Custom Search

Saturday, October 31, 2015

Suspected Bot List [2015-10-30]

detection period: 2015-10-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 23

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.229.44.18Argentina
AR186.56.155.176Argentina
AR186.137.248.3Argentina
AR190.178.107.63Argentina
AR190.190.251.191Argentina
AR190.195.18.97Argentina
IN59.88.216.203India
IN59.176.102.194India
IN112.133.246.104India
IN117.208.20.45India
IN122.163.215.148India
IN122.172.142.158India
IN122.175.78.236India
IN182.64.201.185India
IN223.176.13.178India
MX177.246.89.164Mexico
MX189.152.251.120Mexico
MX201.110.91.249Mexico
RO92.83.84.128Romania
RO92.86.70.95Romania
RO109.98.165.6Romania
RS24.135.10.125Serbia
US162.144.104.214United States

Botnet Statistics [2015-10-30]

detection period: 2015-10-30 00:00-23:59 UTC
total number of suspected botnet IPs: 2063
number of botnet IPs notified to network operators: 2040
number of spam blocked: 151757
recipient count of spam blocked: 3271934

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1221
2UNICOM-ZJ152
3WASU111
4WASU-BB99
5VNPT-VNNIC-VN67
6CHINANET-ZJ42
7CHINANET-HB36
8CHINANET-AH30
9CHINANET-GD25
10FPT-VN21

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1226
2China589
3Viet Nam136
4Brazil17
5United States10
6India10
7Ukraine9
8Romania9
9Thailand6
10Russian Federation6

Friday, October 30, 2015

Suspected Bot List [2015-10-29]

detection period: 2015-10-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 21

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR186.128.182.62Argentina
AR200.0.213.2Argentina
AR200.24.255.139Argentina
AR200.55.47.61Argentina
AR201.251.24.73Argentina
ES87.235.177.251Spain
ES92.58.117.16Spain
IN59.88.199.72India
IN59.96.221.222India
IN59.97.132.72India
IN116.73.152.109India
IN117.240.169.138India
IN122.169.11.109India
IN122.177.254.220India
MX187.214.93.166Mexico
PH122.54.161.38Philippines
PK39.32.227.184Pakistan
TW180.177.39.158Taiwan
US162.144.104.214United States
US198.154.241.165United States
UZ213.230.76.206Uzbekistan

Botnet Statistics [2015-10-29]

detection period: 2015-10-29 00:00-23:59 UTC
total number of suspected botnet IPs: 2134
number of botnet IPs notified to network operators: 2113
number of spam blocked: 333944
recipient count of spam blocked: 3405539

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1248
2UNICOM-ZJ161
3WASU127
4WASU-BB100
5CHINANET-HB51
6CHINANET-ZJ48
7CHINANET-GD46
8VNPT-VNNIC-VN38
9CHINANET-AH27
10UNICOM-BJ14

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1256
2China668
3Viet Nam83
4Brazil18
5United States15
6Ukraine10
7India8
8Colombia6
9South Korea5
10Argentina5

Thursday, October 29, 2015

Suspected Bot List [2015-10-28]

detection period: 2015-10-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 30

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.23.11.95Argentina
AR186.60.70.250Argentina
AR190.18.9.101Argentina
AR190.55.33.137Argentina
BO190.129.127.163Bolivia
ES87.235.177.251Spain
IL31.154.92.62Israel
IN27.251.5.182India
IN59.92.246.246India
IN117.194.121.79India
IN117.195.107.202India
IN117.203.211.238India
IN117.208.96.229India
IN117.212.245.154India
IN117.222.122.162India
IN122.174.23.141India
IN125.21.255.126India
IN182.77.87.116India
KE195.202.72.107Kenya
MA197.129.86.212Morocco
MX189.172.186.211Mexico
MX189.190.115.224Mexico
RO86.34.135.26Romania
TR213.248.146.53Turkey
US108.167.133.29United States
US108.179.199.86United States
US162.144.34.20United States
US162.144.104.214United States
US162.144.248.207United States
US198.154.241.165United States

Botnet Statistics [2015-10-28]

detection period: 2015-10-28 00:00-23:59 UTC
total number of suspected botnet IPs: 2041
number of botnet IPs notified to network operators: 2011
number of spam blocked: 285938
recipient count of spam blocked: 3401343

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1254
2UNICOM-ZJ161
3WASU102
4WASU-BB80
5CHINANET-HB59
6VNPT-VNNIC-VN53
7CHINANET-AH39
8CHINANET-GD26
9UNICOM-AH20
10UNICOM-BJ11

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1263
2China551
3Viet Nam99
4United States17
5India14
6Russian Federation13
7Brazil10
8Indonesia6
9Turkey5
10Kazakhstan5

Wednesday, October 28, 2015

Suspected Bot List [2015-10-27]

detection period: 2015-10-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 22

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AL79.106.109.230Albania
AR186.137.28.202Argentina
AR186.182.58.20Argentina
AR190.182.234.95Argentina
AR201.231.194.88Argentina
IN117.214.33.25India
IN119.235.48.179India
IN122.174.214.246India
KE195.202.72.107Kenya
ME178.175.15.212Montenegro
MM203.81.91.11Myanmar
MX187.145.220.206Mexico
MX189.194.141.80Mexico
PK39.32.104.32Pakistan
PL95.160.195.10Poland
RO92.83.68.174Romania
RO109.98.160.210Romania
TR188.3.154.61Turkey
TW180.176.90.119Taiwan
UA176.121.242.238Ukraine
US108.179.199.86United States
US162.144.104.214United States

Botnet Statistics [2015-10-27]

detection period: 2015-10-27 00:00-23:59 UTC
total number of suspected botnet IPs: 1859
number of botnet IPs notified to network operators: 1837
number of spam blocked: 269609
recipient count of spam blocked: 3052124

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1213
2UNICOM-ZJ173
3WASU94
4WASU-BB53
5CHINANET-AH44
6CHINANET-HB41
7CHINANET-GD23
8UNICOM-BJ17
9VNPT-VNNIC-VN11
10CHINANET-SD9

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1218
2China515
3Viet Nam28
4United States12
5Brazil11
6Ukraine5
7Romania5
8South Korea5
9Poland4
10Germany4

Tuesday, October 27, 2015

Suspected Bot List [2015-10-26]

detection period: 2015-10-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 12

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR190.210.204.12Argentina
AR190.244.101.160Argentina
CO190.60.108.2Colombia
EC186.46.56.42Ecuador
ES87.235.177.251Spain
ES88.0.160.6Spain
ES188.85.140.112Spain
IN117.217.89.68India
IN117.240.224.246India
MX189.208.70.219Mexico
TR213.248.172.190Turkey
US162.144.104.214United States

Botnet Statistics [2015-10-26]

detection period: 2015-10-26 00:00-23:59 UTC
total number of suspected botnet IPs: 1876
number of botnet IPs notified to network operators: 1864
number of spam blocked: 263533
recipient count of spam blocked: 2859263

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1172
2WASU191
3UNICOM-ZJ159
4WASU-BB149
5CHINANET-GD33
6UNICOM-BJ17
7CHINANET-SH9
8UNICOM-JS6
9CMNET5
10UNICOM-GD4

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1178
2China633
3United States16
4Brazil5
5Russian Federation4
6Spain4
7Viet Nam3
8India3
9France3
10Germany3

Monday, October 26, 2015

Suspected Bot List [2015-10-25]

detection period: 2015-10-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 11

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR186.134.22.144Argentina
BG77.70.80.21Bulgaria
CN202.142.16.70China
CZ95.46.240.32Czech Republic
EC186.46.56.42Ecuador
IN1.39.13.177India
IN117.211.110.116India
MX177.228.177.90Mexico
MX187.177.172.13Mexico
MX189.212.15.247Mexico
US162.144.104.214United States

Botnet Statistics [2015-10-25]

detection period: 2015-10-25 00:00-23:59 UTC
total number of suspected botnet IPs: 1677
number of botnet IPs notified to network operators: 1666
number of spam blocked: 209190
recipient count of spam blocked: 2677563

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1168
2UNICOM-ZJ125
3WASU99
4WASU-BB77
5CHINANET-GD24
6UNICOM-BJ20
7CHINANET-ZJ17
8CHINANET-HB15
9CHINANET-AH13
10UNICOM-AH9

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1172
2China440
3United States16
4Viet Nam10
5Brazil6
6India4
7Russian Federation3
8Mexico3
9Thailand2
10Indonesia2

Sunday, October 25, 2015

Suspected Bot List [2015-10-24]

detection period: 2015-10-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 13

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR190.15.202.179Argentina
AR190.182.146.2Argentina
AR190.210.204.12Argentina
AR201.255.169.160Argentina
BG77.70.80.21Bulgaria
IN182.71.116.193India
IN203.192.212.52India
MZ41.190.178.222Mozambique
PH122.52.119.54Philippines
RO92.85.154.246Romania
US66.63.178.26United States
US192.254.137.244United States
UZ213.230.86.243Uzbekistan

Botnet Statistics [2015-10-24]

detection period: 2015-10-24 00:00-23:59 UTC
total number of suspected botnet IPs: 1821
number of botnet IPs notified to network operators: 1808
number of spam blocked: 219744
recipient count of spam blocked: 2958050

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1297
2CHINANET-HB85
3CHINANET-ZJ82
4CHINANET-AH80
5CHINANET-GD43
6UNICOM-AH38
7VNPT-VNNIC-VN32
8FPT-VN16
9UNICOM-BJ14
10VIETEL-VNNIC-VN8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1299
2China386
3Viet Nam68
4United States7
5Brazil6
6Romania5
7Russian Federation4
8Indonesia4
9Argentina4
10Ukraine3

Saturday, October 24, 2015

Suspected Bot List [2015-10-23]

detection period: 2015-10-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 24

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR186.62.220.202Argentina
AR190.12.170.108Argentina
AR190.190.124.186Argentina
AR190.244.101.160Argentina
AZ95.86.144.115Azerbaijan
BG77.70.80.21Bulgaria
ES87.235.177.251Spain
IN59.182.184.61India
IN61.3.8.135India
IN116.74.101.132India
IN117.212.234.231India
IN117.214.141.7India
IN117.245.46.196India
KZ193.193.252.14Kazakhstan
KZ213.157.39.54Kazakhstan
MX187.142.247.169Mexico
MX189.236.155.229Mexico
PT62.169.91.234Portugal
RO92.81.169.146Romania
RS188.2.154.88Serbia
US50.206.182.125United States
US72.172.136.97United States
US162.144.104.214United States
US192.254.137.244United States

Botnet Statistics [2015-10-23]

detection period: 2015-10-23 00:00-23:59 UTC
total number of suspected botnet IPs: 2265
number of botnet IPs notified to network operators: 2241
number of spam blocked: 209206
recipient count of spam blocked: 2777361

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1294
2UNICOM-ZJ176
3WASU142
4CHINANET-HB88
5WASU-BB84
6CHINANET-ZJ76
7CHINANET-AH64
8CHINANET-GD55
9UNICOM-AH39
10VNPT-VNNIC-VN35

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1298
2China781
3Viet Nam70
4United States12
5Brazil10
6Ukraine9
7India9
8Turkey6
9Russian Federation6
10Romania5

Friday, October 23, 2015

Suspected Bot List [2015-10-22]

detection period: 2015-10-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 19

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.20.69.243Argentina
AR181.31.243.94Argentina
AR190.15.235.48Argentina
AR200.91.38.248Argentina
BG77.70.80.21Bulgaria
EC190.63.8.67Ecuador
GR37.6.241.211Greece
KZ80.241.32.110Kazakhstan
MX187.143.83.44Mexico
MX187.143.135.54Mexico
RO86.35.185.9Romania
RS178.149.49.126Serbia
US50.192.175.33United States
US108.179.199.86United States
US162.144.104.214United States
US192.254.137.244United States
US198.57.162.203United States
US216.172.173.36United States
ZA169.0.148.160South Africa

Botnet Statistics [2015-10-22]

detection period: 2015-10-22 00:00-23:59 UTC
total number of suspected botnet IPs: 1793
number of botnet IPs notified to network operators: 1774
number of spam blocked: 245530
recipient count of spam blocked: 2633417

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET943
2UNICOM-ZJ210
3WASU127
4WASU-BB100
5UNICOM-AH73
6CHINANET-HB61
7CHINANET-GD50
8CHINANET-ZJ30
9CHINANET-AH25
10VNPT-VNNIC-VN23

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan948
2China733
3Viet Nam43
4United States13
5Brazil6
6Ukraine5
7Kazakhstan4
8Germany4
9Argentina4
10Mexico3

Thursday, October 22, 2015

Suspected Bot List [2015-10-21]

detection period: 2015-10-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 21

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR190.210.142.13Argentina
BG77.70.80.21Bulgaria
BW168.167.214.48Botswana
ES46.26.217.172Spain
ES188.86.167.137Spain
IN59.99.132.162India
IN117.192.197.59India
IN117.196.20.230India
IN120.59.184.122India
IN122.179.28.120India
IN182.72.168.122India
KW178.161.48.185Kuwait
ME178.175.126.8Montenegro
MX177.247.1.86Mexico
MX201.116.227.163Mexico
RO92.85.20.103Romania
SV190.62.170.15El Salvador
UA176.121.242.238Ukraine
US108.179.199.86United States
US162.144.104.214United States
US198.154.241.165United States

Botnet Statistics [2015-10-21]

detection period: 2015-10-21 00:00-23:59 UTC
total number of suspected botnet IPs: 2233
number of botnet IPs notified to network operators: 2212
number of spam blocked: 287188
recipient count of spam blocked: 3847546

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1029
2CHINANET-HB220
3UNICOM-AH197
4UNICOM-ZJ195
5WASU165
6WASU-BB97
7VNPT-VNNIC-VN47
8CHINANET-GD45
9UNICOM-BJ11
10FPT-VN10

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1030
2China1022
3Viet Nam85
4United States14
5India7
6Ukraine5
7Russian Federation5
8United Kingdom5
9Turkey4
10Romania4

Wednesday, October 21, 2015

Suspected Bot List [2015-10-20]

detection period: 2015-10-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 8

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.171.50.251Argentina
BG77.70.80.21Bulgaria
MX187.177.172.13Mexico
MX187.237.63.162Mexico
PH122.3.16.26Philippines
PK39.55.50.65Pakistan
US68.112.21.237United States
US162.144.34.20United States

Botnet Statistics [2015-10-20]

detection period: 2015-10-20 00:00-23:59 UTC
total number of suspected botnet IPs: 2090
number of botnet IPs notified to network operators: 2082
number of spam blocked: 252559
recipient count of spam blocked: 3818668

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1039
2UNICOM-ZJ160
3WASU-BB122
4WASU122
5CHINANET-HB119
6CHINANET-ZJ118
7CHINANET-AH109
8UNICOM-AH107
9CHINANET-GD24
10UNICOM-BJ15

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1040
2China963
3United States20
4Viet Nam12
5Brazil7
6Ukraine5
7Hong Kong4
8Germany4
9Russian Federation3
10Turkey2

Tuesday, October 20, 2015

Suspected Bot List [2015-10-19]

detection period: 2015-10-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 32

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR186.18.124.121Argentina
AR190.185.172.17Argentina
AR190.245.255.68Argentina
AR201.231.200.54Argentina
CO190.60.108.2Colombia
ES87.235.177.251Spain
GR62.169.208.183Greece
IN59.94.98.180India
IN116.75.26.135India
IN117.193.198.104India
IN117.212.208.41India
IN122.161.180.196India
IN122.169.18.42India
IN182.70.245.72India
IN202.142.67.149India
IN202.157.83.35India
IN203.217.145.165India
IR85.9.99.178Iran
KZ2.132.7.250Kazakhstan
KZ5.34.7.192Kazakhstan
KZ87.243.36.139Kazakhstan
MX177.227.166.248Mexico
MX200.94.75.210Mexico
MX201.116.227.163Mexico
RO92.80.211.101Romania
RS178.149.255.142Serbia
RS188.2.111.230Serbia
US108.179.199.86United States
US162.144.104.214United States
US216.172.173.36United States
UY167.59.25.32Uruguay
UY167.61.103.45Uruguay

Botnet Statistics [2015-10-19]

detection period: 2015-10-19 00:00-23:59 UTC
total number of suspected botnet IPs: 3129
number of botnet IPs notified to network operators: 3097
number of spam blocked: 264709
recipient count of spam blocked: 3946649

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1091
2UNICOM-AH458
3CHINANET-HB271
4CHINANET-ZJ208
5WASU168
6UNICOM-ZJ146
7CHINANET-AH137
8WASU-BB129
9CHINANET-GD64
10VNPT-VNNIC-VN52

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1733
2Taiwan1093
3Viet Nam99
4United States58
5India19
6Brazil14
7Ukraine12
8Russian Federation10
9Turkey8
10Romania7

Monday, October 19, 2015

Suspected Bot List [2015-10-18]

detection period: 2015-10-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 15

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.23.156.195Argentina
BG62.221.148.196Bulgaria
CA192.207.61.238Canada
ID202.62.10.210Indonesia
IN115.118.209.75India
IN117.247.50.73India
IN203.194.109.142India
KZ5.34.98.130Kazakhstan
MA41.137.19.3Morocco
MX187.175.101.72Mexico
TZ169.255.187.80Tanzania
US96.44.129.50United States
US157.55.234.245United States
US208.80.211.177United States
UY167.61.115.46Uruguay

Botnet Statistics [2015-10-18]

detection period: 2015-10-18 00:00-23:59 UTC
total number of suspected botnet IPs: 2588
number of botnet IPs notified to network operators: 2573
number of spam blocked: 230084
recipient count of spam blocked: 3495633

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1008
2UNICOM-AH353
3CHINANET-HB267
4CHINANET-GD87
5CHINANET-ZJ83
6WASU81
7WASU-BB64
8CHINANET-AH60
9UNICOM-ZJ51
10NET-107-151-128-042

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1254
2Taiwan1011
3United States117
4Viet Nam53
5South Korea32
6Russian Federation11
7Brazil10
8Ukraine9
9Netherlands7
10India7

Sunday, October 18, 2015

Suspected Bot List [2015-10-17]

detection period: 2015-10-17 00:00-23:59 UTC
number of suspected bots' IPs listed here: 20

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR190.178.192.153Argentina
CA192.207.61.238Canada
ES87.111.49.137Spain
IN117.201.59.37India
IN122.170.179.79India
IN125.16.12.146India
IN182.70.140.172India
IN182.72.139.50India
IQ93.91.194.137Iraq
MR41.188.91.61Mauritania
MX189.157.229.142Mexico
MX200.94.75.210Mexico
PH122.3.36.202Philippines
RO92.84.129.171Romania
RS89.216.147.59Serbia
US65.55.169.245United States
US68.188.100.21United States
US96.44.129.50United States
US198.55.115.11United States
US198.57.162.203United States

Botnet Statistics [2015-10-17]

detection period: 2015-10-17 00:00-23:59 UTC
total number of suspected botnet IPs: 2300
number of botnet IPs notified to network operators: 2280
number of spam blocked: 228530
recipient count of spam blocked: 3629130

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1085
2UNICOM-AH332
3CHINANET-HB210
4CHINANET-GD74
5NET-107-151-128-036
6CNHOST-ASIA35
7VNPT-VNNIC-VN30
8UNICOM-BJ27
9CHINANET-HN26
10KORNET-KR25

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1088
2China881
3United States104
4Viet Nam69
5South Korea34
6Brazil14
7Ukraine12
8India11
9Russian Federation7
10Turkey6

Saturday, October 17, 2015

Suspected Bot List [2015-10-16]

detection period: 2015-10-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 29

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR190.188.123.168Argentina
AR190.244.101.160Argentina
AR201.253.69.105Argentina
AZ95.86.162.17Azerbaijan
BY217.21.46.81Belarus
CO190.60.108.2Colombia
ES87.111.49.137Spain
ID202.62.10.210Indonesia
IN59.88.151.109India
IN117.211.38.172India
IN122.178.100.177India
IN182.64.167.40India
IN182.68.73.219India
IN182.72.139.50India
IN203.194.109.142India
IR91.98.243.172Iran
IT2.194.73.55Italy
MX187.217.83.34Mexico
MX200.94.75.210Mexico
RO92.80.4.96Romania
RO109.98.164.84Romania
TR5.47.215.88Turkey
TW180.176.90.119Taiwan
US50.116.120.220United States
US50.193.108.88United States
US162.144.104.214United States
US198.55.115.11United States
UY167.61.68.253Uruguay
UY167.61.103.80Uruguay

Botnet Statistics [2015-10-16]

detection period: 2015-10-16 00:00-23:59 UTC
total number of suspected botnet IPs: 3064
number of botnet IPs notified to network operators: 3035
number of spam blocked: 212049
recipient count of spam blocked: 3446062

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1078
2UNICOM-AH341
3CHINANET-HB298
4UNICOM-ZJ125
5WASU123
6CHINANET-GD120
7CHINANET-AH105
8CHINANET-ZJ100
9WASU-BB72
10NET-107-151-128-066

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1570
2Taiwan1085
3United States146
4Viet Nam62
5South Korea40
6Brazil25
7Ukraine15
8India15
9Colombia11
10Turkey8

Friday, October 16, 2015

Suspected Bot List [2015-10-15]

detection period: 2015-10-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 53

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.1.173.87Argentina
AR186.59.29.173Argentina
AR190.175.16.209Argentina
CO190.60.108.2Colombia
DZ41.102.90.94Algeria
ES87.111.49.137Spain
ES87.235.177.251Spain
IN59.89.213.197India
IN61.12.94.166India
IN101.0.45.116India
IN117.208.33.119India
IN117.211.61.26India
IN117.213.3.73India
IN122.170.105.219India
IN122.174.57.6India
IN122.176.25.175India
IN203.194.109.142India
MX187.159.82.224Mexico
MX200.94.75.210Mexico
MX201.116.227.163Mexico
PK182.185.83.173Pakistan
RO109.98.160.15Romania
TZ169.255.187.80Tanzania
US68.188.100.96United States
US155.94.180.12United States
US155.94.180.20United States
US155.94.180.28United States
US155.94.180.54United States
US155.94.180.59United States
US155.94.180.60United States
US155.94.180.84United States
US155.94.180.85United States
US155.94.180.90United States
US155.94.180.99United States
US155.94.180.107United States
US155.94.180.134United States
US155.94.180.135United States
US155.94.180.139United States
US155.94.180.144United States
US155.94.180.149United States
US155.94.180.158United States
US155.94.180.175United States
US155.94.180.185United States
US155.94.180.192United States
US155.94.180.203United States
US155.94.180.207United States
US155.94.180.216United States
US155.94.180.217United States
US155.94.180.232United States
US155.94.180.250United States
US157.56.111.80United States
US162.144.104.214United States
UY167.61.68.253Uruguay

Botnet Statistics [2015-10-15]

detection period: 2015-10-15 00:00-23:59 UTC
total number of suspected botnet IPs: 3360
number of botnet IPs notified to network operators: 3307
number of spam blocked: 195431
recipient count of spam blocked: 3258027

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1021
2CHINANET-HB378
3UNICOM-AH307
4UNICOM-ZJ176
5CHINANET-AH174
6WASU171
7CHINANET-ZJ154
8CHINANET-GD143
9WASU-BB123
10NET-107-151-128-077

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1962
2Taiwan1025
3United States187
4Viet Nam42
5South Korea20
6India17
7Brazil17
8Russian Federation9
9Romania6
10Colombia6

Wednesday, October 14, 2015

Suspected Bot List [2015-10-13]

detection period: 2015-10-13 00:00-23:59 UTC
number of suspected bots' IPs listed here: 21

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR181.15.192.210Argentina
AR190.51.181.238Argentina
AR190.179.133.252Argentina
AR200.49.158.44Argentina
BR150.164.88.242Brazil
CO190.60.108.2Colombia
EC181.196.187.102Ecuador
ID103.16.199.130Indonesia
ID103.16.199.131Indonesia
ID103.26.215.3Indonesia
ID202.62.10.210Indonesia
IN203.194.109.142India
IT95.74.78.186Italy
MA212.217.2.8Morocco
MX189.228.154.58Mexico
MX201.132.123.9Mexico
RO92.83.49.41Romania
TR95.65.234.123Turkey
US68.188.100.96United States
US198.154.241.165United States
UY167.61.138.37Uruguay

Botnet Statistics [2015-10-13]

detection period: 2015-10-13 00:00-23:59 UTC
total number of suspected botnet IPs: 2501
number of botnet IPs notified to network operators: 2480
number of spam blocked: 205606
recipient count of spam blocked: 3359676

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1019
2UNICOM-AH425
3CHINANET-HB328
4CHINANET-AH118
5WASU87
6UNICOM-ZJ84
7WASU-BB57
8CHINANET-GD51
9CHINANET-ZJ46
10CHINANET-HN25

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1330
2Taiwan1024
3Brazil21
4United States18
5Viet Nam11
6Russian Federation10
7Indonesia6
8Colombia6
9South Korea5
10India5

Tuesday, October 13, 2015

Suspected Bot List [2015-10-12]

detection period: 2015-10-12 00:00-23:59 UTC
number of suspected bots' IPs listed here: 27

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR186.18.124.121Argentina
AR190.190.234.252Argentina
CA72.55.153.155Canada
EC181.112.60.106Ecuador
ES87.111.49.137Spain
ID103.16.199.130Indonesia
ID111.94.104.141Indonesia
ID182.23.32.91Indonesia
IN59.98.200.205India
IN59.99.180.62India
IN61.246.137.58India
IN116.74.69.253India
IN117.193.20.159India
IN117.241.113.128India
IN120.59.235.95India
IN122.170.105.219India
IN125.16.12.146India
IN150.129.103.124India
IN182.72.107.166India
IN182.72.139.50India
KZ2.132.84.176Kazakhstan
KZ213.157.50.254Kazakhstan
MA212.217.2.8Morocco
MX187.177.172.13Mexico
PK182.191.43.62Pakistan
US68.188.100.96United States
ZA105.210.163.136South Africa

Botnet Statistics [2015-10-12]

detection period: 2015-10-12 00:00-23:59 UTC
total number of suspected botnet IPs: 2777
number of botnet IPs notified to network operators: 2750
number of spam blocked: 224503
recipient count of spam blocked: 3517160

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1050
2UNICOM-AH388
3CHINANET-HB320
4UNICOM-ZJ151
5WASU134
6CHINANET-GD117
7CHINANET-AH95
8WASU-BB54
9VNPT-VNNIC-VN44
10CHINANET-HN30

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1466
2Taiwan1056
3Viet Nam87
4Brazil20
5United States18
6Russian Federation17
7India17
8Ukraine8
9South Korea8
10Turkey7

Monday, October 12, 2015

Suspected Bot List [2015-10-11]

detection period: 2015-10-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 21

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR179.41.240.184Argentina
AR181.26.183.73Argentina
AR186.22.20.218Argentina
AR190.244.43.47Argentina
AR200.122.100.100Argentina
CO190.60.108.2Colombia
DZ197.117.4.174Algeria
ES87.111.49.137Spain
ID180.250.210.23Indonesia
ID180.252.181.15Indonesia
IN122.162.184.168India
IN203.194.109.142India
IT109.52.216.242Italy
KZ5.34.106.190Kazakhstan
MA212.217.2.8Morocco
MX189.250.21.85Mexico
MX200.94.75.210Mexico
RS178.149.49.126Serbia
US68.188.100.96United States
US162.144.104.214United States
US198.154.214.215United States

Botnet Statistics [2015-10-11]

detection period: 2015-10-11 00:00-23:59 UTC
total number of suspected botnet IPs: 2547
number of botnet IPs notified to network operators: 2526
number of spam blocked: 305136
recipient count of spam blocked: 3580646

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1066
2UNICOM-AH265
3CHINANET-HB172
4CHINANET-GD168
5UNICOM-ZJ135
6WASU125
7WASU-BB64
8CHINANET-LN45
9VNPT-VNNIC-VN41
10CHINANET-HN37

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1201
2Taiwan1070
3Viet Nam81
4Brazil23
5United States20
6Ukraine19
7India14
8Russian Federation13
9South Korea9
10Indonesia8

Sunday, October 11, 2015

Suspected Bots' IP List for September 2015

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here (as shown below). You are free to use them to create more effective defenses, discover latest trends in cyber attacks, etc.

Suspected Bots IP [2015-09-01]
Suspected Bots IP [2015-09-02]
Suspected Bots IP [2015-09-03]
Suspected Bots IP [2015-09-04]
Suspected Bots IP [2015-09-05]
Suspected Bots IP [2015-09-06]
Suspected Bots IP [2015-09-07]
Suspected Bots IP [2015-09-08]
Suspected Bots IP [2015-09-09]
Suspected Bots IP [2015-09-10]
Suspected Bots IP [2015-09-11]
Suspected Bots IP [2015-09-12]
Suspected Bots IP [2015-09-13]
Suspected Bots IP [2015-09-14]
Suspected Bots IP [2015-09-15]
Suspected Bots IP [2015-09-16]
Suspected Bots IP [2015-09-17]
Suspected Bots IP [2015-09-18]
Suspected Bots IP [2015-09-19]
Suspected Bots IP [2015-09-20]
Suspected Bots IP [2015-09-21]
Suspected Bots IP [2015-09-22]
Suspected Bots IP [2015-09-23]
Suspected Bots IP [2015-09-24]
Suspected Bots IP [2015-09-25]
Suspected Bots IP [2015-09-26]
Suspected Bots IP [2015-09-27]
Suspected Bots IP [2015-09-28]
Suspected Bots IP [2015-09-29]
Suspected Bots IP [2015-09-30]

Suspected Bot List [2015-10-10]

detection period: 2015-10-10 00:00-23:59 UTC
number of suspected bots' IPs listed here: 19

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR190.57.231.253Argentina
AZ91.135.242.172Azerbaijan
BR150.164.88.242Brazil
CO190.60.108.2Colombia
ES87.111.49.137Spain
ID202.62.10.210Indonesia
IN59.178.148.44India
IN120.57.76.82India
IN122.177.216.141India
IN125.16.12.146India
IN203.194.109.142India
MA212.217.2.8Morocco
MO60.246.191.187Macau
MX177.225.243.67Mexico
MX189.142.103.19Mexico
MX200.94.75.210Mexico
RS188.2.226.123Serbia
US174.45.219.54United States
UY167.61.21.122Uruguay

Botnet Statistics [2015-10-10]

detection period: 2015-10-10 00:00-23:59 UTC
total number of suspected botnet IPs: 3029
number of botnet IPs notified to network operators: 3010
number of spam blocked: 195709
recipient count of spam blocked: 3530794

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1084
2CHINANET-HB366
3UNICOM-AH258
4WASU206
5CHINANET-GD203
6WASU-BB179
7UNICOM-ZJ111
8CHINANET-JS56
9CHINANET-HN56
10CHINANET-LN42

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1724
2Taiwan1085
3Viet Nam34
4Brazil27
5United States18
6India17
7Russian Federation16
8European Union16
9South Korea10
10Colombia9

Saturday, October 10, 2015

Suspected Bot List [2015-10-09]

detection period: 2015-10-09 00:00-23:59 UTC
number of suspected bots' IPs listed here: 38

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR186.182.40.206Argentina
BG78.128.24.57Bulgaria
BG94.26.77.68Bulgaria
BY91.149.173.211Belarus
CO190.60.108.2Colombia
ES87.111.49.137Spain
ES87.235.177.251Spain
ID103.16.199.131Indonesia
ID103.26.215.3Indonesia
ID111.94.135.226Indonesia
ID202.62.10.210Indonesia
IN59.94.210.14India
IN106.220.174.55India
IN117.201.40.43India
IN117.222.114.150India
IN117.247.222.156India
IN122.170.105.219India
IN122.179.28.214India
IN182.74.98.218India
IN182.75.49.6India
IN203.192.212.52India
IN203.194.109.142India
IT150.145.60.121Italy
KZ109.201.55.64Kazakhstan
MX189.193.198.243Mexico
MX189.211.83.146Mexico
MX200.94.75.210Mexico
MZ197.235.32.2Mozambique
PK39.55.193.127Pakistan
RO86.34.170.206Romania
RO86.34.221.102Romania
RO89.120.75.232Romania
RO89.122.117.53Romania
UA176.121.238.165Ukraine
US47.59.68.219United States
US162.144.104.214United States
UY167.61.46.174Uruguay
UY167.61.69.66Uruguay

Botnet Statistics [2015-10-09]

detection period: 2015-10-09 00:00-23:59 UTC
total number of suspected botnet IPs: 3339
number of botnet IPs notified to network operators: 3301
number of spam blocked: 198329
recipient count of spam blocked: 3627371

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1099
2UNICOM-AH469
3CHINANET-HB397
4CHINANET-GD182
5CHINANET-ZJ150
6UNICOM-ZJ141
7WASU119
8WASU-BB97
9CHINANET-JS81
10CHINANET-HN58

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China1959
2Taiwan1102
3Viet Nam89
4Brazil30
5Russian Federation26
6India22
7United States20
8Indonesia10
9Colombia7
10Ukraine5

Friday, October 9, 2015

Suspected Bot List [2015-10-08]

detection period: 2015-10-08 00:00-23:59 UTC
number of suspected bots' IPs listed here: 33

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

country codeIP addressCountry
AR190.17.59.163Argentina
AR190.51.158.82Argentina
AR190.193.54.18Argentina
AR200.50.176.46Argentina
BG78.128.24.57Bulgaria
CO190.60.108.2Colombia
ES83.53.151.96Spain
ES87.111.49.137Spain
ID103.16.199.130Indonesia
ID103.16.199.131Indonesia
ID103.26.215.3Indonesia
ID114.141.49.90Indonesia
ID202.62.10.210Indonesia
IN59.88.149.126India
IN117.201.25.53India
IN117.241.208.165India
IN125.16.12.146India
IN182.72.139.50India
IN203.192.212.52India
IN203.194.109.142India
IT2.194.89.254Italy
KZ109.229.176.111Kazakhstan
MA41.137.19.3Morocco
MA212.217.2.8Morocco
MX177.231.134.232Mexico
MX189.148.219.114Mexico
MX200.94.75.210Mexico
MX201.113.168.144Mexico
PH122.3.36.203Philippines
PK39.41.128.48Pakistan
US24.240.82.184United States
US162.144.104.214United States
UY167.61.25.160Uruguay