Custom Search

Wednesday, September 30, 2015

Suspected Bot List [2015-09-29]

detection period: 2015-09-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 16

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR190.172.10.95Argentina
CN202.142.16.70China
DZ105.109.96.4Algeria
ES87.235.177.251Spain
ID116.90.165.12Indonesia
ID118.82.14.254Indonesia
IN112.133.214.251India
IN117.203.240.108India
IN122.168.63.21India
KZ176.223.75.80Kazakhstan
MR41.188.89.38Mauritania
MX177.242.235.67Mexico
MX189.202.66.43Mexico
MX189.220.197.249Mexico
PH124.107.173.16Philippines
TR213.248.168.22Turkey

Botnet Statistics [2015-09-29]

detection period: 2015-09-29 00:00-23:59 UTC
total number of suspected botnet IPs: 1850
number of botnet IPs notified to network operators: 1834
number of spam blocked: 187122
recipient count of spam blocked: 2463897

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET906
2UNICOM-AH355
3CHINANET-HB197
4CHINANET-GD58
5VNPT-VNNIC-VN41
6UNICOM-GD16
7CHINANET-JS16
8CHINANET-HN16
9UNICOM-BJ13
10CHINANET-SX12

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan909
2China762
3Viet Nam75
4United States21
5Brazil12
6India8
7Germany7
8Russian Federation4
9Mexico4
10France4

Tuesday, September 29, 2015

Suspected Bot List [2015-09-28]

detection period: 2015-09-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 35

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR131.100.182.194Argentina
AR181.27.131.219Argentina
AR190.14.157.161Argentina
AR190.179.184.217Argentina
AR190.182.133.40Argentina
CO190.7.134.170Colombia
DZ197.118.50.105Algeria
EG81.10.34.107Egypt
ES87.235.177.251Spain
HN181.210.32.24Honduras
ID103.30.87.85Indonesia
ID150.107.248.146Indonesia
ID203.160.62.90Indonesia
ID203.176.183.170Indonesia
IL94.159.252.174Israel
IN27.4.229.230India
IN59.98.100.193India
IN117.194.113.98India
IN117.241.231.0India
IN122.161.204.235India
IN122.162.242.61India
IN122.169.180.133India
IN125.16.18.69India
KZ5.34.51.113Kazakhstan
KZ92.46.10.218Kazakhstan
MA212.217.2.8Morocco
MX177.239.123.142Mexico
MX187.172.157.239Mexico
MX201.152.8.55Mexico
PK39.54.28.142Pakistan
RO92.82.17.228Romania
TW180.176.90.119Taiwan
US192.232.192.251United States
US216.172.166.181United States
UY167.59.48.150Uruguay

Botnet Statistics [2015-09-28]

detection period: 2015-09-28 00:00-23:59 UTC
total number of suspected botnet IPs: 1845
number of botnet IPs notified to network operators: 1810
number of spam blocked: 200682
recipient count of spam blocked: 2721255

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET692
2UNICOM-AH428
3CHINANET-HB224
4CHINANET-SD73
5VNPT-VNNIC-VN51
6CHINANET-GD49
7CHINANET-HN14
8CHINANET-SX12
9CHINANET-SN11
10CHINANET-HA11

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China905
2Taiwan695
3Viet Nam93
4Russian Federation14
5India14
6United States13
7Turkey11
8Ukraine8
9Israel6
10Indonesia6

Monday, September 28, 2015

Suspected Bot List [2015-09-27]

detection period: 2015-09-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 21

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.169.118.105Argentina
AR186.59.8.163Argentina
AR190.247.186.10Argentina
AR200.50.178.128Argentina
IL94.159.252.174Israel
IN112.133.229.11India
IN117.222.172.89India
IN202.91.75.179India
MA212.217.2.8Morocco
MX187.156.141.67Mexico
MX187.233.251.179Mexico
MX189.199.78.35Mexico
PK39.32.48.93Pakistan
RO109.101.87.247Romania
RS188.2.108.26Serbia
US74.129.170.198United States
US104.47.124.249United States
US104.47.126.241United States
UY167.59.2.245Uruguay
UY167.59.38.166Uruguay
UY186.48.39.229Uruguay

Botnet Statistics [2015-09-27]

detection period: 2015-09-27 00:00-23:59 UTC
total number of suspected botnet IPs: 2575
number of botnet IPs notified to network operators: 2554
number of spam blocked: 258376
recipient count of spam blocked: 3500912

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1048
2UNICOM-AH458
3CHINANET-HB357
4CHINANET-SD100
5CHINANET-GD92
6CHINANET-JS55
7CHINANET-SX52
8CHINANET-HN46
9CHINANET-LN36
10CHINANET-SN32

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1347
2Taiwan1050
3Viet Nam48
4Brazil22
5United States21
6Ukraine13
7Romania5
8Mexico4
9India4
10Germany4

Sunday, September 27, 2015

Suspected Bot List [2015-09-26]

detection period: 2015-09-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 15

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR168.96.200.193Argentina
AR186.138.182.141Argentina
IL94.159.252.174Israel
IN117.244.15.243India
IN223.187.62.127India
IQ109.127.78.25Iraq
MA212.217.2.8Morocco
MX187.237.90.170Mexico
MX189.142.81.162Mexico
NL185.77.128.173Netherlands
RO92.83.241.189Romania
RO109.96.255.110Romania
UA31.41.109.52Ukraine
US68.188.100.102United States
UY186.49.228.40Uruguay

Botnet Statistics [2015-09-26]

detection period: 2015-09-26 00:00-23:59 UTC
total number of suspected botnet IPs: 2585
number of botnet IPs notified to network operators: 2570
number of spam blocked: 171127
recipient count of spam blocked: 3774793

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1066
2CHINANET-HB429
3UNICOM-AH338
4CHINANET-GD164
5CHINANET-SD103
6CHINANET-JS76
7CHINANET-HN40
8CHINANET-YN34
9CHINANET-SN32
10CHINANET-SX29

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1379
2Taiwan1068
3Viet Nam34
4United States19
5Brazil12
6India7
7Ukraine6
8Turkey6
9Germany5
10Russian Federation4

Saturday, September 26, 2015

Suspected Bot List [2015-09-25]

detection period: 2015-09-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 32

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
ID202.62.10.210Indonesia
IN122.170.105.219India
IN125.16.12.146India
IN182.72.139.50India
IN203.194.109.130India
MX148.204.139.170Mexico
MX200.94.75.210Mexico
PT93.102.80.52Portugal
US68.188.100.102United States
US198.144.189.149United States

List from greylisting:

country codeIP addressCountry
AR181.25.151.148Argentina
AR181.166.65.175Argentina
AR186.135.140.206Argentina
AR190.50.191.233Argentina
AR190.179.170.153Argentina
AR200.50.178.128Argentina
AR200.89.154.99Argentina
DE80.69.98.247Germany
EC200.107.60.50Ecuador
ES87.235.177.251Spain
IL94.159.252.174Israel
IN117.202.28.36India
IN122.160.45.203India
IN203.194.109.142India
KZ87.243.52.159Kazakhstan
NL185.77.128.173Netherlands
PK39.45.115.119Pakistan
RO92.80.104.139Romania
US68.188.100.102United States
US74.129.170.198United States
US216.172.166.181United States
UY167.59.100.251Uruguay

Botnet Statistics [2015-09-25]

detection period: 2015-09-25 00:00-23:59 UTC
total number of suspected botnet IPs: 2704
number of botnet IPs notified to network operators: 2673
number of spam blocked: 168521
recipient count of spam blocked: 3456747

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1020
2CHINANET-HB302
3CHINANET-GD266
4UNICOM-AH251
5CHINANET-JS129
6CHINANET-HN82
7CHINANET-SX77
8CHINANET-LN65
9CHINANET-SD57
10CHINANET-YN45

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1479
2Taiwan1022
3Viet Nam48
4Brazil25
5United States17
6Russian Federation12
7India11
8Ukraine10
9Argentina8
10Indonesia5

Friday, September 25, 2015

Suspected Bot List [2015-09-24]

detection period: 2015-09-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 26

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR200.50.178.128Argentina
DE80.69.98.251Germany
ES80.58.152.176Spain
ES87.235.177.251Spain
IL94.159.252.174Israel
IN59.88.76.238India
IN59.177.243.228India
IN106.216.140.26India
IN117.196.173.220India
IN117.202.184.11India
IN117.207.83.44India
IN120.61.52.183India
IN122.170.3.7India
IN122.174.213.111India
IN122.175.34.148India
IN182.65.173.13India
KZ2.132.21.48Kazakhstan
KZ2.132.94.169Kazakhstan
MA212.217.2.8Morocco
MX148.204.139.170Mexico
NL185.77.128.173Netherlands
PH122.52.15.249Philippines
RO89.123.234.145Romania
RO109.97.31.206Romania
US216.172.166.181United States
UY167.61.22.176Uruguay

Botnet Statistics [2015-09-24]

detection period: 2015-09-24 00:00-23:59 UTC
total number of suspected botnet IPs: 2791
number of botnet IPs notified to network operators: 2765
number of spam blocked: 163560
recipient count of spam blocked: 3758941

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1081
2UNICOM-AH349
3CHINANET-HB336
4CHINANET-GD169
5CHINANET-JS107
6CHINANET-SX88
7CHINANET-HN65
8CHINANET-SN64
9CHINANET-YN62
10CHINANET-LN57

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1475
2Taiwan1084
3Viet Nam74
4Russian Federation24
5United States20
6India20
7Brazil16
8Germany6
9Ukraine5
10Turkey5

Thursday, September 24, 2015

Suspected Bot List [2015-09-23]

detection period: 2015-09-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 40

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR186.39.184.224Argentina
AR201.251.32.192Argentina
AZ95.86.176.180Azerbaijan
DE80.69.98.247Germany
ES87.235.177.251Spain
IN59.96.183.177India
IN101.0.45.44India
IN117.192.4.47India
IN117.201.50.162India
IN117.201.113.110India
IN117.205.150.245India
IN117.222.219.116India
IN122.169.33.45India
IN122.175.34.148India
IN122.175.238.27India
IN150.107.197.67India
IN182.65.170.217India
IT62.19.220.151Italy
KZ185.48.150.234Kazakhstan
KZ213.157.45.74Kazakhstan
MX187.139.95.250Mexico
RO89.122.117.53Romania
RO89.123.181.248Romania
RO109.98.164.51Romania
UA89.252.29.9Ukraine
US104.47.124.228United States
US104.47.124.248United States
US104.47.124.249United States
US104.47.125.212United States
US104.47.125.218United States
US104.47.126.202United States
US104.47.126.207United States
US104.47.126.212United States
US104.47.126.218United States
US104.47.126.230United States
US192.232.192.251United States
US192.254.137.244United States
US198.57.180.170United States
US216.172.166.181United States
UY167.60.122.58Uruguay

Botnet Statistics [2015-09-23]

detection period: 2015-09-23 00:00-23:59 UTC
total number of suspected botnet IPs: 2788
number of botnet IPs notified to network operators: 2748
number of spam blocked: 140568
recipient count of spam blocked: 3631976

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1071
2UNICOM-AH282
3CHINANET-HB280
4CHINANET-GD192
5CHINANET-YN156
6CHINANET-LN91
7CHINANET-JS88
8CHINANET-SX83
9CHINANET-SN69
10CHINANET-HN65

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1483
2Taiwan1073
3Viet Nam102
4United States32
5India17
6Ukraine14
7Russian Federation11
8Turkey6
9Romania6
10Germany6

Wednesday, September 23, 2015

Suspected Bot List [2015-09-22]

detection period: 2015-09-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 31

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.23.41.233Argentina
AR181.23.172.22Argentina
AR186.130.197.13Argentina
AR190.18.248.33Argentina
AR190.31.106.219Argentina
AR190.174.67.158Argentina
AR190.176.71.135Argentina
AR191.80.141.88Argentina
DZ105.102.33.129Algeria
DZ196.20.105.114Algeria
EC200.125.239.214Ecuador
ES87.235.177.251Spain
IN14.140.235.82India
IN61.3.230.33India
IN117.193.151.67India
IN117.239.77.69India
IN117.242.76.242India
IN122.165.232.120India
IN122.168.240.6India
IN122.171.189.162India
IN150.107.9.244India
IN182.73.204.74India
IN219.64.166.110India
MO27.109.167.33Macau
MX189.147.125.237Mexico
MX200.36.121.217Mexico
PH110.55.5.226Philippines
PK39.35.61.23Pakistan
US192.254.137.244United States
US198.57.180.170United States
US216.172.166.181United States

Botnet Statistics [2015-09-22]

detection period: 2015-09-22 00:00-23:59 UTC
total number of suspected botnet IPs: 3219
number of botnet IPs notified to network operators: 3188
number of spam blocked: 132096
recipient count of spam blocked: 3479792

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1080
2CHINANET-HB485
3UNICOM-AH382
4CHINANET-GD183
5CHINANET-YN129
6CHINANET-SD97
7CHINANET-JS93
8CHINANET-LN79
9CHINANET-SN68
10CHINANET-HN65

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1865
2Taiwan1086
3Viet Nam74
4Russian Federation28
5India25
6Brazil24
7United States16
8Ukraine15
9Turkey8
10Argentina8

Tuesday, September 22, 2015

Suspected Bot List [2015-09-21]

detection period: 2015-09-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 36

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR24.232.43.7Argentina
AR168.96.200.193Argentina
AR179.40.166.73Argentina
AR181.29.138.211Argentina
AR186.128.98.42Argentina
AR186.137.98.91Argentina
AR190.55.193.71Argentina
AR190.188.42.217Argentina
AR190.188.123.168Argentina
AR200.41.192.90Argentina
AR201.219.161.225Argentina
AR201.231.104.164Argentina
IL31.154.162.243Israel
IN116.73.51.36India
IN117.194.16.25India
IN117.195.232.6India
IN117.201.79.35India
IN117.206.64.11India
IN117.212.7.198India
IN117.218.4.210India
IN117.247.12.11India
IN122.168.214.128India
IN182.64.168.49India
IN210.212.230.132India
LT188.69.195.157Lithuania
MX187.143.85.46Mexico
MX187.156.214.57Mexico
MX189.196.132.254Mexico
MX189.236.231.128Mexico
NL185.77.128.173Netherlands
RS185.22.90.88Serbia
US65.55.169.248United States
US65.55.169.253United States
US66.56.184.232United States
US157.56.110.245United States
US157.56.111.248United States

Botnet Statistics [2015-09-21]

detection period: 2015-09-21 00:00-23:59 UTC
total number of suspected botnet IPs: 3654
number of botnet IPs notified to network operators: 3618
number of spam blocked: 123801
recipient count of spam blocked: 3447137

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1042
2CHINANET-HB415
3UNICOM-AH340
4CHINANET-GD273
5CHINANET-YN216
6CHINANET-JS189
7CHINANET-SX149
8CHINANET-SD134
9CHINANET-HN123
10CHINANET-SN122

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2375
2Taiwan1045
3Viet Nam77
4India20
5Russian Federation18
6Brazil14
7Ukraine13
8Argentina12
9United States11
10Turkey5

Monday, September 21, 2015

Suspected Bot List [2015-09-20]

detection period: 2015-09-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 42

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
US198.144.189.140United States

List from greylisting:

country codeIP addressCountry
AL79.106.109.181Albania
AM5.77.236.222Armenia
AM46.241.228.250Armenia
AR24.232.195.202Argentina
AR181.23.142.113Argentina
AR186.0.193.130Argentina
AR186.0.193.246Argentina
AR186.61.92.246Argentina
AR186.62.4.212Argentina
AR190.96.113.10Argentina
AR190.183.60.117Argentina
AR200.43.231.13Argentina
AZ5.178.5.236Azerbaijan
BH62.209.14.213Bahrain
BR187.108.174.76Brazil
GB91.109.13.254United Kingdom
GE95.137.166.63Republic Of Georgia
GR109.242.71.24Greece
GT190.4.29.89Guatemala
ID103.10.105.60Indonesia
IN117.193.214.152India
IN117.204.14.235India
IN117.241.120.94India
IN120.62.196.37India
IN122.163.218.90India
IN122.168.57.45India
IR5.200.68.118Iran
IR188.245.205.11Iran
JO87.236.233.98Jordan
LB185.99.32.2Lebanon
MX177.236.37.119Mexico
MX177.241.3.176Mexico
MX187.153.61.103Mexico
MX187.212.192.21Mexico
MX189.170.23.236Mexico
MX189.176.132.225Mexico
MY123.136.107.100Malaysia
NL185.77.128.173Netherlands
PL193.105.125.117Poland
UA91.219.83.133Ukraine
US207.242.2.186United States

Botnet Statistics [2015-09-20]

detection period: 2015-09-20 00:00-23:59 UTC
total number of suspected botnet IPs: 2410
number of botnet IPs notified to network operators: 2368
number of spam blocked: 125096
recipient count of spam blocked: 3579375

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1051
2CHINANET-HB204
3UNICOM-AH199
4CHINANET-GD186
5CHINANET-JS93
6CHINANET-YN92
7CHINANET-LN51
8CHINANET-SN49
9VNPT-VNNIC-VN48
10CHINANET-HN46

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1086
2Taiwan1052
3Viet Nam84
4Russian Federation34
5India18
6Ukraine12
7Japan12
8Argentina9
9South Korea7
10Mexico6

Sunday, September 20, 2015

Suspected Bot List [2015-09-19]

detection period: 2015-09-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 34

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AL79.106.109.207Albania
AR181.26.192.15Argentina
AR181.164.234.222Argentina
AR186.128.84.251Argentina
DZ41.200.16.138Algeria
DZ105.103.186.52Algeria
GB91.109.13.254United Kingdom
ID101.128.87.117Indonesia
ID111.95.126.226Indonesia
IN117.197.81.181India
IN117.206.241.224India
IN117.221.248.236India
IN122.174.238.99India
IN122.179.90.56India
IN150.107.9.216India
IN182.58.237.95India
IN182.65.137.8India
IN223.176.47.171India
IQ130.193.152.144Iraq
KZ92.46.10.17Kazakhstan
KZ193.193.252.14Kazakhstan
LK175.157.240.153Sri Lanka
MX177.230.228.144Mexico
MX177.242.235.67Mexico
MX187.187.19.25Mexico
NL185.77.128.173Netherlands
PK182.185.37.85Pakistan
RO89.123.43.18Romania
RO92.84.202.137Romania
RO109.98.161.104Romania
TR95.65.241.214Turkey
TR188.3.172.10Turkey
UA188.191.30.143Ukraine
UZ213.230.81.234Uzbekistan

Botnet Statistics [2015-09-19]

detection period: 2015-09-19 00:00-23:59 UTC
total number of suspected botnet IPs: 2279
number of botnet IPs notified to network operators: 2245
number of spam blocked: 143834
recipient count of spam blocked: 3771094

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1085
2CHINANET-HB203
3UNICOM-AH186
4CHINANET-GD128
5CHINANET-YN88
6VNPT-VNNIC-VN61
7CHINANET-HN53
8CHINANET-JS52
9CHINANET-SX42
10CHINANET-LN40

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1087
2China935
3Viet Nam115
4Ukraine17
5India15
6Japan13
7United States9
8Kazakhstan7
9Brazil7
10Russian Federation6

Saturday, September 19, 2015

Suspected Bot List [2015-09-18]

detection period: 2015-09-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 17

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.46.206.167Argentina
AR190.93.208.13Argentina
ES87.235.177.251Spain
GB91.109.13.254United Kingdom
ID175.106.8.202Indonesia
IN45.64.192.138India
IN59.183.5.206India
IN117.212.234.114India
IN117.223.180.106India
IN117.239.77.69India
IN122.176.148.246India
MX187.177.50.130Mexico
NL185.77.128.173Netherlands
PK182.180.109.239Pakistan
RO92.80.106.169Romania
RO109.98.194.212Romania
SV190.62.153.87El Salvador

Botnet Statistics [2015-09-18]

detection period: 2015-09-18 00:00-23:59 UTC
total number of suspected botnet IPs: 2695
number of botnet IPs notified to network operators: 2678
number of spam blocked: 236588
recipient count of spam blocked: 3795859

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1030
2CHINANET-HB283
3UNICOM-AH215
4CHINANET-GD207
5CHINANET-YN92
6CHINANET-ZJ86
7CHINANET-JS79
8CHINANET-SX74
9CHINANET-HN66
10CHINANET-SD60

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1471
2Taiwan1032
3Viet Nam87
4India18
5Brazil12
6Ukraine8
7United States7
8Russian Federation6
9Germany6
10Turkey5

Friday, September 18, 2015

Suspected Bot List [2015-09-17]

detection period: 2015-09-17 00:00-23:59 UTC
number of suspected bots' IPs listed here: 41

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR186.19.29.67Argentina
AR186.56.242.239Argentina
AR190.104.73.16Argentina
AR190.104.208.51Argentina
AR190.175.53.128Argentina
AR190.192.107.190Argentina
AR200.127.144.123Argentina
AR201.250.159.235Argentina
BG217.9.224.140Bulgaria
DZ193.194.69.43Algeria
EC181.196.187.102Ecuador
EC200.107.60.50Ecuador
ES87.235.177.251Spain
GB91.109.13.254United Kingdom
IL31.154.92.52Israel
IN59.97.8.106India
IN59.97.221.111India
IN103.224.156.77India
IN103.233.116.38India
IN103.249.122.9India
IN117.204.53.240India
IN122.165.116.47India
IN182.70.30.96India
IR91.98.249.229Iran
KR166.104.239.93South Korea
KZ2.132.84.233Kazakhstan
MO27.109.183.8Macau
MO60.246.159.1Macau
MX177.230.53.33Mexico
MX187.153.91.137Mexico
MX187.154.65.40Mexico
MX189.186.14.48Mexico
MX189.252.102.50Mexico
NL93.174.90.36Netherlands
NL93.174.90.81Netherlands
RO89.121.245.57Romania
RO89.123.253.221Romania
RO109.96.37.174Romania
US74.129.170.198United States
US174.139.218.181United States
UY186.53.25.228Uruguay

Botnet Statistics [2015-09-17]

detection period: 2015-09-17 00:00-23:59 UTC
total number of suspected botnet IPs: 3243
number of botnet IPs notified to network operators: 3202
number of spam blocked: 163210
recipient count of spam blocked: 3779856

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1067
2CHINANET-HB340
3UNICOM-AH262
4CHINANET-GD176
5CHINANET-ZJ146
6CHINANET-SD117
7CHINANET-JS105
8UNICOM-ZJ92
9WASU75
10CHINANET-YN71

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1823
2Taiwan1071
3Viet Nam147
4Ukraine23
5Brazil23
6India16
7United States14
8Russian Federation11
9South Korea11
10Turkey9

Thursday, September 17, 2015

Suspected Bot List [2015-09-16]

detection period: 2015-09-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 22

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR200.63.163.110Argentina
ES87.111.199.68Spain
ES87.235.177.251Spain
GB91.109.13.254United Kingdom
IN59.89.42.246India
IN115.115.222.125India
IN120.60.144.203India
IN122.174.138.213India
IN182.65.138.104India
IT217.202.248.205Italy
KW178.161.116.250Kuwait
MA212.217.2.8Morocco
MX189.161.96.133Mexico
MX189.248.161.108Mexico
NL93.174.90.49Netherlands
RS109.72.51.38Serbia
UA89.252.41.252Ukraine
US104.47.124.213United States
US104.47.125.222United States
US192.254.134.62United States
US216.169.110.166United States
UY186.49.238.215Uruguay

Botnet Statistics [2015-09-16]

detection period: 2015-09-16 00:00-23:59 UTC
total number of suspected botnet IPs: 2982
number of botnet IPs notified to network operators: 2960
number of spam blocked: 130752
recipient count of spam blocked: 3657035

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1060
2CHINANET-HB410
3UNICOM-AH248
4CHINANET-ZJ185
5CHINANET-GD185
6CHINANET-SD136
7UNICOM-ZJ80
8CHINANET-HN69
9CHINANET-JS64
10CHINANET-SX51

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1739
2Taiwan1064
3Viet Nam35
4United States29
5Brazil20
6Russian Federation13
7Ukraine12
8Turkey7
9Germany7
10India6

Wednesday, September 16, 2015

Suspected Bot List [2015-09-15]

detection period: 2015-09-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 33

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
EG193.227.34.20Egypt

List from greylisting:

country codeIP addressCountry
AM46.241.171.91Armenia
AR181.171.50.251Argentina
AR186.57.171.176Argentina
AR190.189.219.152Argentina
AR200.42.93.198Argentina
DZ41.200.234.56Algeria
EG156.184.125.27Egypt
ES87.235.177.251Spain
GB91.109.13.254United Kingdom
ID103.19.111.1Indonesia
ID103.26.215.3Indonesia
ID103.246.1.138Indonesia
ID124.40.250.114Indonesia
ID202.158.104.194Indonesia
ID203.190.119.1Indonesia
ID210.210.142.99Indonesia
IN59.99.226.136India
IN122.169.166.38India
KW178.161.125.212Kuwait
KW188.71.248.251Kuwait
KZ92.46.20.245Kazakhstan
MA41.137.19.3Morocco
MA212.217.2.8Morocco
MX189.238.63.121Mexico
MX201.116.227.163Mexico
NL93.174.90.50Netherlands
NL93.174.90.93Netherlands
TR31.155.65.110Turkey
TR46.1.135.91Turkey
UA176.121.242.238Ukraine
US68.188.100.100United States
UY167.58.3.230Uruguay

Botnet Statistics [2015-09-15]

detection period: 2015-09-15 00:00-23:59 UTC
total number of suspected botnet IPs: 3339
number of botnet IPs notified to network operators: 3306
number of spam blocked: 163023
recipient count of spam blocked: 3660095

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1048
2CHINANET-HB506
3UNICOM-AH252
4UNICOM-ZJ221
5CHINANET-ZJ183
6CHINANET-GD175
7WASU173
8WASU-BB131
9CHINANET-SD116
10CHINANET-HN49

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2086
2Taiwan1051
3Viet Nam51
4United States24
5Brazil12
6Ukraine9
7Indonesia8
8Russian Federation6
9Turkey5
10Poland5

Tuesday, September 15, 2015

Suspected Bot List [2015-09-14]

detection period: 2015-09-14 00:00-23:59 UTC
number of suspected bots' IPs listed here: 14

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
CA192.207.60.197Canada
CN118.67.124.10China
GB91.109.13.254United Kingdom
HN190.5.77.216Honduras
IT109.52.244.42Italy
MA212.217.2.8Morocco
MX189.234.104.158Mexico
MX201.116.227.163Mexico
NL93.174.90.34Netherlands
NL185.77.128.173Netherlands
US64.132.119.71United States
US68.188.100.100United States
US74.131.25.162United States
US108.179.198.74United States

Botnet Statistics [2015-09-14]

detection period: 2015-09-14 00:00-23:59 UTC
total number of suspected botnet IPs: 3178
number of botnet IPs notified to network operators: 3164
number of spam blocked: 163362
recipient count of spam blocked: 3370931

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET949
2CHINANET-HB337
3UNICOM-ZJ237
4CHINANET-GD212
5UNICOM-AH211
6WASU164
7CHINANET-ZJ163
8WASU-BB132
9CHINANET-SD115
10CHINANET-JS75

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2088
2Taiwan949
3United States72
4Viet Nam12
5Brazil6
6Russian Federation4
7Turkey3
8Thailand3
9Poland3
10Mexico3

Monday, September 14, 2015

Suspected Bot List [2015-09-13]

detection period: 2015-09-13 00:00-23:59 UTC
number of suspected bots' IPs listed here: 22

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BO186.27.126.130Bolivia
ID103.26.215.3Indonesia
ID116.90.165.12Indonesia
MA212.217.2.8Morocco
MX189.234.104.158Mexico
SV201.247.149.77El Salvador
US69.144.223.99United States
US184.167.56.70United States
ZA196.46.23.121South Africa

List from greylisting:

country codeIP addressCountry
BG217.9.224.141Bulgaria
GB91.109.13.254United Kingdom
ID202.162.203.108Indonesia
IL94.159.217.120Israel
IN117.222.95.118India
MX189.234.104.158Mexico
NL185.77.128.173Netherlands
PK39.35.132.105Pakistan
RO109.99.176.211Romania
TT190.58.249.22Trinidad/Tobago
US64.132.119.71United States
US68.188.100.100United States
US74.131.25.162United States

Botnet Statistics [2015-09-13]

detection period: 2015-09-13 00:00-23:59 UTC
total number of suspected botnet IPs: 3265
number of botnet IPs notified to network operators: 3244
number of spam blocked: 176474
recipient count of spam blocked: 3632060

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1026
2CHINANET-HB289
3CHINANET-GD280
4UNICOM-AH184
5CHINANET-JS158
6CHINANET-SX156
7UNICOM-ZJ122
8CHINANET-ZJ113
9CHINANET-SD108
10CHINANET-HN98

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1996
2Taiwan1030
3Viet Nam70
4United States39
5Brazil20
6Russian Federation16
7Ukraine11
8India7
9Indonesia7
10Germany7

Sunday, September 13, 2015

Suspected Bot List [2015-09-12]

detection period: 2015-09-12 00:00-23:59 UTC
number of suspected bots' IPs listed here: 36

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AM5.77.208.104Armenia
BO186.27.126.130Bolivia
ID103.26.215.3Indonesia
IN125.16.12.146India
IT109.52.231.207Italy
IT217.202.248.96Italy
MA212.217.2.8Morocco
MX189.234.104.158Mexico
SV201.247.149.77El Salvador
US68.188.100.100United States
US69.144.223.99United States
US74.131.25.162United States
US184.167.56.70United States

List from greylisting:

country codeIP addressCountry
AR190.13.217.163Argentina
AR190.122.144.33Argentina
AR190.188.123.168Argentina
CA70.38.11.233Canada
CA192.207.60.197Canada
EG41.65.126.98Egypt
GB91.109.13.254United Kingdom
ID111.94.135.199Indonesia
IN117.217.252.149India
IN123.201.38.47India
IN182.75.40.246India
IT217.202.248.96Italy
KZ92.46.3.111Kazakhstan
MA212.217.2.8Morocco
MX189.234.104.158Mexico
PK39.55.143.110Pakistan
RO109.99.176.211Romania
SV201.247.149.77El Salvador
UA91.211.213.42Ukraine
US68.188.100.100United States
US69.144.223.99United States
UY179.24.204.157Uruguay
UY186.54.29.172Uruguay

Botnet Statistics [2015-09-12]

detection period: 2015-09-12 00:00-23:59 UTC
total number of suspected botnet IPs: 4301
number of botnet IPs notified to network operators: 4271
number of spam blocked: 175885
recipient count of spam blocked: 3635429

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1046
2CHINANET-GD579
3CHINANET-HB544
4UNICOM-AH281
5CHINANET-JS266
6CHINANET-HN206
7CHINANET-SX176
8CHINANET-LN153
9CHINANET-ZJ144
10CHINANET-SN134

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2997
2Taiwan1046
3Viet Nam75
4United States33
5Brazil25
6Russian Federation19
7India8
8Germany7
9Turkey6
10Thailand6

Saturday, September 12, 2015

Suspected Bot List [2015-09-11]

detection period: 2015-09-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 18

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AM5.77.198.73Armenia
AR186.62.31.147Argentina
AR190.104.232.112Argentina
BO161.22.135.34Bolivia
BY87.252.236.220Belarus
EG41.65.126.98Egypt
GB90.223.242.174United Kingdom
GB91.109.13.254United Kingdom
ID124.40.250.114Indonesia
IN27.5.159.79India
MX189.234.104.158Mexico
PT93.102.176.28Portugal
RO81.12.215.226Romania
RO109.99.176.211Romania
SV201.247.149.77El Salvador
US68.188.100.100United States
US74.129.170.198United States
US74.131.25.162United States

Botnet Statistics [2015-09-11]

detection period: 2015-09-11 00:00-23:59 UTC
total number of suspected botnet IPs: 3442
number of botnet IPs notified to network operators: 3424
number of spam blocked: 165287
recipient count of spam blocked: 3378307

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1032
2CHINANET-ZJ267
3CHINANET-GD262
4CHINANET-HB232
5UNICOM-AH203
6WASU196
7UNICOM-ZJ166
8CHINANET-JS136
9WASU-BB133
10CHINANET-SD121

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2279
2Taiwan1034
3United States19
4Brazil18
5Viet Nam13
6Russian Federation7
7Poland6
8Kazakhstan5
9Turkey4
10Indonesia4

Friday, September 11, 2015

Suspected Bot List [2015-09-10]

detection period: 2015-09-10 00:00-23:59 UTC
number of suspected bots' IPs listed here: 29

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR190.51.168.86Argentina
AR190.104.232.112Argentina
BO186.27.126.130Bolivia
BR150.164.88.242Brazil
CA192.207.60.197Canada
EG193.227.49.83Egypt
ES87.235.177.251Spain
ID202.162.214.116Indonesia
IN59.90.91.95India
IN122.170.105.219India
IN122.174.250.39India
IN122.179.56.103India
IN203.192.212.52India
IT217.201.73.75Italy
MA212.217.2.8Morocco
MX201.116.227.163Mexico
RO109.99.176.211Romania
RS178.148.142.64Serbia
US64.132.119.71United States
US68.188.100.100United States
US69.144.223.99United States
US72.9.96.248United States
US72.9.96.249United States
US72.9.96.250United States
US72.9.96.251United States
US75.134.115.198United States
US184.167.56.70United States
UY167.62.135.4Uruguay
ZA196.46.23.121South Africa

Botnet Statistics [2015-09-10]

detection period: 2015-09-10 00:00-23:59 UTC
total number of suspected botnet IPs: 3376
number of botnet IPs notified to network operators: 3347
number of spam blocked: 217472
recipient count of spam blocked: 3527199

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1061
2CHINANET-HB315
3CHINANET-ZJ243
4CHINANET-GD206
5CHINANET-SD197
6WASU168
7UNICOM-AH157
8CHINANET-JS144
9UNICOM-ZJ132
10WASU-BB123

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China2124
2Taiwan1063
3United States52
4Brazil23
5Viet Nam13
6Russian Federation9
7India7
8Ukraine6
9Turkey5
10Indonesia5

Thursday, September 10, 2015

Suspected Bot List [2015-09-09]

detection period: 2015-09-09 00:00-23:59 UTC
number of suspected bots' IPs listed here: 45

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AE83.111.163.30Arab Emirates
AM5.77.219.143Armenia
AR181.30.50.138Argentina
AR186.59.197.176Argentina
AR190.104.232.112Argentina
AR190.174.102.145Argentina
DZ41.200.236.18Algeria
GB90.223.242.174United Kingdom
IN1.39.15.219India
IN59.93.219.139India
IN106.194.2.233India
IN117.202.192.144India
IN117.204.62.158India
IN117.241.208.45India
IN117.248.208.15India
IN122.172.23.179India
IN125.16.12.146India
IN182.72.139.50India
IN203.192.212.52India
MA212.217.2.8Morocco
MX148.204.139.170Mexico
MX177.240.78.33Mexico
MX189.202.48.119Mexico
MX189.210.193.216Mexico
MX189.234.104.158Mexico
MX200.94.129.6Mexico
PK39.35.208.2Pakistan
PL188.146.1.179Poland
RO92.87.54.61Romania
RO109.99.176.211Romania
SE83.209.193.49Sweden
SV201.247.149.77El Salvador
TW106.1.34.107Taiwan
US50.197.121.185United States
US50.253.204.227United States
US68.188.100.100United States
US69.144.223.99United States
US75.134.115.198United States
US108.179.198.74United States
US184.167.56.70United States
US192.185.219.221United States
US200.12.232.6United States
UY167.61.86.182Uruguay
UY167.61.218.193Uruguay
ZA197.245.191.83South Africa

Botnet Statistics [2015-09-09]

detection period: 2015-09-09 00:00-23:59 UTC
total number of suspected botnet IPs: 2498
number of botnet IPs notified to network operators: 2453
number of spam blocked: 115836
recipient count of spam blocked: 2966733

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1003
2UNICOM-ZJ209
3WASU182
4WASU-BB176
5CHINANET-HB111
6UNICOM-AH109
7CHINANET-GD70
8CHINANET-ZJ65
9VNPT-VNNIC-VN41
10CHINANET-YN25

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1133
2Taiwan1007
3Viet Nam81
4United States52
5Brazil37
6India19
7Russian Federation18
8Indonesia16
9Ukraine11
10Netherlands9