To encourage cyber security information sharing (as some form of open data) while still giving victims enough time to clean up their computers, the IP list of suspected infected computers will be released here (as shown below). You are free to use them to create more effective defenses, discover latest trends in cyber attacks, etc.
Suspected Bots IP [2018-03-01]
Suspected Bots IP [2018-03-02]
Suspected Bots IP [2018-03-03]
Suspected Bots IP [2018-03-04]
Suspected Bots IP [2018-03-05]
Suspected Bots IP [2018-03-06]
Suspected Bots IP [2018-03-07]
Suspected Bots IP [2018-03-08]
Suspected Bots IP [2018-03-09]
Suspected Bots IP [2018-03-10]
Suspected Bots IP [2018-03-11]
Suspected Bots IP [2018-03-12]
Suspected Bots IP [2018-03-13]
Suspected Bots IP [2018-03-14]
Suspected Bots IP [2018-03-15]
Suspected Bots IP [2018-03-16]
Suspected Bots IP [2018-03-17]
Suspected Bots IP [2018-03-18]
Suspected Bots IP [2018-03-19]
Suspected Bots IP [2018-03-20]
Suspected Bots IP [2018-03-21]
Suspected Bots IP [2018-03-22]
Suspected Bots IP [2018-03-23]
Suspected Bots IP [2018-03-24]
Suspected Bots IP [2018-03-25]
Suspected Bots IP [2018-03-26]
Suspected Bots IP [2018-03-27]
Suspected Bots IP [2018-03-28]
Suspected Bots IP [2018-03-29]
Suspected Bots IP [2018-03-30]
Suspected Bots IP [2018-03-31]
Custom Search
Monday, April 30, 2018
Botnet Statistics [2018-04-29]
detection period: 2018-04-29 00:00-23:59 UTC
total number of suspected botnet IPs: 253
number of botnet IPs notified to network operators: 233
number of spam blocked: 17568
recipient count of spam blocked: 526344
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 253
number of botnet IPs notified to network operators: 233
number of spam blocked: 17568
recipient count of spam blocked: 526344
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | GO-DADDY-COM-LLC | 7 |
2 | VNPT-VNNIC-VN | 6 |
3 | TencentCloud | 6 |
4 | KORNET-KR | 4 |
5 | broadNnet-KR | 3 |
6 | UNKNOWN | 3 |
7 | HO-2 | 3 |
8 | HINET-NET | 3 |
9 | CMNET | 3 |
10 | CHINANET-ZJ | 3 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 42 |
2 | United States | 39 |
3 | France | 20 |
4 | Germany | 16 |
5 | India | 13 |
6 | Russian Federation | 11 |
7 | Viet Nam | 9 |
8 | South Korea | 7 |
9 | Canada | 7 |
10 | Brazil | 7 |
Suspected Bot List [2018-04-29]
detection period: 2018-04-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 20
List from greylisting:
number of suspected bots' IPs listed here: 20
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
VE | 190.202.116.101 | Venezuela |
List from greylisting:
Sunday, April 29, 2018
Botnet Statistics [2018-04-28]
detection period: 2018-04-28 00:00-23:59 UTC
total number of suspected botnet IPs: 273
number of botnet IPs notified to network operators: 259
number of spam blocked: 29558
recipient count of spam blocked: 773858
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 273
number of botnet IPs notified to network operators: 259
number of spam blocked: 29558
recipient count of spam blocked: 773858
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 8 |
2 | VNPT-VNNIC-VN | 6 |
3 | KORNET-KR | 6 |
4 | broadNnet-KR | 5 |
5 | AMAZON-2011L | 5 |
6 | FR-OVH-20150522 | 4 |
7 | OVH | 3 |
8 | FR-OVH-20060920 | 3 |
9 | CloudVsp | 3 |
10 | hcmccable-net | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | United States | 41 |
2 | China | 33 |
3 | France | 31 |
4 | Viet Nam | 13 |
5 | South Korea | 13 |
6 | Russian Federation | 12 |
7 | Germany | 12 |
8 | Italy | 8 |
9 | Brazil | 8 |
10 | Netherlands | 7 |
Suspected Bot List [2018-04-28]
detection period: 2018-04-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 14
List from greylisting:
number of suspected bots' IPs listed here: 14
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
VE | 190.202.116.101 | Venezuela |
List from greylisting:
Saturday, April 28, 2018
Botnet Statistics [2018-04-27]
detection period: 2018-04-27 00:00-23:59 UTC
total number of suspected botnet IPs: 401
number of botnet IPs notified to network operators: 374
number of spam blocked: 34168
recipient count of spam blocked: 770611
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 401
number of botnet IPs notified to network operators: 374
number of spam blocked: 34168
recipient count of spam blocked: 770611
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 12 |
2 | KORNET-KR | 10 |
3 | GO-DADDY-COM-LLC | 8 |
4 | VNPT-VNNIC-VN | 7 |
5 | LINODE-US | 5 |
6 | HINET-NET | 5 |
7 | TENCENT-CN | 4 |
8 | FR-OVH-20120320 | 4 |
9 | CO-EPME1-LACNIC | 4 |
10 | CO-ACSA-LACNIC | 4 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | United States | 74 |
2 | China | 58 |
3 | France | 35 |
4 | Russian Federation | 23 |
5 | Brazil | 21 |
6 | South Korea | 17 |
7 | Germany | 14 |
8 | India | 13 |
9 | Viet Nam | 11 |
10 | Colombia | 10 |
Suspected Bot List [2018-04-27]
detection period: 2018-04-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 27
List from greylisting:
number of suspected bots' IPs listed here: 27
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
US | 97.80.15.138 | United States |
List from greylisting:
Friday, April 27, 2018
Botnet Statistics [2018-04-26]
detection period: 2018-04-26 00:00-23:59 UTC
total number of suspected botnet IPs: 417
number of botnet IPs notified to network operators: 395
number of spam blocked: 35958
recipient count of spam blocked: 872278
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 417
number of botnet IPs notified to network operators: 395
number of spam blocked: 35958
recipient count of spam blocked: 872278
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 10 |
2 | GO-DADDY-COM-LLC | 10 |
3 | TencentCloud | 8 |
4 | LINODE-US | 8 |
5 | TENCENT-CN | 6 |
6 | CO-ACSA-LACNIC | 6 |
7 | broadNnet-KR | 5 |
8 | OVH | 5 |
9 | VNPT-VNNIC-VN | 4 |
10 | FR-OVH-20120320 | 4 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | United States | 76 |
2 | China | 59 |
3 | France | 37 |
4 | South Korea | 21 |
5 | Germany | 20 |
6 | Russian Federation | 18 |
7 | United Kingdom | 15 |
8 | Colombia | 14 |
9 | Canada | 12 |
10 | Netherlands | 11 |
Suspected Bot List [2018-04-26]
detection period: 2018-04-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 22
List from greylisting:
number of suspected bots' IPs listed here: 22
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
US | 97.80.15.138 | United States |
VE | 190.202.116.101 | Venezuela |
List from greylisting:
Thursday, April 26, 2018
Botnet Statistics [2018-04-25]
detection period: 2018-04-25 00:00-23:59 UTC
total number of suspected botnet IPs: 457
number of botnet IPs notified to network operators: 439
number of spam blocked: 33574
recipient count of spam blocked: 760688
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 457
number of botnet IPs notified to network operators: 439
number of spam blocked: 33574
recipient count of spam blocked: 760688
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 10 |
2 | GO-DADDY-COM-LLC | 10 |
3 | TencentCloud | 9 |
4 | LINODE-US | 8 |
5 | CO-ACSA-LACNIC | 8 |
6 | FR-OVH-20120116 | 7 |
7 | FR-OVH-20060920 | 7 |
8 | broadNnet-KR | 6 |
9 | OVH | 6 |
10 | FR-ILIAD-ENTREPRISES-CUSTOMERS | 6 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | United States | 78 |
2 | France | 65 |
3 | China | 51 |
4 | Germany | 48 |
5 | United Kingdom | 23 |
6 | South Korea | 19 |
7 | Russian Federation | 17 |
8 | Canada | 15 |
9 | Colombia | 12 |
10 | Viet Nam | 10 |
Suspected Bot List [2018-04-25]
detection period: 2018-04-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 18
List from greylisting:
number of suspected bots' IPs listed here: 18
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|
List from greylisting:
Wednesday, April 25, 2018
Botnet Statistics [2018-04-24]
detection period: 2018-04-24 00:00-23:59 UTC
total number of suspected botnet IPs: 118
number of botnet IPs notified to network operators: 109
number of spam blocked: 42662
recipient count of spam blocked: 901887
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 118
number of botnet IPs notified to network operators: 109
number of spam blocked: 42662
recipient count of spam blocked: 901887
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | KORNET-KR | 7 |
2 | TencentCloud | 4 |
3 | HINET-NET | 3 |
4 | broadNnet-KR | 2 |
5 | MSFT | 2 |
6 | DIX-CL | 2 |
7 | CHINANET-ZJ | 2 |
8 | CHINANET-GD | 2 |
9 | micronet | 1 |
10 | hcmccable-net | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 23 |
2 | United States | 16 |
3 | South Korea | 10 |
4 | India | 6 |
5 | France | 6 |
6 | Germany | 6 |
7 | Brazil | 6 |
8 | Russian Federation | 5 |
9 | Taiwan | 4 |
10 | United Kingdom | 4 |
Suspected Bot List [2018-04-24]
detection period: 2018-04-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 10
List from greylisting:
number of suspected bots' IPs listed here: 10
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
US | 75.139.49.132 | United States |
VE | 190.202.116.101 | Venezuela |
List from greylisting:
Tuesday, April 24, 2018
Botnet Statistics [2018-04-23]
detection period: 2018-04-23 00:00-23:59 UTC
total number of suspected botnet IPs: 156
number of botnet IPs notified to network operators: 146
number of spam blocked: 36621
recipient count of spam blocked: 922580
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 156
number of botnet IPs notified to network operators: 146
number of spam blocked: 36621
recipient count of spam blocked: 922580
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 7 |
2 | broadNnet-KR | 4 |
3 | CMNET | 4 |
4 | MSFT | 3 |
5 | KORNET-KR | 3 |
6 | CHINANET-GD | 3 |
7 | hcmccable-net | 2 |
8 | VNPT-VNNIC-VN | 2 |
9 | TENCENT-CN | 2 |
10 | TELKOMNET | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 31 |
2 | United States | 21 |
3 | South Korea | 10 |
4 | France | 9 |
5 | Russian Federation | 8 |
6 | Indonesia | 8 |
7 | Viet Nam | 7 |
8 | Brazil | 6 |
9 | India | 4 |
10 | Germany | 4 |
Suspected Bot List [2018-04-23]
detection period: 2018-04-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 10
List from greylisting:
number of suspected bots' IPs listed here: 10
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
VE | 190.202.116.101 | Venezuela |
List from greylisting:
Monday, April 23, 2018
Botnet Statistics for March 2018
detection period: 2018-03-01 00:00 - 2018-03-31 23:59 UTC
total number of suspected botnet IPs: 1273
number of blocked spams: 1005516
recipient count of blocked spams: 26718540
The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:
The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:
total number of suspected botnet IPs: 1273
number of blocked spams: 1005516
recipient count of blocked spams: 26718540
The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
Rank | Country | # of suspected botnet IPs |
---|---|---|
1 | China | 251 |
2 | United States | 167 |
3 | South Korea | 139 |
4 | Viet Nam | 80 |
5 | France | 60 |
6 | Russian Federation | 40 |
7 | India | 39 |
8 | Brazil | 39 |
9 | Egypt | 26 |
10 | Germany | 26 |
11 | Indonesia | 25 |
12 | United Kingdom | 25 |
13 | Italy | 21 |
14 | Taiwan | 20 |
15 | Netherlands | 20 |
16 | Canada | 17 |
17 | Australia | 15 |
18 | Japan | 13 |
19 | Spain | 13 |
20 | Hong Kong | 11 |
21 | Argentina | 11 |
22 | Singapore | 10 |
23 | Ukraine | 9 |
24 | Thailand | 9 |
25 | Nigeria | 9 |
The top 25 countries (as defined by the 2-character country code), ordered by number of blocked spams are:
Rank | Country | # of blocked spams |
---|---|---|
1 | China | 562224 |
2 | Czech Republic | 123991 |
3 | United States | 59945 |
4 | Venezuela | 58679 |
5 | Hong Kong | 54595 |
6 | Netherlands | 48164 |
7 | Brazil | 40364 |
8 | United Kingdom | 17635 |
9 | Ireland | 12149 |
10 | Seychelles | 4735 |
11 | Poland | 4587 |
12 | Tunisia | 4256 |
13 | Hungary | 3914 |
14 | Sweden | 2348 |
15 | Italy | 1663 |
16 | South Korea | 1636 |
17 | India | 1156 |
18 | ZZ | 1121 |
19 | France | 749 |
20 | Colombia | 465 |
21 | Pakistan | 183 |
22 | Egypt | 128 |
23 | Belgium | 103 |
24 | Saudi Arabia | 94 |
25 | Viet Nam | 82 |
The top 25 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:
Botnet Statistics [2018-04-22]
detection period: 2018-04-22 00:00-23:59 UTC
total number of suspected botnet IPs: 91
number of botnet IPs notified to network operators: 90
number of spam blocked: 23075
recipient count of spam blocked: 701705
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 91
number of botnet IPs notified to network operators: 90
number of spam blocked: 23075
recipient count of spam blocked: 701705
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 4 |
2 | UNITEDPROTECTION-NET | 3 |
3 | CHINANET-ZJ | 3 |
4 | NETVIGATOR | 2 |
5 | KORNET-KR | 2 |
6 | HOSTWAY-05 | 2 |
7 | DXTNET | 2 |
8 | CHINANET-JX | 2 |
9 | CHINANET-JS | 2 |
10 | CHINANET-GD | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 28 |
2 | United States | 17 |
3 | Russian Federation | 6 |
4 | France | 5 |
5 | Viet Nam | 3 |
6 | South Korea | 3 |
7 | Brazil | 3 |
8 | Singapore | 2 |
9 | Hong Kong | 2 |
10 | United Kingdom | 2 |
Suspected Bot List [2018-04-22]
detection period: 2018-04-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1
List from greylisting:
number of suspected bots' IPs listed here: 1
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|
List from greylisting:
Sunday, April 22, 2018
Botnet Statistics [2018-04-21]
detection period: 2018-04-21 00:00-23:59 UTC
total number of suspected botnet IPs: 99
number of botnet IPs notified to network operators: 93
number of spam blocked: 23429
recipient count of spam blocked: 701913
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 99
number of botnet IPs notified to network operators: 93
number of spam blocked: 23429
recipient count of spam blocked: 701913
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 7 |
2 | KORNET-KR | 4 |
3 | CO-ACSA-LACNIC | 3 |
4 | BSNLNET | 3 |
5 | VNPT-VNNIC-VN | 2 |
6 | UNICOM-CN | 2 |
7 | TELKOMNET | 2 |
8 | LINTASARTA-NET | 2 |
9 | HOSTWAY-05 | 2 |
10 | DOPI1 | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 19 |
2 | United States | 13 |
3 | India | 8 |
4 | Indonesia | 8 |
5 | South Korea | 7 |
6 | Colombia | 4 |
7 | Viet Nam | 3 |
8 | Russian Federation | 3 |
9 | France | 3 |
10 | Brazil | 3 |
Suspected Bot List [2018-04-21]
detection period: 2018-04-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 6
List from greylisting:
number of suspected bots' IPs listed here: 6
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
VE | 190.202.116.101 | Venezuela |
List from greylisting:
Saturday, April 21, 2018
Botnet Statistics [2018-04-20]
detection period: 2018-04-20 00:00-23:59 UTC
total number of suspected botnet IPs: 127
number of botnet IPs notified to network operators: 114
number of spam blocked: 29849
recipient count of spam blocked: 852465
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 127
number of botnet IPs notified to network operators: 114
number of spam blocked: 29849
recipient count of spam blocked: 852465
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 11 |
2 | broadNnet-KR | 4 |
3 | KORNET-KR | 3 |
4 | CHINANET-ZJ | 3 |
5 | hcmccable-net | 2 |
6 | UNICOM-LN | 2 |
7 | TRIPLETNET-TH | 2 |
8 | TN-ATI-20061212 | 2 |
9 | THAINET-TH | 2 |
10 | TATACOMM-IN | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 36 |
2 | United States | 17 |
3 | India | 10 |
4 | South Korea | 9 |
5 | France | 9 |
6 | Thailand | 5 |
7 | Russian Federation | 5 |
8 | Viet Nam | 4 |
9 | Indonesia | 4 |
10 | Canada | 3 |
Suspected Bot List [2018-04-20]
detection period: 2018-04-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 13
List from greylisting:
number of suspected bots' IPs listed here: 13
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
HK | 45.115.36.59 | Hong Kong |
VE | 190.202.116.101 | Venezuela |
List from greylisting:
Friday, April 20, 2018
Botnet Statistics [2018-04-19]
detection period: 2018-04-19 00:00-23:59 UTC
total number of suspected botnet IPs: 94
number of botnet IPs notified to network operators: 88
number of spam blocked: 41192
recipient count of spam blocked: 801680
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 94
number of botnet IPs notified to network operators: 88
number of spam blocked: 41192
recipient count of spam blocked: 801680
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 7 |
2 | KORNET-KR | 5 |
3 | CHINANET-ZJ | 3 |
4 | broadNnet-KR | 2 |
5 | UCLOUD-NET | 2 |
6 | TIMCL-MM | 2 |
7 | NETVIGATOR | 2 |
8 | HOSTWAY-05 | 2 |
9 | hcmccable-net | 1 |
10 | VPSONLINE-VN | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 23 |
2 | United States | 10 |
3 | South Korea | 7 |
4 | Russian Federation | 6 |
5 | France | 6 |
6 | Viet Nam | 5 |
7 | India | 4 |
8 | Hong Kong | 3 |
9 | Colombia | 3 |
10 | Brazil | 3 |
Suspected Bot List [2018-04-19]
detection period: 2018-04-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 6
List from greylisting:
number of suspected bots' IPs listed here: 6
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|
List from greylisting:
Thursday, April 19, 2018
Botnet Statistics [2018-04-18]
detection period: 2018-04-18 00:00-23:59 UTC
total number of suspected botnet IPs: 133
number of botnet IPs notified to network operators: 123
number of spam blocked: 46074
recipient count of spam blocked: 1221451
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 133
number of botnet IPs notified to network operators: 123
number of spam blocked: 46074
recipient count of spam blocked: 1221451
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 10 |
2 | KORNET-KR | 6 |
3 | GO-DADDY-COM-LLC | 4 |
4 | NETVIGATOR | 3 |
5 | CHINANET-ZJ | 3 |
6 | BSNLNET | 3 |
7 | UNICOM-CN | 2 |
8 | TIMCL-MM | 2 |
9 | THAINET-TH | 2 |
10 | MX-USCV4-LACNIC | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 27 |
2 | United States | 20 |
3 | South Korea | 10 |
4 | India | 10 |
5 | Russian Federation | 7 |
6 | Indonesia | 6 |
7 | Thailand | 5 |
8 | France | 5 |
9 | Brazil | 5 |
10 | Hong Kong | 4 |
Suspected Bot List [2018-04-18]
detection period: 2018-04-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 10
List from greylisting:
number of suspected bots' IPs listed here: 10
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
VE | 190.202.116.101 | Venezuela |
List from greylisting:
Wednesday, April 18, 2018
Botnet Statistics [2018-04-17]
detection period: 2018-04-17 00:00-23:59 UTC
total number of suspected botnet IPs: 150
number of botnet IPs notified to network operators: 142
number of spam blocked: 27403
recipient count of spam blocked: 706179
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 150
number of botnet IPs notified to network operators: 142
number of spam blocked: 27403
recipient count of spam blocked: 706179
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 8 |
2 | KORNET-KR | 5 |
3 | HINET-NET | 4 |
4 | CHINANET-ZJ | 4 |
5 | NETVIGATOR | 3 |
6 | MSFT | 3 |
7 | HOSTWAY-05 | 3 |
8 | GO-DADDY-COM-LLC | 3 |
9 | TIMCL-MM | 2 |
10 | TENCENT-CN | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 35 |
2 | United States | 25 |
3 | India | 10 |
4 | Russian Federation | 9 |
5 | South Korea | 8 |
6 | France | 7 |
7 | Taiwan | 5 |
8 | Indonesia | 4 |
9 | Hong Kong | 4 |
10 | Brazil | 4 |
Tuesday, April 17, 2018
Botnet Statistics [2018-04-16]
detection period: 2018-04-16 00:00-23:59 UTC
total number of suspected botnet IPs: 104
number of botnet IPs notified to network operators: 100
number of spam blocked: 25981
recipient count of spam blocked: 741249
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 104
number of botnet IPs notified to network operators: 100
number of spam blocked: 25981
recipient count of spam blocked: 741249
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | HINET-NET | 5 |
2 | TencentCloud | 3 |
3 | VNPT-VNNIC-VN | 2 |
4 | VE-CSVE-LACNIC | 2 |
5 | UNICOM-LN | 2 |
6 | UNICOM-CN | 2 |
7 | TN-ATI-20061212 | 2 |
8 | TATACOMM-IN | 2 |
9 | OVH | 2 |
10 | KORNET-KR | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 26 |
2 | United States | 14 |
3 | India | 7 |
4 | France | 6 |
5 | Taiwan | 5 |
6 | Viet Nam | 4 |
7 | South Korea | 4 |
8 | Brazil | 4 |
9 | Venezuela | 3 |
10 | Hong Kong | 3 |
Suspected Bot List [2018-04-16]
detection period: 2018-04-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 4
List from greylisting:
number of suspected bots' IPs listed here: 4
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|
List from greylisting:
Monday, April 16, 2018
Botnet Statistics [2018-04-15]
detection period: 2018-04-15 00:00-23:59 UTC
total number of suspected botnet IPs: 101
number of botnet IPs notified to network operators: 89
number of spam blocked: 48959
recipient count of spam blocked: 1163371
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 101
number of botnet IPs notified to network operators: 89
number of spam blocked: 48959
recipient count of spam blocked: 1163371
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 5 |
2 | HINET-NET | 4 |
3 | KORNET-KR | 3 |
4 | CHINANET-GD | 3 |
5 | VNPT-VNNIC-VN | 2 |
6 | CMNET | 2 |
7 | CHINANET-ZJ | 2 |
8 | BEAMTELE-IN | 2 |
9 | broadNnet-KR | 1 |
10 | WASUHZ | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 24 |
2 | United States | 10 |
3 | France | 6 |
4 | Taiwan | 4 |
5 | South Korea | 4 |
6 | India | 4 |
7 | Argentina | 4 |
8 | Russian Federation | 3 |
9 | Germany | 3 |
10 | Colombia | 3 |
Suspected Bot List [2018-04-15]
detection period: 2018-04-15 00:00-23:59 UTC
number of suspected bots' IPs listed here: 12
List from greylisting:
number of suspected bots' IPs listed here: 12
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|
List from greylisting:
Sunday, April 15, 2018
Botnet Statistics [2018-04-14]
detection period: 2018-04-14 00:00-23:59 UTC
total number of suspected botnet IPs: 83
number of botnet IPs notified to network operators: 80
number of spam blocked: 40047
recipient count of spam blocked: 1115176
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 83
number of botnet IPs notified to network operators: 80
number of spam blocked: 40047
recipient count of spam blocked: 1115176
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | CHINANET-ZJ | 3 |
2 | broadNnet-KR | 2 |
3 | TencentCloud | 2 |
4 | CMNET | 2 |
5 | CHINANET-TJ | 2 |
6 | Xpeed-KR | 1 |
7 | VIS-70-104 | 1 |
8 | VE-CSVE-LACNIC | 1 |
9 | VBG-NET | 1 |
10 | UNITEDPROTECTION-NET | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 21 |
2 | United States | 12 |
3 | South Korea | 5 |
4 | Brazil | 5 |
5 | Colombia | 4 |
6 | United Kingdom | 3 |
7 | France | 3 |
8 | Germany | 3 |
9 | Canada | 3 |
10 | Bulgaria | 3 |
Suspected Bot List [2018-04-14]
detection period: 2018-04-14 00:00-23:59 UTC
number of suspected bots' IPs listed here: 3
List from greylisting:
number of suspected bots' IPs listed here: 3
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|
List from greylisting:
Saturday, April 14, 2018
Botnet Statistics [2018-04-13]
detection period: 2018-04-13 00:00-23:59 UTC
total number of suspected botnet IPs: 105
number of botnet IPs notified to network operators: 99
number of spam blocked: 33778
recipient count of spam blocked: 953935
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 105
number of botnet IPs notified to network operators: 99
number of spam blocked: 33778
recipient count of spam blocked: 953935
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 5 |
2 | UCLOUD-NET | 3 |
3 | OVH | 3 |
4 | HINET-NET | 3 |
5 | UNICOM-CN | 2 |
6 | TENCENT-CN | 2 |
7 | CHINANET-ZJ | 2 |
8 | CHINANET-GD | 2 |
9 | YUNIFY-NET | 1 |
10 | Xpeed-KR | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 30 |
2 | United States | 13 |
3 | France | 6 |
4 | Taiwan | 4 |
5 | Russian Federation | 4 |
6 | Italy | 4 |
7 | Hong Kong | 4 |
8 | Germany | 4 |
9 | Turkey | 3 |
10 | India | 3 |
Suspected Bot List [2018-04-13]
detection period: 2018-04-13 00:00-23:59 UTC
number of suspected bots' IPs listed here: 6
List from greylisting:
number of suspected bots' IPs listed here: 6
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|
List from greylisting:
Friday, April 13, 2018
Botnet Statistics [2018-04-12]
detection period: 2018-04-12 00:00-23:59 UTC
total number of suspected botnet IPs: 109
number of botnet IPs notified to network operators: 100
number of spam blocked: 49195
recipient count of spam blocked: 1334823
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 109
number of botnet IPs notified to network operators: 100
number of spam blocked: 49195
recipient count of spam blocked: 1334823
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | CHINANET-ZJ | 4 |
2 | TencentCloud | 3 |
3 | MSFT | 3 |
4 | broadNnet-KR | 2 |
5 | VNPT-VNNIC-VN | 2 |
6 | TENCENT-CN | 2 |
7 | TATACOMM-IN | 2 |
8 | KORNET-KR | 2 |
9 | HOSTWAY-05 | 2 |
10 | CHINANET-JS | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 28 |
2 | United States | 20 |
3 | Russian Federation | 7 |
4 | India | 7 |
5 | South Korea | 6 |
6 | Brazil | 5 |
7 | Viet Nam | 4 |
8 | Indonesia | 3 |
9 | Hong Kong | 3 |
10 | France | 3 |
Suspected Bot List [2018-04-12]
detection period: 2018-04-12 00:00-23:59 UTC
number of suspected bots' IPs listed here: 9
List from greylisting:
number of suspected bots' IPs listed here: 9
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Thursday, April 12, 2018
Botnet Statistics [2018-04-11]
detection period: 2018-04-11 00:00-23:59 UTC
total number of suspected botnet IPs: 194
number of botnet IPs notified to network operators: 178
number of spam blocked: 47468
recipient count of spam blocked: 1338129
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 194
number of botnet IPs notified to network operators: 178
number of spam blocked: 47468
recipient count of spam blocked: 1338129
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 8 |
2 | MSFT | 5 |
3 | KORNET-KR | 5 |
4 | JDCOM | 4 |
5 | HOSTWAY-05 | 4 |
6 | FR-OVH-20060920 | 4 |
7 | broadNnet-KR | 3 |
8 | DOPI1 | 3 |
9 | CHINANET-JS | 3 |
10 | ULTICLOUD | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 37 |
2 | United States | 33 |
3 | Russian Federation | 11 |
4 | South Korea | 11 |
5 | France | 11 |
6 | Indonesia | 10 |
7 | India | 8 |
8 | Taiwan | 6 |
9 | United Kingdom | 5 |
10 | Germany | 5 |
Suspected Bot List [2018-04-11]
detection period: 2018-04-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 16
List from greylisting:
number of suspected bots' IPs listed here: 16
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
US | 148.72.144.18 | United States |
List from greylisting:
Wednesday, April 11, 2018
Botnet Statistics [2018-04-10]
detection period: 2018-04-10 00:00-23:59 UTC
total number of suspected botnet IPs: 110
number of botnet IPs notified to network operators: 92
number of spam blocked: 49545
recipient count of spam blocked: 1313568
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 110
number of botnet IPs notified to network operators: 92
number of spam blocked: 49545
recipient count of spam blocked: 1313568
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 4 |
2 | CHINANET-ZJ | 4 |
3 | MSFT | 3 |
4 | ULTICLOUD | 2 |
5 | NETVIGATOR | 2 |
6 | KORNET-KR | 2 |
7 | JDCOM | 2 |
8 | C_and_C_Advanced_Online_Services_Ltd | 2 |
9 | VODAFONE-IT-63 | 1 |
10 | VELTON-TC-LUGANSK-NET | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 22 |
2 | United States | 18 |
3 | Russian Federation | 8 |
4 | India | 7 |
5 | Germany | 6 |
6 | France | 5 |
7 | Viet Nam | 3 |
8 | South Korea | 3 |
9 | Indonesia | 3 |
10 | Hong Kong | 3 |
Suspected Bot List [2018-04-10]
detection period: 2018-04-10 00:00-23:59 UTC
number of suspected bots' IPs listed here: 18
List from greylisting:
number of suspected bots' IPs listed here: 18
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
US | 148.72.144.18 | United States |
List from greylisting:
Tuesday, April 10, 2018
Botnet Statistics [2018-04-09]
detection period: 2018-04-09 00:00-23:59 UTC
total number of suspected botnet IPs: 84
number of botnet IPs notified to network operators: 79
number of spam blocked: 54252
recipient count of spam blocked: 1181687
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 84
number of botnet IPs notified to network operators: 79
number of spam blocked: 54252
recipient count of spam blocked: 1181687
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | VNPT-VNNIC-VN | 5 |
2 | LAOTELECOM | 3 |
3 | UNICOM-SD | 2 |
4 | UNICOM-LN | 2 |
5 | UNICOM-CN | 2 |
6 | RU-AVANGARD-DSL | 2 |
7 | MSFT | 2 |
8 | HINET-NET | 2 |
9 | Cyanlink | 2 |
10 | CMNET | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 15 |
2 | United States | 8 |
3 | Russian Federation | 8 |
4 | Viet Nam | 7 |
5 | France | 7 |
6 | Brazil | 5 |
7 | Laos | 3 |
8 | United Kingdom | 3 |
9 | Taiwan | 2 |
10 | South Korea | 2 |
Suspected Bot List [2018-04-09]
detection period: 2018-04-09 00:00-23:59 UTC
number of suspected bots' IPs listed here: 5
List from greylisting:
number of suspected bots' IPs listed here: 5
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Monday, April 9, 2018
Botnet Statistics [2018-04-08]
detection period: 2018-04-08 00:00-23:59 UTC
total number of suspected botnet IPs: 164
number of botnet IPs notified to network operators: 146
number of spam blocked: 42668
recipient count of spam blocked: 1277345
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 164
number of botnet IPs notified to network operators: 146
number of spam blocked: 42668
recipient count of spam blocked: 1277345
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | MSFT | 5 |
2 | TencentCloud | 4 |
3 | HINET-NET | 4 |
4 | Bofinet-Wifi-FTTx | 4 |
5 | hcmccable-net | 3 |
6 | broadNnet-KR | 3 |
7 | TENCENT-CN | 3 |
8 | TEDATA-20091105 | 3 |
9 | DOPI1 | 3 |
10 | DIGITALOCEAN-AP | 3 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 32 |
2 | United States | 16 |
3 | India | 14 |
4 | Russian Federation | 10 |
5 | Indonesia | 7 |
6 | Viet Nam | 6 |
7 | South Korea | 6 |
8 | Singapore | 5 |
9 | United Kingdom | 5 |
10 | France | 5 |
Suspected Bot List [2018-04-08]
detection period: 2018-04-08 00:00-23:59 UTC
number of suspected bots' IPs listed here: 18
List from greylisting:
number of suspected bots' IPs listed here: 18
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
US | 148.72.144.18 | United States |
List from greylisting:
Sunday, April 8, 2018
Botnet Statistics [2018-04-07]
detection period: 2018-04-07 00:00-23:59 UTC
total number of suspected botnet IPs: 167
number of botnet IPs notified to network operators: 158
number of spam blocked: 39068
recipient count of spam blocked: 1170112
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 167
number of botnet IPs notified to network operators: 158
number of spam blocked: 39068
recipient count of spam blocked: 1170112
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 12 |
2 | MSFT | 7 |
3 | VNPT-VNNIC-VN | 5 |
4 | KORNET-KR | 4 |
5 | HOSTWAY-05 | 4 |
6 | broadNnet-KR | 3 |
7 | TENCENT-CN | 3 |
8 | HINET-NET | 3 |
9 | GO-DADDY-COM-LLC | 3 |
10 | CHINANET-JS | 3 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 42 |
2 | United States | 27 |
3 | Indonesia | 10 |
4 | Viet Nam | 9 |
5 | Russian Federation | 8 |
6 | South Korea | 7 |
7 | France | 7 |
8 | India | 6 |
9 | Brazil | 5 |
10 | Taiwan | 4 |
Suspected Bot List [2018-04-07]
detection period: 2018-04-07 00:00-23:59 UTC
number of suspected bots' IPs listed here: 9
List from greylisting:
number of suspected bots' IPs listed here: 9
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Saturday, April 7, 2018
Botnet Statistics [2018-04-06]
detection period: 2018-04-06 00:00-23:59 UTC
total number of suspected botnet IPs: 141
number of botnet IPs notified to network operators: 131
number of spam blocked: 41798
recipient count of spam blocked: 1170854
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 141
number of botnet IPs notified to network operators: 131
number of spam blocked: 41798
recipient count of spam blocked: 1170854
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 5 |
2 | MSFT | 4 |
3 | broadNnet-KR | 3 |
4 | VNPT-VNNIC-VN | 3 |
5 | KORNET-KR | 3 |
6 | HINET-NET | 3 |
7 | SO-NET | 2 |
8 | NETVIGATOR | 2 |
9 | LINTASARTA-NET | 2 |
10 | HOSTWAY-05 | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 29 |
2 | United States | 15 |
3 | South Korea | 9 |
4 | Indonesia | 8 |
5 | France | 7 |
6 | Germany | 7 |
7 | India | 6 |
8 | Brazil | 5 |
9 | Viet Nam | 4 |
10 | Taiwan | 3 |
Suspected Bot List [2018-04-06]
detection period: 2018-04-06 00:00-23:59 UTC
number of suspected bots' IPs listed here: 10
List from greylisting:
number of suspected bots' IPs listed here: 10
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
KW | 37.34.243.227 | Kuwait |
SA | 188.53.163.228 | Saudi Arabia |
List from greylisting:
Friday, April 6, 2018
Botnet Statistics [2018-04-05]
detection period: 2018-04-05 00:00-23:59 UTC
total number of suspected botnet IPs: 221
number of botnet IPs notified to network operators: 207
number of spam blocked: 46447
recipient count of spam blocked: 1208066
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 221
number of botnet IPs notified to network operators: 207
number of spam blocked: 46447
recipient count of spam blocked: 1208066
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 6 |
2 | KORNET-KR | 6 |
3 | broadNnet-KR | 5 |
4 | CHINANET-ZJ | 5 |
5 | VNPT-VNNIC-VN | 4 |
6 | UCLOUD-NET | 4 |
7 | CMNET | 4 |
8 | UNICOM-GD | 3 |
9 | MSFT | 3 |
10 | LGTELECOM-KR | 3 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 46 |
2 | United States | 29 |
3 | South Korea | 18 |
4 | Viet Nam | 11 |
5 | Russian Federation | 11 |
6 | France | 11 |
7 | India | 9 |
8 | Indonesia | 7 |
9 | Brazil | 7 |
10 | Taiwan | 5 |
Suspected Bot List [2018-04-05]
detection period: 2018-04-05 00:00-23:59 UTC
number of suspected bots' IPs listed here: 14
List from greylisting:
number of suspected bots' IPs listed here: 14
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
KW | 37.34.243.227 | Kuwait |
MN | 202.170.70.8 | Mongolia |
RS | 178.149.102.210 | Serbia |
SA | 188.53.163.228 | Saudi Arabia |
SA | 212.76.76.242 | Saudi Arabia |
US | 96.37.155.42 | United States |
List from greylisting:
Thursday, April 5, 2018
Botnet Statistics [2018-04-04]
detection period: 2018-04-04 00:00-23:59 UTC
total number of suspected botnet IPs: 146
number of botnet IPs notified to network operators: 133
number of spam blocked: 44691
recipient count of spam blocked: 1209331
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 146
number of botnet IPs notified to network operators: 133
number of spam blocked: 44691
recipient count of spam blocked: 1209331
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 6 |
2 | VNPT-VNNIC-VN | 5 |
3 | UCLOUD-NET | 3 |
4 | MSFT | 3 |
5 | LGTELECOM-KR | 3 |
6 | CHINANET-ZJ | 3 |
7 | BORANET-KR | 3 |
8 | VE-CSVE-LACNIC | 2 |
9 | TLKM_NASIONAL_180_RESERVED | 2 |
10 | TENCENT-CN | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 29 |
2 | United States | 20 |
3 | India | 12 |
4 | France | 11 |
5 | Viet Nam | 10 |
6 | South Korea | 9 |
7 | Indonesia | 6 |
8 | Russian Federation | 4 |
9 | Canada | 4 |
10 | Brazil | 4 |
Suspected Bot List [2018-04-04]
detection period: 2018-04-04 00:00-23:59 UTC
number of suspected bots' IPs listed here: 13
List from greylisting:
number of suspected bots' IPs listed here: 13
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
KW | 37.34.243.227 | Kuwait |
PK | 202.61.51.123 | Pakistan |
RS | 178.149.102.210 | Serbia |
SA | 129.208.217.199 | Saudi Arabia |
SA | 188.50.130.43 | Saudi Arabia |
SA | 212.76.76.242 | Saudi Arabia |
US | 97.80.15.138 | United States |
List from greylisting:
Wednesday, April 4, 2018
Botnet Statistics [2018-04-03]
detection period: 2018-04-03 00:00-23:59 UTC
total number of suspected botnet IPs: 164
number of botnet IPs notified to network operators: 153
number of spam blocked: 41918
recipient count of spam blocked: 1080702
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 164
number of botnet IPs notified to network operators: 153
number of spam blocked: 41918
recipient count of spam blocked: 1080702
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | LGTELECOM-KR | 15 |
2 | TencentCloud | 8 |
3 | VNPT-VNNIC-VN | 6 |
4 | broadNnet-KR | 2 |
5 | TENCENT-CN | 2 |
6 | TELKOMNET | 2 |
7 | RRNY | 2 |
8 | HINET-NET | 2 |
9 | FR-OVH-20120823 | 2 |
10 | FR-OVH-20100119 | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 30 |
2 | United States | 21 |
3 | South Korea | 20 |
4 | France | 9 |
5 | Viet Nam | 8 |
6 | Russian Federation | 6 |
7 | India | 6 |
8 | Indonesia | 6 |
9 | United Kingdom | 5 |
10 | Germany | 4 |
Suspected Bot List [2018-04-03]
detection period: 2018-04-03 00:00-23:59 UTC
number of suspected bots' IPs listed here: 11
List from greylisting:
number of suspected bots' IPs listed here: 11
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
AR | 200.63.36.151 | Argentina |
CZ | 185.82.212.95 | Czech Republic |
IN | 202.62.76.14 | India |
KW | 37.34.243.227 | Kuwait |
PK | 202.61.51.123 | Pakistan |
SA | 212.76.76.242 | Saudi Arabia |
SA | 213.181.172.244 | Saudi Arabia |
TN | 196.234.189.16 | Tunisia |
List from greylisting:
Tuesday, April 3, 2018
Botnet Statistics [2018-04-02]
detection period: 2018-04-02 00:00-23:59 UTC
total number of suspected botnet IPs: 252
number of botnet IPs notified to network operators: 232
number of spam blocked: 38331
recipient count of spam blocked: 1087928
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 252
number of botnet IPs notified to network operators: 232
number of spam blocked: 38331
recipient count of spam blocked: 1087928
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | LGTELECOM-KR | 18 |
2 | TencentCloud | 11 |
3 | VNPT-VNNIC-VN | 5 |
4 | UCLOUD-NET | 5 |
5 | TENCENT-CN | 4 |
6 | KORNET-KR | 4 |
7 | NETVIGATOR | 3 |
8 | NETBLK-CHARTER-NET | 3 |
9 | HOSTWAY-05 | 3 |
10 | HINET-NET | 3 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 50 |
2 | United States | 31 |
3 | South Korea | 30 |
4 | France | 13 |
5 | Russian Federation | 12 |
6 | United Kingdom | 11 |
7 | India | 9 |
8 | Viet Nam | 8 |
9 | Taiwan | 8 |
10 | Netherlands | 6 |
Suspected Bot List [2018-04-02]
detection period: 2018-04-02 00:00-23:59 UTC
number of suspected bots' IPs listed here: 20
List from greylisting:
number of suspected bots' IPs listed here: 20
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
EG | 41.65.218.72 | Egypt |
IN | 202.62.76.14 | India |
KW | 37.34.243.227 | Kuwait |
PK | 202.61.51.123 | Pakistan |
RS | 178.149.102.210 | Serbia |
SA | 212.76.76.242 | Saudi Arabia |
SA | 213.181.172.244 | Saudi Arabia |
TN | 196.234.189.16 | Tunisia |
US | 97.80.15.138 | United States |
VE | 190.202.116.101 | Venezuela |
List from greylisting:
Monday, April 2, 2018
Botnet Statistics [2018-04-01]
detection period: 2018-04-01 00:00-23:59 UTC
total number of suspected botnet IPs: 99
number of botnet IPs notified to network operators: 91
number of spam blocked: 52897
recipient count of spam blocked: 1107540
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 99
number of botnet IPs notified to network operators: 91
number of spam blocked: 52897
recipient count of spam blocked: 1107540
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | VNPT-VNNIC-VN | 3 |
2 | TencentCloud | 3 |
3 | KORNET-KR | 3 |
4 | DOPI1 | 3 |
5 | CHINANET-ZJ | 3 |
6 | CHINANET-JS | 3 |
7 | broadNnet-KR | 2 |
8 | TimeNet | 2 |
9 | NETVIGATOR | 2 |
10 | HINET-NET | 2 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 24 |
2 | United States | 12 |
3 | Viet Nam | 7 |
4 | Russian Federation | 6 |
5 | Netherlands | 5 |
6 | South Korea | 5 |
7 | India | 5 |
8 | United Kingdom | 5 |
9 | France | 5 |
10 | Taiwan | 3 |
Suspected Bot List [2018-04-01]
detection period: 2018-04-01 00:00-23:59 UTC
number of suspected bots' IPs listed here: 8
List from greylisting:
number of suspected bots' IPs listed here: 8
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
List from greylisting:
Sunday, April 1, 2018
Botnet Statistics [2018-03-31]
detection period: 2018-03-31 00:00-23:59 UTC
total number of suspected botnet IPs: 65
number of botnet IPs notified to network operators: 62
number of spam blocked: 50403
recipient count of spam blocked: 1161190
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
total number of suspected botnet IPs: 65
number of botnet IPs notified to network operators: 62
number of spam blocked: 50403
recipient count of spam blocked: 1161190
The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:
Rank | Network | # of suspected botnet IPs |
---|---|---|
1 | TencentCloud | 7 |
2 | CHINANET-ZJ | 4 |
3 | VNPT-VNNIC-VN | 2 |
4 | UNICOM-LN | 2 |
5 | MSFT | 2 |
6 | CHINANET-JS | 2 |
7 | 010.379.340/0001-29 | 2 |
8 | Xpeed-KR | 1 |
9 | WHF-NETWORK | 1 |
10 | VE-CSVE-LACNIC | 1 |
The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:
1 | China | 30 |
2 | United States | 8 |
3 | Indonesia | 3 |
4 | Viet Nam | 2 |
5 | Israel | 2 |
6 | Brazil | 2 |
7 | Venezuela | 1 |
8 | Taiwan | 1 |
9 | Thailand | 1 |
10 | Singapore | 1 |
Suspected Bot List [2018-03-31]
detection period: 2018-03-31 00:00-23:59 UTC
number of suspected bots' IPs listed here: 3
List from greylisting:
number of suspected bots' IPs listed here: 3
IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.
List from fake open relays:
country code | IP address | Country |
---|---|---|
CZ | 185.82.212.95 | Czech Republic |
VE | 190.202.116.101 | Venezuela |
List from greylisting:
Subscribe to:
Posts (Atom)