Custom Search

Tuesday, February 28, 2017

Suspected Bot List [2017-02-27]

detection period: 2017-02-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 34

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2017-02-27]

detection period: 2017-02-27 00:00-23:59 UTC
total number of suspected botnet IPs: 878
number of botnet IPs notified to network operators: 844
number of spam blocked: 71358
recipient count of spam blocked: 1998124

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET531
2UNICOM-ZJ65
3WASU-BB45
4VNPT-VNNIC-VN26
5WASU12
6CMNET7
7CHINANET-GD7
8VIETEL-VNNIC-VN6
9FPT-VN6
10BHARTI-IN6

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan531
2China163
3Viet Nam45
4India18
5Peru9
6Iran9
7Brazil9
8Mexico8
9Argentina8
10Thailand7

Monday, February 27, 2017

Suspected Bot List [2017-02-26]

detection period: 2017-02-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 27

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2017-02-26]

detection period: 2017-02-26 00:00-23:59 UTC
total number of suspected botnet IPs: 792
number of botnet IPs notified to network operators: 765
number of spam blocked: 70041
recipient count of spam blocked: 1936138

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET502
2UNICOM-ZJ62
3WASU-BB33
4VNPT-VNNIC-VN19
5WASU10
6CHINANET-GD8
7CMNET7
8VIETEL-VNNIC-VN5
9FPT-VN5
10Chinafic5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan502
2China151
3Viet Nam35
4India13
5Iran8
6United States7
7Mexico7
8United Kingdom6
9Brazil6
10Saudi Arabia4

Sunday, February 26, 2017

Suspected Bot List [2017-02-25]

detection period: 2017-02-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 32

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
ID103.56.207.212Indonesia
IN125.16.12.146India
IN203.192.212.52India
IN223.196.86.228India
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-25]

detection period: 2017-02-25 00:00-23:59 UTC
total number of suspected botnet IPs: 1205
number of botnet IPs notified to network operators: 1173
number of spam blocked: 72806
recipient count of spam blocked: 2036700

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET538
2UNICOM-ZJ91
3WASU-BB64
4CHINANET-JS33
5UNICOM-SD27
6UNICOM-GX24
7VNPT-VNNIC-VN21
8CHINANET-CQ15
9CHINANET-GD14
10WASU13

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan548
2China442
3Viet Nam47
4United States21
5India20
6Brazil15
7Peru9
8Mexico7
9United Kingdom6
10Thailand5

Saturday, February 25, 2017

Suspected Bot List [2017-02-24]

detection period: 2017-02-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 28

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
CO190.60.234.186Colombia
ID103.56.207.212Indonesia
IN125.16.12.146India
IN125.16.240.197India
IN203.192.212.52India
MX189.202.187.68Mexico
RU91.197.234.102Russian Federation
SA212.12.175.222Saudi Arabia
TW106.1.195.68Taiwan
TW123.193.126.130Taiwan
TW180.176.226.2Taiwan
US206.125.41.139United States
US206.125.47.5United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-24]

detection period: 2017-02-24 00:00-23:59 UTC
total number of suspected botnet IPs: 1108
number of botnet IPs notified to network operators: 1081
number of spam blocked: 67356
recipient count of spam blocked: 1940255

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET514
2UNICOM-ZJ47
3UNICOM-SD40
4CHINANET-JS37
5WASU-BB28
6UNICOM-GX26
7CHINANET-CQ25
8CHINANET-GD18
9UNICOM-SX14
10CMNET12

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan531
2China434
3United States29
4Brazil17
5India10
6Italy9
7Colombia8
8Viet Nam6
9Russian Federation6
10South Korea5

Friday, February 24, 2017

Suspected Bot List [2017-02-23]

detection period: 2017-02-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 24

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
GB163.172.21.117United Kingdom
IN125.16.240.17India
IN125.16.240.197India
IN203.192.212.52India
TW123.193.126.130Taiwan
US206.125.47.5United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-23]

detection period: 2017-02-23 00:00-23:59 UTC
total number of suspected botnet IPs: 1089
number of botnet IPs notified to network operators: 1065
number of spam blocked: 73591
recipient count of spam blocked: 2062793

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET489
2UNICOM-ZJ84
3WASU-BB52
4CHINANET-JS27
5UNICOM-GX19
6CMNET19
7CHINANET-GD19
8UNICOM-SD18
9DEDFIBERCO12
10CHINANET-CQ12

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan499
2China430
3United States30
4Russian Federation21
5India18
6Brazil13
7Italy8
8South Korea6
9Colombia5
10Viet Nam3

Thursday, February 23, 2017

Suspected Bot List [2017-02-22]

detection period: 2017-02-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 27

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
GB163.172.21.117United Kingdom
IN125.16.12.146India
IN125.16.240.17India
IN125.16.240.197India
IN203.192.212.52India
SA212.12.175.222Saudi Arabia
TW118.233.118.10Taiwan
TW123.193.126.130Taiwan
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-22]

detection period: 2017-02-22 00:00-23:59 UTC
total number of suspected botnet IPs: 1041
number of botnet IPs notified to network operators: 1015
number of spam blocked: 72550
recipient count of spam blocked: 2021150

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET520
2UNICOM-ZJ65
3WASU-BB47
4CHINANET-GD23
5CHINANET-JS20
6UNICOM-SD17
7UNICOM-GX17
8CMNET14
9UNICOM-HA9
10CHINANET-ZJ8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan531
2China360
3United States29
4Russian Federation21
5India14
6Brazil11
7Ukraine8
8South Korea6
9Italy6
10Colombia6

Wednesday, February 22, 2017

Suspected Bot List [2017-02-21]

detection period: 2017-02-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 49

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2017-02-21]

detection period: 2017-02-21 00:00-23:59 UTC
total number of suspected botnet IPs: 1099
number of botnet IPs notified to network operators: 1050
number of spam blocked: 110582
recipient count of spam blocked: 3232376

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET605
2VNPT-VNNIC-VN31
3CMNET20
4CHINANET-GD19
5CHINANET-AH12
6BHARTI-IN11
7CHINANET-SN9
8CHINANET-JS9
9FPT-VN7
10DEDFIBERCO7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan607
2China176
3Viet Nam56
4India45
5Russian Federation26
6Brazil18
7United States16
8Peru11
9South Korea10
10Ukraine9

Tuesday, February 21, 2017

Suspected Bot List [2017-02-20]

detection period: 2017-02-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 60

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2017-02-20]

detection period: 2017-02-20 00:00-23:59 UTC
total number of suspected botnet IPs: 996
number of botnet IPs notified to network operators: 936
number of spam blocked: 135938
recipient count of spam blocked: 4008566

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET619
2VNPT-VNNIC-VN28
3CHINANET-GD23
4MX-IPMS2-LACNIC7
5FPT-VN7
6CO-ACSA-LACNIC7
7PE-TPSA-LACNIC6
8VIETEL-VNNIC-VN5
9ETC-VNNIC-VN5
10Chinafic5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan621
2China61
3Viet Nam59
4India38
5Mexico20
6Brazil20
7Iran16
8Colombia16
9Turkey15
10Peru9

Monday, February 20, 2017

Suspected Bot List [2017-02-19]

detection period: 2017-02-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 95

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2017-02-19]

detection period: 2017-02-19 00:00-23:59 UTC
total number of suspected botnet IPs: 1302
number of botnet IPs notified to network operators: 1207
number of spam blocked: 138991
recipient count of spam blocked: 4018936

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET616
2VNPT-VNNIC-VN38
3CHINANET-GD31
4CHINANET-AH20
5CMNET16
6BSNLNET14
7CHINANET-JS12
8BHARTI-IN10
9FPT-VN9
10VIETEL-VNNIC-VN7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan619
2China186
3Viet Nam74
4India73
5Russian Federation34
6Mexico24
7Iran24
8Peru15
9Brazil13
10United States12

Sunday, February 19, 2017

Suspected Bots' IP List for January 2017

To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here (as shown below). You are free to use them to create more effective defenses, discover latest trends in cyber attacks, etc.

Suspected Bots IP [2017-01-01]
Suspected Bots IP [2017-01-02]
Suspected Bots IP [2017-01-03]
Suspected Bots IP [2017-01-04]
Suspected Bots IP [2017-01-05]
Suspected Bots IP [2017-01-06]
Suspected Bots IP [2017-01-07]
Suspected Bots IP [2017-01-08]
Suspected Bots IP [2017-01-09]
Suspected Bots IP [2017-01-10]
Suspected Bots IP [2017-01-11]
Suspected Bots IP [2017-01-12]
Suspected Bots IP [2017-01-13]
Suspected Bots IP [2017-01-14]
Suspected Bots IP [2017-01-15]
Suspected Bots IP [2017-01-16]
Suspected Bots IP [2017-01-17]
Suspected Bots IP [2017-01-18]
Suspected Bots IP [2017-01-19]
Suspected Bots IP [2017-01-20]
Suspected Bots IP [2017-01-21]
Suspected Bots IP [2017-01-22]
Suspected Bots IP [2017-01-23]
Suspected Bots IP [2017-01-24]
Suspected Bots IP [2017-01-25]
Suspected Bots IP [2017-01-26]
Suspected Bots IP [2017-01-27]
Suspected Bots IP [2017-01-28]
Suspected Bots IP [2017-01-29]
Suspected Bots IP [2017-01-30]
Suspected Bots IP [2017-01-31]

Suspected Bot List [2017-02-18]

detection period: 2017-02-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 132

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
CO190.60.234.186Colombia
IN125.16.12.146India
IN125.16.240.17India
IN203.192.212.52India
RU91.197.234.102Russian Federation
SA212.12.175.222Saudi Arabia
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-18]

detection period: 2017-02-18 00:00-23:59 UTC
total number of suspected botnet IPs: 1510
number of botnet IPs notified to network operators: 1378
number of spam blocked: 131169
recipient count of spam blocked: 3739338

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET587
2VNPT-VNNIC-VN51
3CHINANET-JS27
4UNICOM-SD22
5BSNLNET18
6FPT-VN16
7CHINANET-AH15
8UNICOM-GX14
9CMNET14
10CHINANET-GD14

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan595
2China296
3India101
4Viet Nam100
5Mexico29
6Iran29
7Russian Federation25
8Brazil25
9Colombia22
10Peru20

Saturday, February 18, 2017

Suspected Bot List [2017-02-17]

detection period: 2017-02-17 00:00-23:59 UTC
number of suspected bots' IPs listed here: 52

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
CO190.242.119.197Colombia
IN125.16.240.17India
IN125.16.240.197India
IN203.192.212.52India
RU91.197.234.102Russian Federation
SA212.12.175.222Saudi Arabia
TW123.193.126.130Taiwan
US206.125.41.139United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-17]

detection period: 2017-02-17 00:00-23:59 UTC
total number of suspected botnet IPs: 1173
number of botnet IPs notified to network operators: 1121
number of spam blocked: 126803
recipient count of spam blocked: 3705937

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET592
2CHINANET-JS25
3CMNET19
4UNICOM-SD18
5CHINANET-GD18
6CHINANET-AH15
7BHARTI-IN12
8CHINANET-ZJ10
9KORNET-KR9
10UNICOM-GX8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan600
2China302
3Russian Federation44
4India34
5United States25
6South Korea15
7Brazil14
8Ukraine13
9Mexico10
10Italy10

Friday, February 17, 2017

Suspected Bot List [2017-02-16]

detection period: 2017-02-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 32

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
IN125.16.12.146India
IN125.16.240.197India
SA212.12.175.222Saudi Arabia
US206.125.41.139United States
US206.125.47.5United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-16]

detection period: 2017-02-16 00:00-23:59 UTC
total number of suspected botnet IPs: 1005
number of botnet IPs notified to network operators: 973
number of spam blocked: 127175
recipient count of spam blocked: 3733398

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET581
2CMNET21
3CHINANET-JS16
4CHINANET-GD15
5UNICOM-SD13
6CHINANET-AH11
7KORNET-KR9
8UNICOM-GX8
9CHINANET-ZJ8
10CHINANET-XJ8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan583
2China225
3Russian Federation38
4United States30
5India21
6Italy12
7South Korea10
8Brazil9
9Colombia6
10Chile6

Thursday, February 16, 2017

Suspected Bot List [2017-02-15]

detection period: 2017-02-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 36

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
IN125.16.12.146India
IN125.16.240.17India
IN125.16.240.197India
SA212.12.175.222Saudi Arabia
TW123.193.126.130Taiwan
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-15]

detection period: 2017-02-15 00:00-23:59 UTC
total number of suspected botnet IPs: 1131
number of botnet IPs notified to network operators: 1095
number of spam blocked: 118449
recipient count of spam blocked: 3504063

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET565
2CHINANET-GD24
3UNICOM-SD20
4CHINANET-JS20
5UNICOM-GX19
6CMNET19
7BHARTI-IN17
8BSNLNET12
9CHINANET-GZ10
10CHINANET-SN8

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan573
2China267
3Russian Federation71
4India47
5United States34
6Italy22
7South Korea13
8Brazil13
9Ukraine11
10United Kingdom6

Wednesday, February 15, 2017

Suspected Bot List [2017-02-14]

detection period: 2017-02-14 00:00-23:59 UTC
number of suspected bots' IPs listed here: 28

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
IN125.16.240.197India
IN203.192.212.52India
SA212.12.175.222Saudi Arabia
TW123.193.126.130Taiwan
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-14]

detection period: 2017-02-14 00:00-23:59 UTC
total number of suspected botnet IPs: 1296
number of botnet IPs notified to network operators: 1268
number of spam blocked: 131629
recipient count of spam blocked: 3548115

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET576
2CHINANET-HN178
3UNICOM-ZJ92
4WASU-BB56
5CHINANET-GD14
6CMNET13
7BSNLNET13
8UNICOM-SD12
9WASU10
10CHINANET-JS10

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan580
2China499
3Russian Federation35
4India34
5United States21
6Brazil15
7Italy11
8South Korea10
9Ukraine9
10United Kingdom8

Tuesday, February 14, 2017

Suspected Bot List [2017-02-13]

detection period: 2017-02-13 00:00-23:59 UTC
number of suspected bots' IPs listed here: 15

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
IN125.16.240.197India
IN203.192.212.52India
RO185.100.86.167Romania
SA212.12.175.222Saudi Arabia
TW123.193.126.130Taiwan
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-13]

detection period: 2017-02-13 00:00-23:59 UTC
total number of suspected botnet IPs: 1527
number of botnet IPs notified to network operators: 1512
number of spam blocked: 130878
recipient count of spam blocked: 3400995

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET745
2CHINANET-HN244
3UNICOM-ZJ89
4WASU-BB65
5VNPT-VNNIC-VN29
6WASU21
7UNICOM-SD21
8CHINANET-JS17
9UNICOM-GX16
10CMNET9

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan753
2China600
3Viet Nam48
4United States18
5Brazil15
6Italy12
7India8
8Thailand6
9Colombia6
10Russian Federation5

Monday, February 13, 2017

Suspected Bot List [2017-02-12]

detection period: 2017-02-12 00:00-23:59 UTC
number of suspected bots' IPs listed here: 21

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
AR190.104.231.246Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
IN125.16.240.197India
IN203.192.212.52India
RO185.100.86.167Romania
RU91.197.234.102Russian Federation
SA212.12.175.222Saudi Arabia
TW106.1.195.68Taiwan
TW118.233.116.192Taiwan
TW123.192.21.125Taiwan
TW123.193.126.130Taiwan
US206.125.41.139United States
US206.125.47.5United States
US206.125.47.7United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-12]

detection period: 2017-02-12 00:00-23:59 UTC
total number of suspected botnet IPs: 1747
number of botnet IPs notified to network operators: 1727
number of spam blocked: 134213
recipient count of spam blocked: 3639704

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET902
2CHINANET-HN165
3UNICOM-ZJ61
4CHINANET-JS50
5UNICOM-SD48
6WASU-BB46
7UNICOM-GX42
8UNICOM-LN18
9CHINANET-CQ17
10CHINANET-GD16

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan934
2China693
3United States26
4Italy15
5Brazil14
6Russian Federation9
7Germany6
8Colombia6
9India4
10United Kingdom4

Sunday, February 12, 2017

Suspected Bot List [2017-02-11]

detection period: 2017-02-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 22

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
AR190.104.231.246Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
IN125.16.240.197India
IN203.192.212.52India
RO185.100.86.167Romania
RU91.197.234.102Russian Federation
SA212.12.175.222Saudi Arabia
TW106.1.195.68Taiwan
TW118.233.116.192Taiwan
TW123.193.126.130Taiwan
US206.125.47.7United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-11]

detection period: 2017-02-11 00:00-23:59 UTC
total number of suspected botnet IPs: 1238
number of botnet IPs notified to network operators: 1216
number of spam blocked: 90613
recipient count of spam blocked: 2178949

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET462
2CHINANET-HN302
3UNICOM-SD40
4CHINANET-JS40
5UNICOM-GX22
6CHINANET-GD19
7CHINANET-CQ13
8CHINANET-ZJ11
9UNICOM-LN10
10CHINANET-ZJ-TZ10

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China630
2Taiwan486
3United States31
4Russian Federation17
5Brazil11
6Italy8
7India7
8South Korea5
9Germany5
10Colombia5

Saturday, February 11, 2017

Suspected Bot List [2017-02-10]

detection period: 2017-02-10 00:00-23:59 UTC
number of suspected bots' IPs listed here: 26

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
AR190.104.231.246Argentina
AR191.85.137.112Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
IN125.16.240.197India
IN203.192.212.52India
RO185.100.86.167Romania
RU91.197.234.102Russian Federation
SA212.12.175.222Saudi Arabia
TW106.1.195.68Taiwan
TW118.233.116.192Taiwan
TW123.194.119.227Taiwan
US206.125.41.139United States
US206.125.47.5United States
US206.125.47.7United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-10]

detection period: 2017-02-10 00:00-23:59 UTC
total number of suspected botnet IPs: 1574
number of botnet IPs notified to network operators: 1548
number of spam blocked: 104920
recipient count of spam blocked: 2629815

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET478
2CHINANET-HN308
3UNICOM-SD67
4UNICOM-ZJ53
5CHINANET-JS53
6UNICOM-GX37
7WASU-BB36
8UNICOM-LN26
9UNICOM-HE26
10UNICOM-SX21

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China947
2Taiwan505
3United States23
4Russian Federation15
5Brazil15
6Italy7
7India6
8Ukraine5
9Germany5
10Colombia5

Friday, February 10, 2017

Suspected Bot List [2017-02-09]

detection period: 2017-02-09 00:00-23:59 UTC
number of suspected bots' IPs listed here: 22

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
AR190.104.231.246Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
IN125.16.240.197India
IN203.192.212.52India
MO27.109.160.130Macau
RO185.100.86.167Romania
RU91.197.234.102Russian Federation
SA212.12.175.222Saudi Arabia
TW106.1.195.68Taiwan
TW118.233.116.192Taiwan
TW123.194.119.227Taiwan
TW123.195.196.105Taiwan
US206.125.41.139United States
US206.125.47.5United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-09]

detection period: 2017-02-09 00:00-23:59 UTC
total number of suspected botnet IPs: 1527
number of botnet IPs notified to network operators: 1506
number of spam blocked: 147670
recipient count of spam blocked: 3965010

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET516
2CHINANET-HN260
3UNICOM-SD72
4UNICOM-GX54
5CHINANET-JS50
6UNICOM-ZJ44
7CHINANET-GD23
8CHINANET-GZ21
9UNICOM-LN19
10WASU-BB18

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China848
2Taiwan556
3Russian Federation21
4United States16
5Brazil15
6Italy8
7India7
8Germany5
9Colombia5
10Ukraine3

Thursday, February 9, 2017

Suspected Bot List [2017-02-08]

detection period: 2017-02-08 00:00-23:59 UTC
number of suspected bots' IPs listed here: 19

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
AR190.104.231.246Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
IN125.16.240.197India
IN203.192.212.52India
MO60.246.96.247Macau
RO185.100.86.167Romania
RU91.197.234.102Russian Federation
SA212.12.175.222Saudi Arabia
TW118.233.116.192Taiwan
TW123.194.119.227Taiwan
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-08]

detection period: 2017-02-08 00:00-23:59 UTC
total number of suspected botnet IPs: 1194
number of botnet IPs notified to network operators: 1176
number of spam blocked: 177542
recipient count of spam blocked: 4693531

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET504
2CHINANET-HN251
3UNICOM-SD31
4UNICOM-GX27
5CHINANET-JS24
6UNICOM-LN15
7CMNET13
8CHINANET-ZJ13
9UNICOM-HE11
10CHINANET-CQ11

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China543
2Taiwan527
3Brazil18
4United States16
5Russian Federation9
6Italy9
7India8
8Germany5
9Colombia5
10Chile5

Wednesday, February 8, 2017

Suspected Bot List [2017-02-07]

detection period: 2017-02-07 00:00-23:59 UTC
number of suspected bots' IPs listed here: 15

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
IN125.16.240.197India
IN203.192.212.52India
RO185.100.86.167Romania
SA212.12.175.222Saudi Arabia
TW118.233.116.192Taiwan
US206.125.47.7United States
US206.125.47.10United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-07]

detection period: 2017-02-07 00:00-23:59 UTC
total number of suspected botnet IPs: 954
number of botnet IPs notified to network operators: 939
number of spam blocked: 180484
recipient count of spam blocked: 4894340

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET496
2CHINANET-HN225
3UNICOM-ZJ40
4WASU-BB35
5WASU8
6TencentCloud6
7RingLink6
8CMNET6
9CHINANET-GD6
10UNICOM-GD5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan499
2China372
3United States16
4Brazil10
5Ukraine6
6India5
7Russian Federation4
8Colombia4
9Romania3
10Germany3

Tuesday, February 7, 2017

Suspected Bot List [2017-02-06]

detection period: 2017-02-06 00:00-23:59 UTC
number of suspected bots' IPs listed here: 14

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
IN125.16.240.197India
IN203.192.212.52India
SA212.12.175.222Saudi Arabia
TW118.233.116.192Taiwan
US206.125.47.7United States
US206.125.47.10United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-06]

detection period: 2017-02-06 00:00-23:59 UTC
total number of suspected botnet IPs: 924
number of botnet IPs notified to network operators: 910
number of spam blocked: 160057
recipient count of spam blocked: 4462173

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET456
2CHINANET-HN140
3UNICOM-ZJ65
4WASU-BB46
5WASU42
6CHINANET-GD9
7UNICOM-GD6
8RingLink6
9UNICOM-SD5
10TencentCloud5

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan460
2China372
3United States18
4Brazil10
5Colombia7
6Russian Federation6
7Italy5
8India5
9Ukraine4
10Pakistan3

Monday, February 6, 2017

Suspected Bot List [2017-02-05]

detection period: 2017-02-05 00:00-23:59 UTC
number of suspected bots' IPs listed here: 23

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
AR190.104.231.246Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
IN125.16.240.197India
IN203.192.212.52India
IN223.196.86.228India
MX189.202.187.68Mexico
TW106.1.51.81Taiwan
TW106.1.195.68Taiwan
TW118.233.116.192Taiwan
US206.125.41.139United States
US206.125.47.5United States
US206.125.47.7United States
US206.125.47.10United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-05]

detection period: 2017-02-05 00:00-23:59 UTC
total number of suspected botnet IPs: 1172
number of botnet IPs notified to network operators: 1149
number of spam blocked: 107953
recipient count of spam blocked: 2840798

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET321
2CHINANET-HN204
3CHINANET-JS52
4UNICOM-SD45
5UNICOM-ZJ29
6UNICOM-GX25
7UNICOM-LN24
8CHINANET-YN19
9WASU17
10CHINANET-AH17

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China702
2Taiwan359
3United States19
4Russian Federation16
5Brazil14
6Italy5
7Germany5
8Colombia5
9South Korea4
10United Kingdom4

Sunday, February 5, 2017

Suspected Bot List [2017-02-04]

detection period: 2017-02-04 00:00-23:59 UTC
number of suspected bots' IPs listed here: 19

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
AR190.104.231.246Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
CO190.242.119.197Colombia
IN125.16.240.197India
IN203.192.212.52India
IN223.196.86.228India
SA212.12.175.222Saudi Arabia
TW106.1.51.81Taiwan
TW106.1.195.68Taiwan
TW118.233.116.192Taiwan
TW123.194.119.227Taiwan
US206.125.41.139United States
US206.125.47.5United States
US206.125.47.7United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-04]

detection period: 2017-02-04 00:00-23:59 UTC
total number of suspected botnet IPs: 953
number of botnet IPs notified to network operators: 934
number of spam blocked: 31874
recipient count of spam blocked: 512657

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-HN208
2HINET-NET70
3CHINANET-JS59
4UNICOM-SD55
5UNICOM-GX41
6CHINANET-ZJ24
7CHINANET-YN24
8UNICOM-LN22
9UNICOM-HE19
10UNICOM-SX18

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China724
2Taiwan119
3United States21
4Brazil20
5Russian Federation12
6Germany6
7Colombia6
8Mexico4
9South Korea4
10United Kingdom4

Saturday, February 4, 2017

Suspected Bot List [2017-02-03]

detection period: 2017-02-03 00:00-23:59 UTC
number of suspected bots' IPs listed here: 21

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
AR190.104.231.246Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
CO190.242.119.197Colombia
IN125.16.240.197India
IN203.192.212.52India
KZ185.19.194.234Kazakhstan
TW106.1.54.147Taiwan
TW106.1.195.68Taiwan
TW118.233.116.192Taiwan
US206.125.41.139United States
US206.125.47.5United States
US206.125.47.7United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-03]

detection period: 2017-02-03 00:00-23:59 UTC
total number of suspected botnet IPs: 487
number of botnet IPs notified to network operators: 466
number of spam blocked: 21135
recipient count of spam blocked: 485505

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-GX42
2HINET-NET36
3CHINANET-JS29
4UNICOM-SD25
5CHINANET-ZJ11
6CHINANET-CQ11
7UNICOM-ZJ10
8UNICOM-SX10
9UNICOM-GD9
10SEEDNET-NET9

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China292
2Taiwan65
3Brazil21
4United States19
5Russian Federation16
6Colombia8
7Germany6
8India5
9Spain5
10South Korea4

Friday, February 3, 2017

Suspected Bot List [2017-02-02]

detection period: 2017-02-02 00:00-23:59 UTC
number of suspected bots' IPs listed here: 29

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
AR190.104.231.246Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
IN125.16.240.197India
IN203.192.212.52India
IN223.196.86.227India
IN223.196.86.228India
KZ185.19.194.234Kazakhstan
RO185.100.86.167Romania
SA212.12.175.222Saudi Arabia
TW106.1.54.147Taiwan
TW106.1.195.68Taiwan
TW118.233.116.192Taiwan
TW123.194.119.227Taiwan
US206.125.41.138United States
US206.125.41.139United States
US206.125.47.5United States
US206.125.47.7United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-02]

detection period: 2017-02-02 00:00-23:59 UTC
total number of suspected botnet IPs: 813
number of botnet IPs notified to network operators: 784
number of spam blocked: 14404
recipient count of spam blocked: 390937

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-JS77
2HINET-NET70
3UNICOM-SD57
4UNICOM-GX39
5CHINANET-GZ27
6UNICOM-LN25
7CHINANET-ZJ19
8CHINANET-CQ19
9UNICOM-ZJ18
10SEEDNET-NET14

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China554
2Taiwan126
3United States20
4Russian Federation15
5Brazil14
6India9
7United Kingdom6
8Germany6
9Colombia6
10Argentina6

Thursday, February 2, 2017

Suspected Bot List [2017-02-01]

detection period: 2017-02-01 00:00-23:59 UTC
number of suspected bots' IPs listed here: 26

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR181.231.28.20Argentina
AR190.104.231.246Argentina
AR200.42.131.70Argentina
BO186.27.126.130Bolivia
CO190.60.234.186Colombia
CO190.242.119.220Colombia
IN125.16.240.197India
IN203.192.212.52India
IN223.196.86.228India
KZ185.19.194.234Kazakhstan
SA212.12.175.222Saudi Arabia
TW106.1.195.68Taiwan
TW118.232.56.63Taiwan
TW118.233.116.192Taiwan
TW123.194.119.227Taiwan
US206.125.41.139United States
US206.125.47.5United States
US206.125.47.7United States
ZA196.46.23.122South Africa

List from greylisting:

Botnet Statistics [2017-02-01]

detection period: 2017-02-01 00:00-23:59 UTC
total number of suspected botnet IPs: 695
number of botnet IPs notified to network operators: 671
number of spam blocked: 14578
recipient count of spam blocked: 229960

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET81
2CHINANET-JS55
3UNICOM-SD49
4UNICOM-GX41
5SEEDNET-NET16
6UNICOM-HE15
7CHINANET-YN15
8CHINANET-GZ14
9UNICOM-ZJ13
10UNICOM-LN13

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China448
2Taiwan130
3United States17
4Brazil16
5Russian Federation11
6Germany9
7Colombia8
8India6
9Argentina5
10South Korea4

Wednesday, February 1, 2017

Botnet Statistics for January 2017

detection period: 2017-01-01 00:00 - 2017-01-31 23:59 UTC
total number of suspected botnet IPs: 5730
number of blocked spams: 551596
recipient count of blocked spams: 2283929

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China4192
2Taiwan520
3United States111
4Brazil100
5Russian Federation66
6Italy58
7India57
8Viet Nam50
9Germany38
10Colombia33
11United Kingdom30
12Argentina26
13South Korea24
14Ukraine22
15Spain22
16Japan20
17Indonesia19
18Romania17
19Poland17
20Netherlands17
21Mexico14
22Armenia14
23France13
24Turkey12
25Pakistan12

The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:

RankCountry# of blocked spams
1Taiwan239181
2China167396
3United States112297
4Poland8544
5Brazil3225
6Colombia2519
7India2439
8Russian Federation1773
9South Korea1287
10Chile930
11Macau859
12Italy703
13Bangladesh620
14Azerbaijan578
15Netherlands543
16South Africa517
17Cambodia504
18El Salvador486
19Ukraine484
20Pakistan449
21Kazakhstan430
22Bolivia409
23Saudi Arabia404
24Argentina383
25United Kingdom368

The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are: