To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here (as shown below). You are free to use them to create more effective defenses, discover latest trends in cyber attacks, etc.
Suspected Bots IP [2018-01-01]
Suspected Bots IP [2018-01-02]
Suspected Bots IP [2018-01-03]
Suspected Bots IP [2018-01-04]
Suspected Bots IP [2018-01-05]
Suspected Bots IP [2018-01-06]
Suspected Bots IP [2018-01-07]
Suspected Bots IP [2018-01-08]
Suspected Bots IP [2018-01-09]
Suspected Bots IP [2018-01-10]
Suspected Bots IP [2018-01-11]
Suspected Bots IP [2018-01-12]
Suspected Bots IP [2018-01-13]
Suspected Bots IP [2018-01-14]
Suspected Bots IP [2018-01-15]
Suspected Bots IP [2018-01-16]
Suspected Bots IP [2018-01-17]
Suspected Bots IP [2018-01-18]
Suspected Bots IP [2018-01-19]
Suspected Bots IP [2018-01-20]
Suspected Bots IP [2018-01-21]
Suspected Bots IP [2018-01-22]
Suspected Bots IP [2018-01-23]
Suspected Bots IP [2018-01-25]
Suspected Bots IP [2018-01-26]
Suspected Bots IP [2018-01-27]
Suspected Bots IP [2018-01-28]
Suspected Bots IP [2018-01-29]
Suspected Bots IP [2018-01-30]
Suspected Bots IP [2018-01-31]
Custom Search
Wednesday, February 28, 2018
Botnet Statistics [2018-02-27]
detection period: 2018-02-27 00:00-23:59 UTC
total number of suspected botnet IPs: 59
number of botnet IPs notified to network operators: 50
number of spam blocked: 28319
recipient count of spam blocked: 768144
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 59
number of botnet IPs notified to network operators: 50
number of spam blocked: 28319
recipient count of spam blocked: 768144
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | LGTELECOM-KR | 7 |
2 | SA-SAHARA-990113 | 2 |
3 | RRNY | 2 |
4 | LINK-NET | 2 |
5 | KORNET-KR | 2 |
6 | CHINANET-ZJ | 2 |
7 | broadNnet-KR | 1 |
8 | WINDSTREAM-COMMUNICATIONS | 1 |
9 | WEBAIRINTERNET | 1 |
10 | VNPT-VNNIC-VN | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | South Korea | 11 |
2 | United States | 7 |
3 | Nigeria | 4 |
4 | China | 4 |
5 | Saudi Arabia | 3 |
6 | Spain | 3 |
7 | Egypt | 3 |
8 | Viet Nam | 2 |
9 | Pakistan | 2 |
10 | India | 2 |
Suspected Bot List [2018-02-27]
detection period: 2018-02-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 9
List from greylisting:
number of suspected bots' IPs listed here: 9
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
AR | 131.108.83.154 | Argentina |
CZ | 185.82.212.95 | Czech Republic |
ES | 81.42.227.135 | Spain |
GR | 62.169.214.53 | Greece |
KW | 37.34.243.227 | Kuwait |
PK | 202.61.51.123 | Pakistan |
SA | 37.216.204.202 | Saudi Arabia |
SA | 212.76.70.131 | Saudi Arabia |
SA | 212.76.76.242 | Saudi Arabia |
List from greylisting:
Tuesday, February 27, 2018
Botnet Statistics [2018-02-26]
detection period: 2018-02-26 00:00-23:59 UTC
total number of suspected botnet IPs: 47
number of botnet IPs notified to network operators: 41
number of spam blocked: 11608
recipient count of spam blocked: 303957
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 47
number of botnet IPs notified to network operators: 41
number of spam blocked: 11608
recipient count of spam blocked: 303957
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | LGTELECOM-KR | 3 |
2 | RRNY | 2 |
3 | CHINANET-ZJ | 2 |
4 | broadNnet-KR | 1 |
5 | WINDSTREAM-COMMUNICATIONS | 1 |
6 | WEBAIRINTERNET | 1 |
7 | VNPT-VNNIC-VN | 1 |
8 | VE-CSVE-LACNIC | 1 |
9 | UNICOM-CN | 1 |
10 | TUNGHO-NET | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | United States | 6 |
2 | South Korea | 5 |
3 | China | 4 |
4 | South Africa | 2 |
5 | Pakistan | 2 |
6 | Iran | 2 |
7 | India | 2 |
8 | Hong Kong | 2 |
9 | Egypt | 2 |
10 | Australia | 2 |
Suspected Bot List [2018-02-26]
detection period: 2018-02-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 6
List from greylisting:
number of suspected bots' IPs listed here: 6
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
GR | 62.169.214.53 | Greece |
KW | 37.34.243.227 | Kuwait |
PK | 202.61.51.123 | Pakistan |
SA | 212.76.76.242 | Saudi Arabia |
TW | 123.195.250.35 | Taiwan |
List from greylisting:
Monday, February 26, 2018
Botnet Statistics [2018-02-25]
detection period: 2018-02-25 00:00-23:59 UTC
total number of suspected botnet IPs: 44
number of botnet IPs notified to network operators: 37
number of spam blocked: 9208
recipient count of spam blocked: 297297
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 44
number of botnet IPs notified to network operators: 37
number of spam blocked: 9208
recipient count of spam blocked: 297297
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | LGTELECOM-KR | 7 |
2 | VNPT-VNNIC-VN | 2 |
3 | SA-SAHARA-990113 | 2 |
4 | KORNET-KR | 2 |
5 | CHINANET-ZJ | 2 |
6 | broadNnet-KR | 1 |
7 | WINDSTREAM-COMMUNICATIONS | 1 |
8 | WEBAIRINTERNET | 1 |
9 | VOLUMEDRIVE | 1 |
10 | UNICOM-CN | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | South Korea | 10 |
2 | United States | 4 |
3 | China | 4 |
4 | Saudi Arabia | 3 |
5 | Viet Nam | 2 |
6 | Pakistan | 2 |
7 | Hong Kong | 2 |
8 | Egypt | 2 |
9 | Australia | 2 |
10 | South Africa | 1 |
Suspected Bot List [2018-02-25]
detection period: 2018-02-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 7
List from greylisting:
number of suspected bots' IPs listed here: 7
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
AR | 131.108.81.216 | Argentina |
GR | 62.169.214.53 | Greece |
KW | 37.34.243.227 | Kuwait |
PK | 202.61.51.123 | Pakistan |
SA | 37.105.192.130 | Saudi Arabia |
SA | 212.76.70.131 | Saudi Arabia |
SA | 212.76.76.242 | Saudi Arabia |
List from greylisting:
Sunday, February 25, 2018
Botnet Statistics [2018-02-24]
detection period: 2018-02-24 00:00-23:59 UTC
total number of suspected botnet IPs: 44
number of botnet IPs notified to network operators: 39
number of spam blocked: 19198
recipient count of spam blocked: 590449
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 44
number of botnet IPs notified to network operators: 39
number of spam blocked: 19198
recipient count of spam blocked: 590449
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | LGTELECOM-KR | 5 |
2 | LINK-NET | 2 |
3 | CHINANET-ZJ | 2 |
4 | WINDSTREAM-COMMUNICATIONS | 1 |
5 | WEBAIRINTERNET | 1 |
6 | VOLUMEDRIVE | 1 |
7 | VNPT-VNNIC-VN | 1 |
8 | UNICOM-CN | 1 |
9 | TPG-AU | 1 |
10 | TELSTRAINTERNET47-AU | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | South Korea | 7 |
2 | United States | 5 |
3 | China | 5 |
4 | Egypt | 3 |
5 | Pakistan | 2 |
6 | Iran | 2 |
7 | Hong Kong | 2 |
8 | Australia | 2 |
9 | South Africa | 1 |
10 | Viet Nam | 1 |
Suspected Bot List [2018-02-24]
detection period: 2018-02-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 5
List from greylisting:
number of suspected bots' IPs listed here: 5
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
GR | 62.169.214.53 | Greece |
KW | 37.34.243.227 | Kuwait |
PK | 202.61.51.123 | Pakistan |
SA | 212.76.76.242 | Saudi Arabia |
List from greylisting:
Saturday, February 24, 2018
Botnet Statistics [2018-02-23]
detection period: 2018-02-23 00:00-23:59 UTC
total number of suspected botnet IPs: 53
number of botnet IPs notified to network operators: 43
number of spam blocked: 29848
recipient count of spam blocked: 545545
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 53
number of botnet IPs notified to network operators: 43
number of spam blocked: 29848
recipient count of spam blocked: 545545
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | LGTELECOM-KR | 6 |
2 | RRNY | 2 |
3 | KORNET-KR | 2 |
4 | CHINANET-ZJ | 2 |
5 | broadNnet-KR | 1 |
6 | WINDSTREAM | 1 |
7 | WEBAIRINTERNET | 1 |
8 | VOLUMEDRIVE | 1 |
9 | VNPT-VNNIC-VN | 1 |
10 | VE-CSVE-LACNIC | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | South Korea | 10 |
2 | United States | 8 |
3 | China | 5 |
4 | Saudi Arabia | 4 |
5 | Egypt | 3 |
6 | Pakistan | 2 |
7 | Netherlands | 2 |
8 | India | 2 |
9 | Viet Nam | 1 |
10 | Venezuela | 1 |
Suspected Bot List [2018-02-23]
detection period: 2018-02-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 10
List from greylisting:
number of suspected bots' IPs listed here: 10
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
AR | 131.108.81.121 | Argentina |
CZ | 185.82.212.95 | Czech Republic |
GR | 62.169.214.53 | Greece |
IN | 202.62.76.14 | India |
KW | 37.34.243.227 | Kuwait |
PK | 202.61.51.123 | Pakistan |
SA | 37.105.192.130 | Saudi Arabia |
SA | 95.218.86.238 | Saudi Arabia |
SA | 212.76.76.242 | Saudi Arabia |
SA | 213.181.172.244 | Saudi Arabia |
List from greylisting:
Friday, February 23, 2018
Botnet Statistics [2018-02-22]
detection period: 2018-02-22 00:00-23:59 UTC
total number of suspected botnet IPs: 55
number of botnet IPs notified to network operators: 48
number of spam blocked: 41895
recipient count of spam blocked: 668764
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 55
number of botnet IPs notified to network operators: 48
number of spam blocked: 41895
recipient count of spam blocked: 668764
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | LGTELECOM-KR | 6 |
2 | LINK-NET | 3 |
3 | KORNET-KR | 3 |
4 | RRNY | 2 |
5 | KTFWING-KR | 2 |
6 | CHINANET-ZJ | 2 |
7 | broadNnet-KR | 1 |
8 | WINDSTREAM | 1 |
9 | WEBAIRINTERNET | 1 |
10 | VNPT-VNNIC-VN | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | South Korea | 12 |
2 | United States | 8 |
3 | Egypt | 4 |
4 | China | 4 |
5 | Netherlands | 3 |
6 | India | 3 |
7 | Pakistan | 2 |
8 | Viet Nam | 1 |
9 | Venezuela | 1 |
10 | Saudi Arabia | 1 |
Suspected Bot List [2018-02-22]
detection period: 2018-02-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 7
List from greylisting:
number of suspected bots' IPs listed here: 7
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
AR | 131.108.82.0 | Argentina |
CZ | 185.82.212.95 | Czech Republic |
GR | 62.169.214.53 | Greece |
KW | 37.34.243.227 | Kuwait |
PK | 202.61.51.123 | Pakistan |
RS | 178.149.102.210 | Serbia |
SA | 212.76.76.242 | Saudi Arabia |
List from greylisting:
Thursday, February 22, 2018
Botnet Statistics [2018-02-21]
detection period: 2018-02-21 00:00-23:59 UTC
total number of suspected botnet IPs: 49
number of botnet IPs notified to network operators: 42
number of spam blocked: 57566
recipient count of spam blocked: 1524554
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 49
number of botnet IPs notified to network operators: 42
number of spam blocked: 57566
recipient count of spam blocked: 1524554
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 4 |
2 | LGTELECOM-KR | 3 |
3 | RRNY | 2 |
4 | LINK-NET | 2 |
5 | KTFWING-KR | 2 |
6 | CHINANET-ZJ | 2 |
7 | WINDSTREAM | 1 |
8 | WEBAIRINTERNET | 1 |
9 | VE-CSVE-LACNIC | 1 |
10 | UNICOM-CN | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | South Korea | 9 |
2 | United States | 8 |
3 | China | 4 |
4 | Egypt | 3 |
5 | Saudi Arabia | 2 |
6 | Serbia | 2 |
7 | Netherlands | 2 |
8 | Australia | 2 |
9 | Viet Nam | 1 |
10 | Venezuela | 1 |
Suspected Bot List [2018-02-21]
detection period: 2018-02-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 7
List from greylisting:
number of suspected bots' IPs listed here: 7
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
GR | 62.169.214.53 | Greece |
PK | 202.61.51.123 | Pakistan |
RS | 89.216.30.202 | Serbia |
RS | 178.149.102.210 | Serbia |
SA | 176.45.240.98 | Saudi Arabia |
SA | 212.76.76.242 | Saudi Arabia |
List from greylisting:
Wednesday, February 21, 2018
Botnet Statistics [2018-02-20]
detection period: 2018-02-20 00:00-23:59 UTC
total number of suspected botnet IPs: 59
number of botnet IPs notified to network operators: 57
number of spam blocked: 47128
recipient count of spam blocked: 1336758
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 59
number of botnet IPs notified to network operators: 57
number of spam blocked: 47128
recipient count of spam blocked: 1336758
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | LGTELECOM-KR | 12 |
2 | KORNET-KR | 3 |
3 | RRNY | 2 |
4 | CHINANET-ZJ | 2 |
5 | broadNnet-KR | 1 |
6 | WINDSTREAM | 1 |
7 | WEBAIRINTERNET | 1 |
8 | VE-CSVE-LACNIC | 1 |
9 | UNICOM-CN | 1 |
10 | TPG-AU | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | South Korea | 18 |
2 | United States | 8 |
3 | Saudi Arabia | 4 |
4 | China | 4 |
5 | Netherlands | 2 |
6 | Iran | 2 |
7 | India | 2 |
8 | Egypt | 2 |
9 | Australia | 2 |
10 | South Africa | 1 |
Suspected Bot List [2018-02-20]
detection period: 2018-02-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 2
List from greylisting:
number of suspected bots' IPs listed here: 2
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
GR | 62.169.214.53 | Greece |
PK | 202.61.51.123 | Pakistan |
List from greylisting:
Tuesday, February 20, 2018
Botnet Statistics for January 2018
detection period: 2018-01-01 00:00 - 2018-01-31 23:59 UTC
total number of suspected botnet IPs: 757
number of blocked spams: 932566
recipient count of blocked spams: 26847830
The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:
The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:
total number of suspected botnet IPs: 757
number of blocked spams: 932566
recipient count of blocked spams: 26847830
The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
Rank | Country | # of suspected botnet IPs |
---|---|---|
1 | China | 540 |
2 | United States | 85 |
3 | Germany | 64 |
4 | Netherlands | 8 |
5 | Costa Rica | 6 |
6 | Canada | 4 |
7 | Romania | 3 |
8 | Norway | 3 |
9 | South Korea | 3 |
10 | India | 3 |
11 | Hong Kong | 3 |
12 | Ukraine | 2 |
13 | Russian Federation | 2 |
14 | New Zealand | 2 |
15 | Nigeria | 2 |
16 | Mexico | 2 |
17 | Myanmar | 2 |
18 | Iceland | 2 |
19 | France | 2 |
20 | Belize | 2 |
21 | South Africa | 1 |
22 | Viet Nam | 1 |
23 | Turkey | 1 |
24 | Singapore | 1 |
25 | Poland | 1 |
The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:
Rank | Country | # of blocked spams |
---|---|---|
1 | China | 463697 |
2 | Brazil | 99792 |
3 | Czech Republic | 87046 |
4 | United States | 66236 |
5 | Ukraine | 34783 |
6 | Hong Kong | 32449 |
7 | South Korea | 20126 |
8 | Macau | 16021 |
9 | Israel | 14703 |
10 | Canada | 14014 |
11 | France | 13166 |
12 | Costa Rica | 10941 |
13 | Netherlands | 10394 |
14 | Romania | 10242 |
15 | Germany | 8378 |
16 | Iceland | 7890 |
17 | Belize | 6566 |
18 | South Africa | 4987 |
19 | Norway | 4310 |
20 | Kyrgyzstan | 2465 |
21 | Singapore | 1521 |
22 | Ireland | 879 |
23 | Mexico | 637 |
24 | New Caledonia | 438 |
25 | Russian Federation | 276 |
The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:
Botnet Statistics for the year of 2017
detection period: 2017-01-01 00:00 - 2017-12-31 23:59 UTC
total number of suspected botnet IPs: 103740
number of blocked spams: 17220086
recipient count of blocked spams: 369595290
detection methods: fake open relay + greylisting
The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:
The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:
total number of suspected botnet IPs: 103740
number of blocked spams: 17220086
recipient count of blocked spams: 369595290
detection methods: fake open relay + greylisting
The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
Rank | Country | # of suspected botnet IPs |
---|---|---|
1 | China | 44902 |
2 | Taiwan | 19140 |
3 | Viet Nam | 8333 |
4 | United States | 7619 |
5 | India | 3218 |
6 | Ukraine | 1738 |
7 | Brazil | 1456 |
8 | Russian Federation | 1107 |
9 | Netherlands | 953 |
10 | Iran | 820 |
11 | Mexico | 775 |
12 | United Kingdom | 718 |
13 | Indonesia | 598 |
14 | Turkey | 558 |
15 | Italy | 535 |
16 | Colombia | 496 |
17 | Poland | 489 |
18 | Peru | 489 |
19 | Argentina | 453 |
20 | South Korea | 439 |
21 | Thailand | 420 |
22 | Romania | 412 |
23 | Hong Kong | 398 |
24 | Pakistan | 386 |
25 | Bulgaria | 341 |
The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:
Rank | Country | # of blocked spams |
---|---|---|
1 | China | 4531866 |
2 | Taiwan | 3890439 |
3 | United States | 3012233 |
4 | Brazil | 840434 |
5 | South Korea | 602432 |
6 | Russian Federation | 462929 |
7 | Poland | 340562 |
8 | Netherlands | 323180 |
9 | Hong Kong | 311700 |
10 | Ukraine | 276767 |
11 | Germany | 263873 |
12 | United Kingdom | 248179 |
13 | Canada | 241403 |
14 | Czech Republic | 205562 |
15 | Venezuela | 187789 |
16 | Azerbaijan | 150585 |
17 | India | 117025 |
18 | Romania | 102556 |
19 | South Africa | 91706 |
20 | Singapore | 73829 |
21 | Norway | 63083 |
22 | Italy | 57475 |
23 | Israel | 56881 |
24 | France | 50498 |
25 | Belize | 48602 |
The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:
Botnet Statistics [2018-02-19]
detection period: 2018-02-19 00:00-23:59 UTC
total number of suspected botnet IPs: 13
number of botnet IPs notified to network operators: 12
number of spam blocked: 38033
recipient count of spam blocked: 892286
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 9 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 13
number of botnet IPs notified to network operators: 12
number of spam blocked: 38033
recipient count of spam blocked: 892286
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 2 |
2 | CHINANET-ZJ | 2 |
3 | VE-CSVE-LACNIC | 1 |
4 | UNICOM-CN | 1 |
5 | NETVIGATOR | 1 |
6 | CZ-WHOISPROTECTION-20141231 | 1 |
7 | CO-ETBE-LACNIC | 1 |
8 | CHINANET-TJ | 1 |
9 | BSNLNET | 1 |
10 | AIRLINERES-CALPOP-COM | 1 |
The top 9 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | South Korea | 2 |
3 | Venezuela | 1 |
4 | United States | 1 |
5 | India | 1 |
6 | Hong Kong | 1 |
7 | Czech Republic | 1 |
8 | Colombia | 1 |
9 | Brazil | 1 |
Suspected Bot List [2018-02-19]
detection period: 2018-02-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Monday, February 19, 2018
Botnet Statistics [2018-02-18]
detection period: 2018-02-18 00:00-23:59 UTC
total number of suspected botnet IPs: 12
number of botnet IPs notified to network operators: 11
number of spam blocked: 33957
recipient count of spam blocked: 1017637
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 8 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 12
number of botnet IPs notified to network operators: 11
number of spam blocked: 33957
recipient count of spam blocked: 1017637
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 2 |
2 | CHINANET-ZJ | 2 |
3 | UNICOM-CN | 1 |
4 | NETVIGATOR | 1 |
5 | CZ-WHOISPROTECTION-20141231 | 1 |
6 | CO-ETBE-LACNIC | 1 |
7 | CHINANET-TJ | 1 |
8 | BSNLNET | 1 |
9 | AIRLINERES-CALPOP-COM | 1 |
10 | 002.558.157/0001-62 | 1 |
The top 8 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | South Korea | 2 |
3 | United States | 1 |
4 | India | 1 |
5 | Hong Kong | 1 |
6 | Czech Republic | 1 |
7 | Colombia | 1 |
8 | Brazil | 1 |
Suspected Bot List [2018-02-18]
detection period: 2018-02-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Sunday, February 18, 2018
Botnet Statistics [2018-02-17]
detection period: 2018-02-17 00:00-23:59 UTC
total number of suspected botnet IPs: 12
number of botnet IPs notified to network operators: 11
number of spam blocked: 42161
recipient count of spam blocked: 1263048
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 8 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 12
number of botnet IPs notified to network operators: 11
number of spam blocked: 42161
recipient count of spam blocked: 1263048
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 2 |
2 | CHINANET-ZJ | 2 |
3 | UNICOM-CN | 1 |
4 | NETVIGATOR | 1 |
5 | CZ-WHOISPROTECTION-20141231 | 1 |
6 | CO-ETBE-LACNIC | 1 |
7 | CHINANET-TJ | 1 |
8 | BSNLNET | 1 |
9 | AIRLINERES-CALPOP-COM | 1 |
10 | 002.558.157/0001-62 | 1 |
The top 8 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | South Korea | 2 |
3 | United States | 1 |
4 | India | 1 |
5 | Hong Kong | 1 |
6 | Czech Republic | 1 |
7 | Colombia | 1 |
8 | Brazil | 1 |
Suspected Bot List [2018-02-17]
detection period: 2018-02-17 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Saturday, February 17, 2018
Botnet Statistics [2018-02-16]
detection period: 2018-02-16 00:00-23:59 UTC
total number of suspected botnet IPs: 12
number of botnet IPs notified to network operators: 11
number of spam blocked: 45330
recipient count of spam blocked: 1236708
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 8 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 12
number of botnet IPs notified to network operators: 11
number of spam blocked: 45330
recipient count of spam blocked: 1236708
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 2 |
2 | CHINANET-ZJ | 2 |
3 | UNICOM-CN | 1 |
4 | NETVIGATOR | 1 |
5 | CZ-WHOISPROTECTION-20141231 | 1 |
6 | CO-ETBE-LACNIC | 1 |
7 | CHINANET-TJ | 1 |
8 | AIRLINERES-CALPOP-COM | 1 |
9 | AFRINIC-20090508 | 1 |
10 | 002.558.157/0001-62 | 1 |
The top 8 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | South Korea | 2 |
3 | United States | 1 |
4 | Nigeria | 1 |
5 | Hong Kong | 1 |
6 | Czech Republic | 1 |
7 | Colombia | 1 |
8 | Brazil | 1 |
Suspected Bot List [2018-02-16]
detection period: 2018-02-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Friday, February 16, 2018
Botnet Statistics [2018-02-15]
detection period: 2018-02-15 00:00-23:59 UTC
total number of suspected botnet IPs: 15
number of botnet IPs notified to network operators: 14
number of spam blocked: 60323
recipient count of spam blocked: 1381447
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 15
number of botnet IPs notified to network operators: 14
number of spam blocked: 60323
recipient count of spam blocked: 1381447
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 2 |
2 | CHINANET-ZJ | 2 |
3 | UNICOM-CN | 1 |
4 | SOLIDSPACE-IP | 1 |
5 | SHAW-COMMUNICATIONS | 1 |
6 | NETVIGATOR | 1 |
7 | CZ-WHOISPROTECTION-20141231 | 1 |
8 | CO-ETBE-LACNIC | 1 |
9 | CHINANET-TJ | 1 |
10 | BSNLNET | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | United States | 2 |
3 | South Korea | 2 |
4 | Nigeria | 1 |
5 | India | 1 |
6 | Hong Kong | 1 |
7 | Czech Republic | 1 |
8 | Colombia | 1 |
9 | Canada | 1 |
10 | Brazil | 1 |
Suspected Bot List [2018-02-15]
detection period: 2018-02-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Thursday, February 15, 2018
Botnet Statistics [2018-02-14]
detection period: 2018-02-14 00:00-23:59 UTC
total number of suspected botnet IPs: 11
number of botnet IPs notified to network operators: 10
number of spam blocked: 49647
recipient count of spam blocked: 1287019
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 8 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 11
number of botnet IPs notified to network operators: 10
number of spam blocked: 49647
recipient count of spam blocked: 1287019
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | CHINANET-ZJ | 2 |
2 | UNICOM-CN | 1 |
3 | SHAW-COMMUNICATIONS | 1 |
4 | NETVIGATOR | 1 |
5 | KORNET-KR | 1 |
6 | CZ-WHOISPROTECTION-20141231 | 1 |
7 | CO-ETBE-LACNIC | 1 |
8 | CHINANET-TJ | 1 |
9 | AIRLINERES-CALPOP-COM | 1 |
10 | 002.558.157/0001-62 | 1 |
The top 8 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | United States | 1 |
3 | South Korea | 1 |
4 | Hong Kong | 1 |
5 | Czech Republic | 1 |
6 | Colombia | 1 |
7 | Canada | 1 |
8 | Brazil | 1 |
Suspected Bot List [2018-02-14]
detection period: 2018-02-14 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Wednesday, February 14, 2018
Botnet Statistics [2018-02-13]
detection period: 2018-02-13 00:00-23:59 UTC
total number of suspected botnet IPs: 13
number of botnet IPs notified to network operators: 12
number of spam blocked: 41601
recipient count of spam blocked: 1024355
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 8 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 13
number of botnet IPs notified to network operators: 12
number of spam blocked: 41601
recipient count of spam blocked: 1024355
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 2 |
2 | CHINANET-ZJ | 2 |
3 | ZOOMNIGERIA | 1 |
4 | UNICOM-CN | 1 |
5 | NETVIGATOR | 1 |
6 | ESTROWEB-01 | 1 |
7 | CZ-WHOISPROTECTION-20141231 | 1 |
8 | CHINANET-TJ | 1 |
9 | ATT | 1 |
10 | AIRLINERES-CALPOP-COM | 1 |
The top 8 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | United States | 2 |
3 | South Korea | 2 |
4 | Netherlands | 1 |
5 | Nigeria | 1 |
6 | Hong Kong | 1 |
7 | Czech Republic | 1 |
8 | Brazil | 1 |
Suspected Bot List [2018-02-13]
detection period: 2018-02-13 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Tuesday, February 13, 2018
Botnet Statistics [2018-02-12]
detection period: 2018-02-12 00:00-23:59 UTC
total number of suspected botnet IPs: 12
number of botnet IPs notified to network operators: 11
number of spam blocked: 33361
recipient count of spam blocked: 782779
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 8 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 12
number of botnet IPs notified to network operators: 11
number of spam blocked: 33361
recipient count of spam blocked: 782779
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | CHINANET-ZJ | 2 |
2 | UNICOM-CN | 1 |
3 | KORNET-KR | 1 |
4 | HOSTWINDS-17-7 | 1 |
5 | ECO-D217587-NET | 1 |
6 | CZ-WHOISPROTECTION-20141231 | 1 |
7 | CO-ETBE-LACNIC | 1 |
8 | CHINANET-TJ | 1 |
9 | BSNLNET | 1 |
10 | AIRLINERES-CALPOP-COM | 1 |
The top 8 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | United States | 2 |
3 | South Korea | 1 |
4 | India | 1 |
5 | Germany | 1 |
6 | Czech Republic | 1 |
7 | Colombia | 1 |
8 | Brazil | 1 |
Suspected Bot List [2018-02-12]
detection period: 2018-02-12 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Monday, February 12, 2018
Botnet Statistics [2018-02-11]
detection period: 2018-02-11 00:00-23:59 UTC
total number of suspected botnet IPs: 12
number of botnet IPs notified to network operators: 11
number of spam blocked: 35459
recipient count of spam blocked: 722444
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 7 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 12
number of botnet IPs notified to network operators: 11
number of spam blocked: 35459
recipient count of spam blocked: 722444
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | CHINANET-ZJ | 2 |
2 | VIS-BLOCK | 1 |
3 | UNICOM-CN | 1 |
4 | KORNET-KR | 1 |
5 | IP2000-ADSL-BAS | 1 |
6 | HOSTWINDS-17-6 | 1 |
7 | CZ-WHOISPROTECTION-20141231 | 1 |
8 | CHINANET-TJ | 1 |
9 | AIRLINERES-CALPOP-COM | 1 |
10 | ADSL250_2 | 1 |
The top 7 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | United States | 3 |
3 | New Caledonia | 1 |
4 | South Korea | 1 |
5 | France | 1 |
6 | Czech Republic | 1 |
7 | Brazil | 1 |
Suspected Bot List [2018-02-11]
detection period: 2018-02-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Sunday, February 11, 2018
Botnet Statistics [2018-02-10]
detection period: 2018-02-10 00:00-23:59 UTC
total number of suspected botnet IPs: 11
number of botnet IPs notified to network operators: 10
number of spam blocked: 44474
recipient count of spam blocked: 731475
The top 9 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 7 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 11
number of botnet IPs notified to network operators: 10
number of spam blocked: 44474
recipient count of spam blocked: 731475
The top 9 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 2 |
2 | CHINANET-ZJ | 2 |
3 | UNICOM-CN | 1 |
4 | CZ-WHOISPROTECTION-20141231 | 1 |
5 | CO-ETBE-LACNIC | 1 |
6 | CHINANET-TJ | 1 |
7 | BSNLNET | 1 |
8 | AIRLINERES-CALPOP-COM | 1 |
9 | 002.558.157/0001-62 | 1 |
The top 7 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | South Korea | 2 |
3 | United States | 1 |
4 | India | 1 |
5 | Czech Republic | 1 |
6 | Colombia | 1 |
7 | Brazil | 1 |
Suspected Bot List [2018-02-10]
detection period: 2018-02-10 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Saturday, February 10, 2018
Botnet Statistics [2018-02-09]
detection period: 2018-02-09 00:00-23:59 UTC
total number of suspected botnet IPs: 13
number of botnet IPs notified to network operators: 11
number of spam blocked: 45142
recipient count of spam blocked: 739286
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 9 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 13
number of botnet IPs notified to network operators: 11
number of spam blocked: 45142
recipient count of spam blocked: 739286
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 2 |
2 | CHINANET-ZJ | 2 |
3 | UNICOM-CN | 1 |
4 | Spectranet-V4 | 1 |
5 | ESTROWEB-01 | 1 |
6 | CZ-WHOISPROTECTION-20141231 | 1 |
7 | CO-ETBE-LACNIC | 1 |
8 | CHINANET-TJ | 1 |
9 | BSNLNET | 1 |
10 | AIRLINERES-CALPOP-COM | 1 |
The top 9 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | South Korea | 2 |
3 | United States | 1 |
4 | Netherlands | 1 |
5 | Nigeria | 1 |
6 | India | 1 |
7 | Czech Republic | 1 |
8 | Colombia | 1 |
9 | Brazil | 1 |
Suspected Bot List [2018-02-09]
detection period: 2018-02-09 00:00-23:59 UTC
number of suspected bots' IPs listed here: 2
List from greylisting:
number of suspected bots' IPs listed here: 2
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
NG | 197.242.102.230 | Nigeria |
List from greylisting:
Friday, February 9, 2018
Botnet Statiistics [2018-02-08]
detection period: 2018-02-08 00:00-23:59 UTC
total number of suspected botnet IPs: 12
number of botnet IPs notified to network operators: 10
number of spam blocked: 61319
recipient count of spam blocked: 746016
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 8 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 12
number of botnet IPs notified to network operators: 10
number of spam blocked: 61319
recipient count of spam blocked: 746016
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 2 |
2 | CHINANET-ZJ | 2 |
3 | UNICOM-CN | 1 |
4 | IT-INTERBUSINESS-20001027 | 1 |
5 | CZ-WHOISPROTECTION-20141231 | 1 |
6 | CO-ETBE-LACNIC | 1 |
7 | CHINANET-TJ | 1 |
8 | BSNLNET | 1 |
9 | AIRLINERES-CALPOP-COM | 1 |
10 | 002.558.157/0001-62 | 1 |
The top 8 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | South Korea | 2 |
3 | United States | 1 |
4 | Italy | 1 |
5 | India | 1 |
6 | Czech Republic | 1 |
7 | Colombia | 1 |
8 | Brazil | 1 |
Suspected Bot List [2018-02-08]
detection period: 2018-02-08 00:00-23:59 UTC
number of suspected bots' IPs listed here: 2
List from greylisting:
number of suspected bots' IPs listed here: 2
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
IT | 217.58.107.218 | Italy |
List from greylisting:
Thursday, February 8, 2018
Botnet Statistics [2018-02-07]
detection period: 2018-02-07 00:00-23:59 UTC
total number of suspected botnet IPs: 10
number of botnet IPs notified to network operators: 9
number of spam blocked: 51053
recipient count of spam blocked: 681513
The top 8 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 6 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 10
number of botnet IPs notified to network operators: 9
number of spam blocked: 51053
recipient count of spam blocked: 681513
The top 8 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 2 |
2 | CHINANET-ZJ | 2 |
3 | UNICOM-CN | 1 |
4 | CZ-WHOISPROTECTION-20141231 | 1 |
5 | CHINANET-TJ | 1 |
6 | BSNLNET | 1 |
7 | AIRLINERES-CALPOP-COM | 1 |
8 | 002.558.157/0001-62 | 1 |
The top 6 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | South Korea | 2 |
3 | United States | 1 |
4 | India | 1 |
5 | Czech Republic | 1 |
6 | Brazil | 1 |
Suspected Bot List [2018-02-07]
detection period: 2018-02-07 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Wednesday, February 7, 2018
Botnet Statistics [2018-02-06]
detection period: 2018-02-06 00:00-23:59 UTC
total number of suspected botnet IPs: 10
number of botnet IPs notified to network operators: 9
number of spam blocked: 39565
recipient count of spam blocked: 711234
The top 8 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 6 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 10
number of botnet IPs notified to network operators: 9
number of spam blocked: 39565
recipient count of spam blocked: 711234
The top 8 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 2 |
2 | CHINANET-ZJ | 2 |
3 | UNICOM-CN | 1 |
4 | CZ-WHOISPROTECTION-20141231 | 1 |
5 | CHINANET-TJ | 1 |
6 | BSNLNET | 1 |
7 | AIRLINERES-CALPOP-COM | 1 |
8 | 002.558.157/0001-62 | 1 |
The top 6 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | South Korea | 2 |
3 | United States | 1 |
4 | India | 1 |
5 | Czech Republic | 1 |
6 | Brazil | 1 |
Suspected Bot List [2018-02-06]
detection period: 2018-02-06 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Tuesday, February 6, 2018
Botnet Statistics [2018-02-05]
detection period: 2018-02-05 00:00-23:59 UTC
total number of suspected botnet IPs: 11
number of botnet IPs notified to network operators: 9
number of spam blocked: 22872
recipient count of spam blocked: 685000
The top 9 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 7 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 11
number of botnet IPs notified to network operators: 9
number of spam blocked: 22872
recipient count of spam blocked: 685000
The top 9 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 2 |
2 | CHINANET-ZJ | 2 |
3 | UNICOM-CN | 1 |
4 | Spectranet-v4 | 1 |
5 | CZ-WHOISPROTECTION-20141231 | 1 |
6 | CHINANET-TJ | 1 |
7 | BSNLNET | 1 |
8 | AIRLINERES-CALPOP-COM | 1 |
9 | 002.558.157/0001-62 | 1 |
The top 7 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | South Korea | 2 |
3 | United States | 1 |
4 | Nigeria | 1 |
5 | India | 1 |
6 | Czech Republic | 1 |
7 | Brazil | 1 |
Suspected Bot List [2018-02-05]
detection period: 2018-02-05 00:00-23:59 UTC
number of suspected bots' IPs listed here: 2
List from greylisting:
number of suspected bots' IPs listed here: 2
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
NG | 197.255.170.223 | Nigeria |
List from greylisting:
Monday, February 5, 2018
Botnet Statistics [2018-02-04]
detection period: 2018-02-04 00:00-23:59 UTC
total number of suspected botnet IPs: 8
number of botnet IPs notified to network operators: 7
number of spam blocked: 24350
recipient count of spam blocked: 729543
The top 7 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 5 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 8
number of botnet IPs notified to network operators: 7
number of spam blocked: 24350
recipient count of spam blocked: 729543
The top 7 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | CHINANET-ZJ | 2 |
2 | UNICOM-CN | 1 |
3 | KORNET-KR | 1 |
4 | CZ-WHOISPROTECTION-20141231 | 1 |
5 | CHINANET-TJ | 1 |
6 | AIRLINERES-CALPOP-COM | 1 |
7 | 002.558.157/0001-62 | 1 |
The top 5 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | United States | 1 |
3 | South Korea | 1 |
4 | Czech Republic | 1 |
5 | Brazil | 1 |
Suspected Bot List [2018-02-04]
detection period: 2018-02-04 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Sunday, February 4, 2018
Botnet Statistics [2018-02-03]
detection period: 2018-02-03 00:00-23:59 UTC
total number of suspected botnet IPs: 9
number of botnet IPs notified to network operators: 8
number of spam blocked: 26129
recipient count of spam blocked: 783087
The top 8 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 6 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 9
number of botnet IPs notified to network operators: 8
number of spam blocked: 26129
recipient count of spam blocked: 783087
The top 8 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | CHINANET-ZJ | 2 |
2 | UNICOM-CN | 1 |
3 | KORNET-KR | 1 |
4 | CZ-WHOISPROTECTION-20141231 | 1 |
5 | CHINANET-TJ | 1 |
6 | BSNLNET | 1 |
7 | AIRLINERES-CALPOP-COM | 1 |
8 | 002.558.157/0001-62 | 1 |
The top 6 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | United States | 1 |
3 | South Korea | 1 |
4 | India | 1 |
5 | Czech Republic | 1 |
6 | Brazil | 1 |
Suspected Bot List [2018-02-03]
detection period: 2018-02-03 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Saturday, February 3, 2018
Botnet Statistics [2018-02-02]
detection period: 2018-02-02 00:00-23:59 UTC
total number of suspected botnet IPs: 8
number of botnet IPs notified to network operators: 7
number of spam blocked: 25572
recipient count of spam blocked: 766377
The top 7 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 5 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 8
number of botnet IPs notified to network operators: 7
number of spam blocked: 25572
recipient count of spam blocked: 766377
The top 7 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | CHINANET-ZJ | 2 |
2 | UNICOM-CN | 1 |
3 | KORNET-KR | 1 |
4 | CZ-WHOISPROTECTION-20141231 | 1 |
5 | CHINANET-TJ | 1 |
6 | AIRLINERES-CALPOP-COM | 1 |
7 | 002.558.157/0001-62 | 1 |
The top 5 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | United States | 1 |
3 | South Korea | 1 |
4 | Czech Republic | 1 |
5 | Brazil | 1 |
Suspected Bot List [2018-02-02]
detection period: 2018-02-02 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Friday, February 2, 2018
Botnet Statistics [2018-02-01]
detection period: 2018-02-01 00:00-23:59 UTC
total number of suspected botnet IPs: 10
number of botnet IPs notified to network operators: 9
number of spam blocked: 26072
recipient count of spam blocked: 773141
The top 9 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 6 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 10
number of botnet IPs notified to network operators: 9
number of spam blocked: 26072
recipient count of spam blocked: 773141
The top 9 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | CHINANET-ZJ | 2 |
2 | UNICOM-CN | 1 |
3 | RRNY | 1 |
4 | KORNET-KR | 1 |
5 | CZ-WHOISPROTECTION-20141231 | 1 |
6 | CHINANET-TJ | 1 |
7 | BSNLNET | 1 |
8 | AIRLINERES-CALPOP-COM | 1 |
9 | 002.558.157/0001-62 | 1 |
The top 6 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | United States | 2 |
3 | South Korea | 1 |
4 | India | 1 |
5 | Czech Republic | 1 |
6 | Brazil | 1 |
Suspected Bot List [2018-02-01]
detection period: 2018-02-01 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Thursday, February 1, 2018
Botnet Statistics [2018-01-31]
detection period: 2018-01-31 00:00-23:59 UTC
total number of suspected botnet IPs: 13
number of botnet IPs notified to network operators: 12
number of spam blocked: 25671
recipient count of spam blocked: 737591
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 9 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 13
number of botnet IPs notified to network operators: 12
number of spam blocked: 25671
recipient count of spam blocked: 737591
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | CHINANET-ZJ | 2 |
2 | VIS-BLOCK | 1 |
3 | UNICOM-CN | 1 |
4 | KORNET-KR | 1 |
5 | ESTROWEB-01 | 1 |
6 | ECO-D217587-NET | 1 |
7 | CZ-WHOISPROTECTION-20141231 | 1 |
8 | CHINANET-TJ | 1 |
9 | AIRLINERES-CALPOP-COM | 1 |
10 | AFRINIC-20090508 | 1 |
The top 9 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 4 |
2 | United States | 2 |
3 | Netherlands | 1 |
4 | Nigeria | 1 |
5 | New Caledonia | 1 |
6 | South Korea | 1 |
7 | Germany | 1 |
8 | Czech Republic | 1 |
9 | Brazil | 1 |
Suspected Bot List [2018-01-31]
detection period: 2018-01-31 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Subscribe to:
Posts (Atom)