Custom Search

Sunday, July 31, 2016

Suspected Bot List [2016-07-30]

detection period: 2016-07-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 118

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR186.57.69.175Argentina
US71.95.169.126United States

List from greylisting:

Botnet Statistics [2016-07-30]

detection period: 2016-07-30 00:00-23:59 UTC
total number of suspected botnet IPs: 1197
number of botnet IPs notified to network operators: 1079
number of spam blocked: 2243
recipient count of spam blocked: 19727

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET269
2SONET-NET220
3CHINANET-HN92
4VNPT-VNNIC-VN38
5MX-USCV4-LACNIC27
6WASU21
7VE-CSVE-LACNIC21
8WASU-BB17
9BSNLNET14
10VIETEL-VN13

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan491
2China190
3Viet Nam85
4India60
5Mexico46
6Turkey29
7Venezuela24
8Peru24
9Brazil22
10Colombia21

Saturday, July 30, 2016

Suspected Bot List [2016-07-29]

detection period: 2016-07-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 145

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR186.57.37.15Argentina
AR186.57.69.175Argentina
TW123.195.102.46Taiwan

List from greylisting:

Botnet Statistics [2016-07-29]

detection period: 2016-07-29 00:00-23:59 UTC
total number of suspected botnet IPs: 1623
number of botnet IPs notified to network operators: 1478
number of spam blocked: 5321
recipient count of spam blocked: 23367

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET256
2SONET-NET238
3WASU139
4CHINANET-HN108
5VNPT-VNNIC-VN50
6UNICOM-ZJ39
7MX-USCV4-LACNIC31
8NorthStar27
9CHINANET-JS20
10BSNLNET19

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan497
2China475
3India119
4Viet Nam99
5Mexico55
6Turkey40
7United States25
8Peru21
9Colombia21
10Iran20

Friday, July 29, 2016

Suspected Bot List [2016-07-28]

detection period: 2016-07-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 149

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
US71.95.169.126United States

List from greylisting:

Botnet Statistics [2016-07-28]

detection period: 2016-07-28 00:00-23:59 UTC
total number of suspected botnet IPs: 1534
number of botnet IPs notified to network operators: 1385
number of spam blocked: 32084
recipient count of spam blocked: 33426

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU244
2HINET-NET172
3SONET-NET129
4UNICOM-ZJ90
5VNPT-VNNIC-VN62
6CHINANET-HN58
7WASU-BB41
8CHINANET-JS31
9BHARTI-IN26
10MSFT24

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China596
2Taiwan303
3Viet Nam119
4India108
5Mexico49
6Brazil30
7Turkey29
8United States28
9Indonesia24
10Pakistan22

Thursday, July 28, 2016

Suspected Bot List [2016-07-27]

detection period: 2016-07-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 110

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
US71.95.169.126United States

List from greylisting:

Botnet Statistics [2016-07-27]

detection period: 2016-07-27 00:00-23:59 UTC
total number of suspected botnet IPs: 1196
number of botnet IPs notified to network operators: 1086
number of spam blocked: 42882
recipient count of spam blocked: 43386

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU225
2HINET-NET142
3SONET-NET91
4UNICOM-ZJ76
5CHINANET-JS39
6WASU-BB28
7VNPT-VNNIC-VN25
8UNICOM-JS20
9MSFT17
10BSNLNET17

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China484
2Taiwan235
3India75
4Viet Nam63
5Mexico40
6Brazil26
7United States22
8Iran21
9Turkey18
10Venezuela16

Wednesday, July 27, 2016

Suspected Bot List [2016-07-26]

detection period: 2016-07-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 186

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2016-07-26]

detection period: 2016-07-26 00:00-23:59 UTC
total number of suspected botnet IPs: 1685
number of botnet IPs notified to network operators: 1499
number of spam blocked: 68610
recipient count of spam blocked: 69464

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU265
2HINET-NET150
3SONET-NET129
4UNICOM-ZJ82
5VNPT-VNNIC-VN73
6UNICOM-JS49
7CHINANET-JS29
8BSNLNET26
9WASU-BB24
10BHARTI-IN21

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China557
2Taiwan286
3India139
4Viet Nam134
5Mexico54
6Iran42
7Turkey35
8Brazil34
9Peru33
10United States23

Tuesday, July 26, 2016

Suspected Bot List [2016-07-25]

detection period: 2016-07-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 82

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2016-07-25]

detection period: 2016-07-25 00:00-23:59 UTC
total number of suspected botnet IPs: 1441
number of botnet IPs notified to network operators: 1359
number of spam blocked: 26887
recipient count of spam blocked: 37070

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU249
2HINET-NET147
3SONET-NET126
4UNICOM-ZJ87
5CHINANET-JS55
6WASU-BB43
7UNICOM-JS43
8VNPT-VNNIC-VN39
9CHINANET-HN39
10NorthStar22

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China624
2Taiwan274
3Viet Nam82
4India70
5Mexico51
6Brazil40
7Iran36
8Peru33
9Colombia22
10United States16

Monday, July 25, 2016

Suspected Bot List [2016-07-24]

detection period: 2016-07-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 61

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2016-07-24]

detection period: 2016-07-24 00:00-23:59 UTC
total number of suspected botnet IPs: 1070
number of botnet IPs notified to network operators: 1009
number of spam blocked: 3320
recipient count of spam blocked: 4334

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET202
2SONET-NET159
3WASU153
4UNICOM-ZJ66
5WASU-BB42
6VNPT-VNNIC-VN40
7CHINANET-HN40
8CHINANET-JS27
9ETC-VNNIC-VN10
10BHARTI-IN9

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China388
2Taiwan362
3Viet Nam71
4India34
5Mexico22
6Iran22
7Peru11
8Brazil11
9Saudi Arabia8
10Venezuela6

Sunday, July 24, 2016

Suspected Bot List [2016-07-23]

detection period: 2016-07-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 67

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
TW118.233.21.82Taiwan

List from greylisting:

Botnet Statistics [2016-07-23]

detection period: 2016-07-23 00:00-23:59 UTC
total number of suspected botnet IPs: 813
number of botnet IPs notified to network operators: 746
number of spam blocked: 4088
recipient count of spam blocked: 16078

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET179
2SONET-NET144
3CHINANET-HN49
4CHINANET-YN24
5CHINANET-HB24
6VNPT-VNNIC-VN19
7MX-USCV4-LACNIC16
8CHINANET-ZJ-JH13
9BSNLNET12
10VE-CSVE-LACNIC10

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan326
2China147
3India46
4Mexico43
5Viet Nam41
6Peru16
7Iran15
8Brazil13
9Turkey12
10Venezuela11

Saturday, July 23, 2016

Suspected Bot List [2016-07-22]

detection period: 2016-07-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 137

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
CO190.7.146.126Colombia
PK175.107.63.2Pakistan
TW123.195.103.136Taiwan
UY179.27.71.147Uruguay

List from greylisting:

Botnet Statistics [2016-07-22]

detection period: 2016-07-22 00:00-23:59 UTC
total number of suspected botnet IPs: 1094
number of botnet IPs notified to network operators: 957
number of spam blocked: 2326
recipient count of spam blocked: 16949

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET152
2SONET-NET126
3WASU73
4CHINANET-HN51
5UNICOM-ZJ49
6MX-USCV4-LACNIC26
7VNPT-VNNIC-VN25
8CHINANET-JS15
9CHINANET-HB15
10CHINANET-YN14

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China303
2Taiwan285
3India80
4Mexico54
5Viet Nam51
6Iran22
7Peru20
8Turkey19
9Brazil19
10Colombia17

Friday, July 22, 2016

Suspected Bot List [2016-07-21]

detection period: 2016-07-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 127

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2016-07-21]

detection period: 2016-07-21 00:00-23:59 UTC
total number of suspected botnet IPs: 1444
number of botnet IPs notified to network operators: 1317
number of spam blocked: 800
recipient count of spam blocked: 2054

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU260
2HINET-NET147
3SONET-NET132
4UNICOM-ZJ90
5VNPT-VNNIC-VN54
6CHINANET-HN45
7WASU-BB42
8CHINANET-JS37
9UNICOM-JS23
10MX-USCV4-LACNIC20

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China576
2Taiwan282
3Viet Nam95
4India82
5Mexico58
6Brazil27
7Turkey22
8Iran21
9Peru20
10Philippines16

Thursday, July 21, 2016

Suspected Bot List [2016-07-20]

detection period: 2016-07-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 152

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2016-07-20]

detection period: 2016-07-20 00:00-23:59 UTC
total number of suspected botnet IPs: 1575
number of botnet IPs notified to network operators: 1423
number of spam blocked: 1408
recipient count of spam blocked: 2303

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU289
2HINET-NET122
3SONET-NET118
4UNICOM-ZJ87
5VNPT-VNNIC-VN54
6CMNET47
7CHINANET-HN45
8CHINANET-JS41
9MX-USCV4-LACNIC39
10UNICOM-JS36

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China644
2Taiwan243
3India113
4Viet Nam89
5Mexico70
6Peru42
7Turkey31
8Iran30
9Brazil29
10Argentina16

Wednesday, July 20, 2016

Suspected Bot List [2016-07-19]

detection period: 2016-07-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 351

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2016-07-19]

detection period: 2016-07-19 00:00-23:59 UTC
total number of suspected botnet IPs: 2591
number of botnet IPs notified to network operators: 2240
number of spam blocked: 1419
recipient count of spam blocked: 2118

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU310
2SONET-NET206
3MX-USCV4-LACNIC135
4HINET-NET121
5UNICOM-ZJ110
6VNPT-VNNIC-VN77
7CMNET37
8WASU-BB36
9UNICOM-JS32
10MX-IPMS2-LACNIC31

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China633
2Taiwan329
3Mexico299
4India167
5Viet Nam149
6Colombia88
7Brazil79
8Iran74
9Peru72
10Turkey49

Tuesday, July 19, 2016

Suspected Bot List [2016-07-18]

detection period: 2016-07-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 165

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2016-07-18]

detection period: 2016-07-18 00:00-23:59 UTC
total number of suspected botnet IPs: 1915
number of botnet IPs notified to network operators: 1750
number of spam blocked: 1125
recipient count of spam blocked: 1556

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU311
2HINET-NET272
3SONET-NET261
4UNICOM-ZJ90
5VNPT-VNNIC-VN69
6CHINANET-JS62
7CMNET46
8UNICOM-JS40
9WASU-BB29
10BSNLNET26

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China649
2Taiwan533
3Viet Nam128
4India115
5Mexico55
6Iran34
7Turkey31
8Philippines27
9Brazil27
10Peru26

Monday, July 18, 2016

Suspected Bot List [2016-07-17]

detection period: 2016-07-17 00:00-23:59 UTC
number of suspected bots' IPs listed here: 10

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
US71.95.169.126United States

List from greylisting:

Botnet Statistics [2016-07-17]

detection period: 2016-07-17 00:00-23:59 UTC
total number of suspected botnet IPs: 891
number of botnet IPs notified to network operators: 881
number of spam blocked: 572
recipient count of spam blocked: 779

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU248
2HINET-NET198
3SONET-NET149
4UNICOM-ZJ81
5WASU-BB41
6NorthStar25
7CHINANET-HN25
8CHINANET-JS22
9CMNET18
10UNICOM-JS15

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China505
2Taiwan348
3United States7
4India3
5Viet Nam2
6Serbia2
7Peru2
8Mexico2
9South Korea2
10Colombia2

Sunday, July 17, 2016

Suspected Bots' IP List for June 2016

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here (as shown below). You are free to use them to create more effective defenses, discover latest trends in cyber attacks, etc.

Suspected Bots IP [2016-06-01]
Suspected Bots IP [2016-06-02]
Suspected Bots IP [2016-06-03]
Suspected Bots IP [2016-06-04]
Suspected Bots IP [2016-06-05]
Suspected Bots IP [2016-06-06]
Suspected Bots IP [2016-06-07]
Suspected Bots IP [2016-06-08]
Suspected Bots IP [2016-06-09]
Suspected Bots IP [2016-06-10]
Suspected Bots IP [2016-06-11]
Suspected Bots IP [2016-06-12]
Suspected Bots IP [2016-06-13]
Suspected Bots IP [2016-06-14]
Suspected Bots IP [2016-06-15]
Suspected Bots IP [2016-06-16]
Suspected Bots IP [2016-06-17]
Suspected Bots IP [2016-06-18]
Suspected Bots IP [2016-06-20]
Suspected Bots IP [2016-06-21]
Suspected Bots IP [2016-06-23]
Suspected Bots IP [2016-06-24]
Suspected Bots IP [2016-06-25]
Suspected Bots IP [2016-06-26]
Suspected Bots IP [2016-06-27]
Suspected Bots IP [2016-06-28]
Suspected Bots IP [2016-06-29]
Suspected Bots IP [2016-06-30]

Suspected Bot List [2016-07-16]

detection period: 2016-07-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 3

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
US71.95.169.126United States

List from greylisting:

Botnet Statistics [2016-07-16]

detection period: 2016-07-16 00:00-23:59 UTC
total number of suspected botnet IPs: 526
number of botnet IPs notified to network operators: 523
number of spam blocked: 3419
recipient count of spam blocked: 3419

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU257
2HINET-NET119
3SONET-NET95
4WASU-BB6
5CMNET5
6CHINANET-GD4
7UNICOM-GD3
8UNICOM-HE2
9HICHINA2
10ALISOFT2

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China285
2Taiwan217
3United States9
4South Korea2
5Hong Kong2
6Russian Federation1
7Romania1
8Philippines1
9Netherlands1
10Mexico1

Saturday, July 16, 2016

Suspected Bot List [2016-07-15]

detection period: 2016-07-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 220

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
PK175.107.63.2Pakistan

List from greylisting:

Botnet Statistics [2016-07-15]

detection period: 2016-07-15 00:00-23:59 UTC
total number of suspected botnet IPs: 1560
number of botnet IPs notified to network operators: 1340
number of spam blocked: 2196
recipient count of spam blocked: 3656

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU287
2HINET-NET139
3SONET-NET117
4VNPT-VNNIC-VN50
5UNICOM-ZJ39
6MX-USCV4-LACNIC35
7BSNLNET27
8BHARTI-IN24
9CMNET20
10PTCLBB-PK17

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China423
2Taiwan263
3India168
4Viet Nam117
5Mexico66
6Turkey44
7Iran34
8Pakistan30
9Peru30
10Indonesia27

Friday, July 15, 2016

Suspected Bot List [2016-07-14]

detection period: 2016-07-14 00:00-23:59 UTC
number of suspected bots' IPs listed here: 106

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
PK175.107.63.2Pakistan
UY179.27.71.147Uruguay

List from greylisting:

Botnet Statistics [2016-07-14]

detection period: 2016-07-14 00:00-23:59 UTC
total number of suspected botnet IPs: 1463
number of botnet IPs notified to network operators: 1357
number of spam blocked: 950
recipient count of spam blocked: 14645

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU278
2HINET-NET178
3SONET-NET161
4UNICOM-ZJ79
5WASU-BB44
6CHINANET-JS44
7UNICOM-JS37
8VNPT-VNNIC-VN34
9NorthStar31
10MX-USCV4-LACNIC24

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China599
2Taiwan344
3India73
4Viet Nam61
5Mexico59
6Peru32
7Turkey26
8Brazil24
9Iran21
10Colombia20

Thursday, July 14, 2016

Suspected Bot List [2016-07-13]

detection period: 2016-07-13 00:00-23:59 UTC
number of suspected bots' IPs listed here: 153

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2016-07-13]

detection period: 2016-07-13 00:00-23:59 UTC
total number of suspected botnet IPs: 1664
number of botnet IPs notified to network operators: 1511
number of spam blocked: 17433
recipient count of spam blocked: 17433

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU328
2SONET-NET148
3HINET-NET143
4VNPT-VNNIC-VN76
5UNICOM-ZJ62
6CHINANET-JS43
7UNICOM-JS35
8WASU-BB32
9CMNET30
10NorthStar29

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China608
2Taiwan292
3Viet Nam144
4India118
5Mexico64
6Iran39
7Peru31
8Turkey26
9Philippines23
10Brazil21

Wednesday, July 13, 2016

Suspected Bot List [2016-07-12]

detection period: 2016-07-12 00:00-23:59 UTC
number of suspected bots' IPs listed here: 137

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
CO190.7.146.126Colombia
PK175.107.63.2Pakistan
TW123.195.84.216Taiwan
UY179.27.71.147Uruguay

List from greylisting:

Botnet Statistics [2016-07-12]

detection period: 2016-07-12 00:00-23:59 UTC
total number of suspected botnet IPs: 1741
number of botnet IPs notified to network operators: 1604
number of spam blocked: 41751
recipient count of spam blocked: 65012

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU388
2HINET-NET163
3SONET-NET119
4UNICOM-ZJ90
5VNPT-VNNIC-VN57
6WASU-BB36
7UNICOM-JS35
8CMNET34
9MX-USCV4-LACNIC31
10CHINANET-JS31

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China712
2Taiwan290
3Viet Nam115
4India109
5Mexico82
6Brazil49
7Peru33
8Turkey30
9Iran27
10Colombia20

Tuesday, July 12, 2016

Suspected Bot List [2016-07-11]

detection period: 2016-07-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 151

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
CO190.7.146.126Colombia
PK175.107.63.2Pakistan
TR213.14.64.190Turkey
US71.95.169.126United States
UY179.27.71.147Uruguay

List from greylisting:

Botnet Statistics [2016-07-11]

detection period: 2016-07-11 00:00-23:59 UTC
total number of suspected botnet IPs: 1870
number of botnet IPs notified to network operators: 1719
number of spam blocked: 8234
recipient count of spam blocked: 24136

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU394
2HINET-NET145
3SONET-NET134
4UNICOM-ZJ100
5VNPT-VNNIC-VN70
6CMNET47
7CHINANET-JS47
8NorthStar45
9UNICOM-JS43
10WASU-BB38

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China831
2Taiwan283
3Viet Nam125
4India109
5Mexico63
6Peru43
7Iran37
8Indonesia26
9Brazil26
10Turkey25

Monday, July 11, 2016

Suspected Bot List [2016-07-10]

detection period: 2016-07-10 00:00-23:59 UTC
number of suspected bots' IPs listed here: 46

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
CO190.7.146.126Colombia
TR213.14.64.190Turkey
US71.95.169.126United States
UY179.27.71.147Uruguay

List from greylisting:

Botnet Statistics [2016-07-10]

detection period: 2016-07-10 00:00-23:59 UTC
total number of suspected botnet IPs: 1321
number of botnet IPs notified to network operators: 1275
number of spam blocked: 2007
recipient count of spam blocked: 3780

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET201
2WASU180
3SONET-NET143
4CNCITYNET122
5UNICOM-ZJ47
6MSFT41
7RingLink39
8CMNET32
9UNICOM-JS30
10WASU-BB27

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China690
2Taiwan346
3United States57
4South Korea26
5Brazil21
6Viet Nam16
7Russian Federation14
8Iran11
9Turkey9
10Indonesia9

Sunday, July 10, 2016

Suspected Bot List [2016-07-09]

detection period: 2016-07-09 00:00-23:59 UTC
number of suspected bots' IPs listed here: 26

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
CO190.7.146.126Colombia
PK175.107.63.2Pakistan
TR213.14.64.190Turkey
US71.95.169.126United States
UY179.27.71.147Uruguay

List from greylisting:

Botnet Statistics [2016-07-09]

detection period: 2016-07-09 00:00-23:59 UTC
total number of suspected botnet IPs: 898
number of botnet IPs notified to network operators: 872
number of spam blocked: 7621
recipient count of spam blocked: 30994

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET207
2SONET-NET170
3CNCITYNET126
4RingLink29
5KORNET-KR24
6CHINANET-GD18
7CMNET10
8CHINANET-JS10
9ALISOFT10
10TencentCloud9

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan383
2China329
3South Korea26
4United States23
5Brazil18
6Russian Federation16
7Turkey9
8Thailand8
9Hong Kong8
10Iran7

Saturday, July 9, 2016

Suspected Bot List [2016-07-08]

detection period: 2016-07-08 00:00-23:59 UTC
number of suspected bots' IPs listed here: 106

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.51.18.145Argentina
BO200.87.110.250Bolivia
PK175.107.63.2Pakistan
UY179.27.71.147Uruguay

List from greylisting:

Botnet Statistics [2016-07-08]

detection period: 2016-07-08 00:00-23:59 UTC
total number of suspected botnet IPs: 1578
number of botnet IPs notified to network operators: 1472
number of spam blocked: 702
recipient count of spam blocked: 9352

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU180
2HINET-NET156
3SONET-NET140
4CNCITYNET132
5UNICOM-ZJ49
6RingLink44
7VNPT-VNNIC-VN31
8MX-USCV4-LACNIC27
9BSNLNET25
10KORNET-KR22

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China604
2Taiwan301
3India126
4Viet Nam65
5Mexico49
6Brazil42
7Peru31
8United States25
9South Korea25
10Russian Federation24

Friday, July 8, 2016

Suspected Bot List [2016-07-07]

detection period: 2016-07-07 00:00-23:59 UTC
number of suspected bots' IPs listed here: 122

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.51.18.145Argentina
BO200.87.110.250Bolivia
PK175.107.63.2Pakistan
UY179.27.71.147Uruguay

List from greylisting:

Botnet Statistics [2016-07-07]

detection period: 2016-07-07 00:00-23:59 UTC
total number of suspected botnet IPs: 1974
number of botnet IPs notified to network operators: 1852
number of spam blocked: 2918
recipient count of spam blocked: 13736

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU442
2SONET-NET141
3HINET-NET134
4CNCITYNET128
5UNICOM-ZJ95
6VNPT-VNNIC-VN75
7RingLink37
8CHINANET-JS37
9WASU-BB34
10UNICOM-JS25

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China973
2Taiwan280
3Viet Nam137
4India113
5Mexico62
6Brazil46
7South Korea27
8Peru25
9United States21
10Turkey20

Thursday, July 7, 2016

Suspected Bot List [2016-07-06]

detection period: 2016-07-06 00:00-23:59 UTC
number of suspected bots' IPs listed here: 91

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.51.18.145Argentina
BO200.87.110.250Bolivia
PK175.107.63.2Pakistan
UY179.27.71.147Uruguay

List from greylisting:

Botnet Statistics [2016-07-06]

detection period: 2016-07-06 00:00-23:59 UTC
total number of suspected botnet IPs: 1521
number of botnet IPs notified to network operators: 1430
number of spam blocked: 8444
recipient count of spam blocked: 35064

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU355
2SONET-NET134
3CNCITYNET109
4UNICOM-ZJ85
5VNPT-VNNIC-VN45
6RingLink43
7WASU-BB40
8CHINANET-JS40
9UNICOM-JS36
10MX-USCV4-LACNIC16

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China844
2Taiwan141
3Viet Nam82
4India56
5Brazil46
6Mexico40
7United States26
8Peru24
9Turkey21
10South Korea19

Wednesday, July 6, 2016

Suspected Bot List [2016-07-05]

detection period: 2016-07-05 00:00-23:59 UTC
number of suspected bots' IPs listed here: 91

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2016-07-05]

detection period: 2016-07-05 00:00-23:59 UTC
total number of suspected botnet IPs: 1652
number of botnet IPs notified to network operators: 1561
number of spam blocked: 1236
recipient count of spam blocked: 9888

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU417
2CNCITYNET135
3SONET-NET120
4UNICOM-ZJ87
5CHINANET-JS59
6HINET-NET53
7UNICOM-JS48
8RingLink48
9WASU-BB33
10VNPT-VNNIC-VN33

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China964
2Taiwan173
3India76
4Viet Nam57
5Mexico33
6Brazil33
7Iran29
8South Korea26
9United States25
10Russian Federation20

Tuesday, July 5, 2016

Suspected Bot List [2016-07-04]

detection period: 2016-07-04 00:00-23:59 UTC
number of suspected bots' IPs listed here: 119

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR186.22.138.150Argentina

List from greylisting:

Botnet Statistics [2016-07-04]

detection period: 2016-07-04 00:00-23:59 UTC
total number of suspected botnet IPs: 1699
number of botnet IPs notified to network operators: 1580
number of spam blocked: 2816
recipient count of spam blocked: 3819

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU404
2SONET-NET145
3HINET-NET101
4UNICOM-ZJ89
5CNCITYNET60
6VNPT-VNNIC-VN52
7UNICOM-JS46
8WASU-BB45
9CHINANET-JS33
10MX-USCV4-LACNIC26

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China786
2Taiwan249
3India132
4Viet Nam101
5Mexico46
6Brazil43
7Iran36
8Turkey20
9United States19
10Peru15

Monday, July 4, 2016

Suspected Bot List [2016-07-03]

detection period: 2016-07-03 00:00-23:59 UTC
number of suspected bots' IPs listed here: 102

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR186.22.138.150Argentina

List from greylisting:

Botnet Statistics [2016-07-03]

detection period: 2016-07-03 00:00-23:59 UTC
total number of suspected botnet IPs: 1524
number of botnet IPs notified to network operators: 1422
number of spam blocked: 1465
recipient count of spam blocked: 25112

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1SONET-NET202
2CNCITYNET168
3WASU156
4HINET-NET127
5RingLink59
6UNICOM-ZJ50
7VNPT-VNNIC-VN43
8WASU-BB23
9KORNET-KR17
10CMNET17

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China616
2Taiwan335
3Viet Nam83
4India54
5Mexico32
6Iran31
7Brazil31
8United States28
9Peru24
10Turkey21

Sunday, July 3, 2016

Botnet Statistics for June 2016

detection period: 2016-06-01 00:00 - 2016-06-30 23:59 UTC
total number of suspected botnet IPs: 20395
number of blocked spams: 107043
recipient count of blocked spams: 1305723

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China11726
2Taiwan3865
3Viet Nam1027
4India546
5United States385
6Mexico282
7Brazil247
8Iran153
9Turkey138
10Peru118
11Russian Federation116
12Indonesia101
13Colombia100
14Argentina70
15Pakistan65
16South Korea65
17Thailand56
18Philippines56
19Romania54
20United Kingdom46
21Saudi Arabia44
22Germany44
23Ukraine43
24Japan43
25Bangladesh43

The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:

RankCountry# of blocked spams
1Poland35225
2China32794
3Germany13342
4Taiwan11953
5United States6278
6South Korea1076
7Thailand970
8Turkey574
9Brazil528
10Colombia470
11United Kingdom455
12Mexico415
13Russian Federation344
14India261
15Peru234
16France167
17Romania156
18Indonesia133
19Netherlands122
20Iran113
21Hong Kong112
22Chile112
23Kenya108
24Pakistan105
25Macau75

The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:

Suspected Bot List [2016-07-02]

detection period: 2016-07-02 00:00-23:59 UTC
number of suspected bots' IPs listed here: 75

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2016-07-02]

detection period: 2016-07-02 00:00-23:59 UTC
total number of suspected botnet IPs: 1044
number of botnet IPs notified to network operators: 969
number of spam blocked: 412
recipient count of spam blocked: 412

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET170
2SONET-NET139
3CNCITYNET129
4RingLink52
5UNICOM-BJ20
6VNPT-VNNIC-VN18
7MX-USCV4-LACNIC16
8KORNET-KR13
9CHINANET-GD13
10TencentCloud11

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China345
2Taiwan315
3India51
4Viet Nam33
5Mexico32
6Iran21
7Peru20
8Brazil19
9Turkey16
10South Korea16

Saturday, July 2, 2016

Suspected Bot List [2016-07-01]

detection period: 2016-07-01 00:00-23:59 UTC
number of suspected bots' IPs listed here: 44

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR186.22.138.150Argentina
BO200.87.110.250Bolivia

List from greylisting:

Botnet Statistics [2016-07-01]

detection period: 2016-07-01 00:00-23:59 UTC
total number of suspected botnet IPs: 1110
number of botnet IPs notified to network operators: 1066
number of spam blocked: 4528
recipient count of spam blocked: 19759

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET171
2CNCITYNET115
3SONET-NET111
4UNICOM-ZJ97
5WASU60
6RingLink32
7WASU-BB26
8CHINANET-JS26
9UNICOM-JS17
10CMNET17

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China518
2Taiwan294
3Viet Nam34
4United States23
5India22
6Brazil21
7Mexico17
8South Korea17
9Iran13
10Turkey12

Friday, July 1, 2016

Suspected Bot List [2016-06-30]

detection period: 2016-06-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 72

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2016-06-30]

detection period: 2016-06-30 00:00-23:59 UTC
total number of suspected botnet IPs: 1734
number of botnet IPs notified to network operators: 1662
number of spam blocked: 1671
recipient count of spam blocked: 4761

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU338
2HINET-NET182
3CNCITYNET155
4SONET-NET136
5UNICOM-ZJ102
6RingLink55
7WASU-BB45
8UNICOM-JS41
9CHINANET-JS41
10VNPT-VNNIC-VN36

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China941
2Taiwan320
3Viet Nam77
4India41
5Brazil30
6Mexico28
7United States23
8South Korea18
9Russian Federation17
10Turkey15