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2015-08-11]

detection period: 2015-08-11 00:00-23:59 UTC
total number of suspected botnet IPs: 1920
number of botnet IPs notified to network operators: 1881
number of spam blocked: 108621
recipient count of spam blocked: 3217412

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1047
2UNICOM-ZJ165
3WASU134
4WASU-BB94
5VNPT-VNNIC-VN61
6CHINANET-GD24
7FPT-VN23
8CHINANET-ZJ-HZ13
9CHINANET-JS13
10UNICOM-SD12

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1051
2China524
3Viet Nam133
4Brazil30
5United States25
6India21
7Ukraine12
8Russian Federation12
9Indonesia8
10Argentina8

Tuesday, August 11, 2015

Suspected Bot List [2015-08-10]

detection period: 2015-08-10 00:00-23:59 UTC
number of suspected bots' IPs listed here: 53

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2015-08-10]

detection period: 2015-08-10 00:00-23:59 UTC
total number of suspected botnet IPs: 1952
number of botnet IPs notified to network operators: 1899
number of spam blocked: 107636
recipient count of spam blocked: 3199418

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET999
2UNICOM-ZJ112
3WASU109
4VNPT-VNNIC-VN95
5WASU-BB93
6CHINANET-GD48
7VIETEL-VN20
8FPT-VN20
9CHINANET-JS17
10VIETEL-VNNIC-VN16

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1003
2China464
3Viet Nam176
4Brazil38
5India30
6United States28
7Ukraine27
8Russian Federation18
9Turkey13
10Kazakhstan12

Monday, August 10, 2015

Suspected Bot List [2015-08-09]

detection period: 2015-08-09 00:00-23:59 UTC
number of suspected bots' IPs listed here: 14

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2015-08-09]

detection period: 2015-08-09 00:00-23:59 UTC
total number of suspected botnet IPs: 1429
number of botnet IPs notified to network operators: 1415
number of spam blocked: 106335
recipient count of spam blocked: 3105017

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET988
2UNICOM-ZJ105
3WASU59
4WASU-BB52
5CHINANET-GD29
6VNPT-VNNIC-VN10
7CHINANET-ZJ-HZ10
8UNICOM-BJ8
9CHINANET-JS5
10ETC-VNNIC-VN4

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan990
2China312
3United States21
4Viet Nam20
5Brazil16
6Ukraine7
7Indonesia6
8Hong Kong4
9Colombia4
10Russian Federation3

Sunday, August 9, 2015

Suspected Bot List [2015-08-08]

detection period: 2015-08-08 00:00-23:59 UTC
number of suspected bots' IPs listed here: 9

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2015-08-08]

detection period: 2015-08-08 00:00-23:59 UTC
total number of suspected botnet IPs: 698
number of botnet IPs notified to network operators: 689
number of spam blocked: 55346
recipient count of spam blocked: 1369405

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET444
2CHINANET-GD34
3CHINANET-JS12
4UNICOM-BJ11
5CHINANET-ZJ-HZ11
6VNPT-VNNIC-VN7
7GIANT5
8DIGITALOCEAN-114
9002.558.157/0001-624
10UNICOM-SD3

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan445
2China109
3United States36
4Brazil20
5Russian Federation17
6Viet Nam13
7Ukraine5
8Thailand4
9South Korea4
10Colombia4

Saturday, August 8, 2015

Suspected Bot List [2015-08-07]

detection period: 2015-08-07 00:00-23:59 UTC
number of suspected bots' IPs listed here: 19

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2015-08-07]

detection period: 2015-08-07 00:00-23:59 UTC
total number of suspected botnet IPs: 1396
number of botnet IPs notified to network operators: 1377
number of spam blocked: 104108
recipient count of spam blocked: 2698821

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET921
2UNICOM-ZJ66
3WASU-BB59
4WASU57
5UNICOM-BJ30
6CHINANET-GD30
7UNICOM-SD17
8UNICOM-HB13
9CHINANET-JS12
10CHINANET-HB9

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan922
2China349
3United States34
4Brazil23
5Russian Federation9
6South Korea7
7India6
8Japan5
9Indonesia4
10Spain4