Custom Search

Thursday, October 31, 2019

Botnet Statistics [2019-10-30]

detection period: 2019-10-30 00:00-23:59 UTC
total number of suspected botnet IPs: 15842
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 15280
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1Baidu627
2TencentCloud584
3TENCENT-CN572
4KORNET322
5CMNET257
6HINET-NET255
7VNPT-VN245
8DO-13236
9VIETTEL-VN191
10DIGITALOCEAN-12180

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China4548
2United States1949
3France764
4Viet Nam691
5Russian Federation619
6India546
7Brazil536
8Indonesia488
9South Korea485
10Taiwan333

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
199947531
244518264
32217506
42313038
550389989
66117559
740227558
89917132
910006948
1091126819

Suspected Bot List [2019-10-30]

detection period: 2019-10-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 562

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans:

Wednesday, October 30, 2019

Botnet Statistics [2019-10-29]

detection period: 2019-10-29 00:00-23:59 UTC
total number of suspected botnet IPs: 16480
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 15837
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1Baidu628
2TencentCloud589
3TENCENT-CN570
4KORNET303
5VNPT-VN258
6HINET-NET250
7CMNET246
8DO-13241
9DIGITALOCEAN-12233
10OVH173

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China4612
2United States2085
3France784
4Viet Nam707
5Russian Federation613
6Brazil603
7India557
8Indonesia504
9South Korea469
10Singapore313

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
199936974
244519016
32216673
42313903
512129554
610008206
791657910
833897137
9217135
106117061

Suspected Bot List [2019-10-29]

detection period: 2019-10-29 00:00-23:59 UTC
number of suspected bots' IPs listed here: 643

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry
ES83.52.70.229Spain
KR210.103.97.135South Korea
NG41.87.80.26Nigeria

List from TCP port scans:

Tuesday, October 29, 2019

Botnet Statistics [2019-10-28]

detection period: 2019-10-28 00:00-23:59 UTC
total number of suspected botnet IPs: 16604
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 15975
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1Baidu640
2TencentCloud598
3TENCENT-CN578
4KORNET302
5VNPT-VN270
6DO-13262
7HINET-NET248
8CMNET231
9DIGITALOCEAN-12208
10ALISOFT182

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China4546
2United States2166
3France806
4Viet Nam696
5Russian Federation684
6Brazil570
7India528
8South Korea464
9Indonesia457
10Singapore318

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
144525951
22216528
32314137
440227605
514336928
690016916
733896764
859006390
927126375
1090006323

Suspected Bot List [2019-10-28]

detection period: 2019-10-28 00:00-23:59 UTC
number of suspected bots' IPs listed here: 629

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans:

Monday, October 28, 2019

Botnet Statistics [2019-10-27]

detection period: 2019-10-27 00:00-23:59 UTC
total number of suspected botnet IPs: 15965
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 15381
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1Baidu643
2TencentCloud597
3TENCENT-CN576
4KORNET318
5DO-13280
6CMNET208
7DIGITALOCEAN-12196
8OVH183
9CHINANET-JS168
10CHINANET-GD166

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China4548
2United States2186
3France869
4Russian Federation610
5Brazil524
6Viet Nam513
7South Korea493
8India468
9Indonesia366
10Singapore337

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
144541612
22222354
32316599
4222210444
512218735
650008402
733897976
8277801
940227667
10221227506

Suspected Bot List [2019-10-27]

detection period: 2019-10-27 00:00-23:59 UTC
number of suspected bots' IPs listed here: 584

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry
GH197.251.207.20Ghana

List from TCP port scans:

Sunday, October 27, 2019

Botnet Statistics [2019-10-26]

detection period: 2019-10-26 00:00-23:59 UTC
total number of suspected botnet IPs: 15987
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 15422
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1Baidu624
2TENCENT-CN581
3TencentCloud575
4KORNET306
5DO-13257
6DIGITALOCEAN-12229
7CMNET228
8OVH185
9HINET-NET180
10VNPT-VN173

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China4443
2United States2131
3France831
4Russian Federation622
5India567
6Viet Nam545
7Brazil529
8South Korea475
9Indonesia416
10Singapore333

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
144540125
22224822
32313334
4210236
522778304
640227716
790016676
890066244
921616195
1027096121

Suspected Bot List [2019-10-26]

detection period: 2019-10-26 00:00-23:59 UTC
number of suspected bots' IPs listed here: 565

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry
CA51.79.123.194Canada

List from TCP port scans:

Saturday, October 26, 2019

Botnet Statistics [2019-10-25]

detection period: 2019-10-25 00:00-23:59 UTC
total number of suspected botnet IPs: 15265
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 14649
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1Baidu525
2TencentCloud507
3TENCENT-CN505
4KORNET290
5VNPT-VN236
6DO-13228
7CMNET207
8DIGITALOCEAN-12202
9HINET-NET179
10OVH171

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China4130
2United States1933
3France745
4Viet Nam643
5India611
6Russian Federation605
7Brazil531
8Indonesia439
9South Korea436
10Singapore296

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
1280172
244533606
32215258
42314774
540228108
670708106
733896754
814336439
990066412
1027016157

Suspected Bot List [2019-10-25]

detection period: 2019-10-25 00:00-23:59 UTC
number of suspected bots' IPs listed here: 616

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry
CA184.67.105.182Canada
ZA197.97.230.163South Africa

List from TCP port scans:

Friday, October 25, 2019

Botnet Statistics [2019-10-24]

detection period: 2019-10-24 00:00-23:59 UTC
total number of suspected botnet IPs: 15600
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 14996
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1Baidu531
2TENCENT-CN511
3TencentCloud497
4KORNET276
5VNPT-VN243
6CMNET238
7DIGITALOCEAN-12218
8DO-13217
9HINET-NET189
10OVH167

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China4337
2United States1842
3France726
4Viet Nam670
5India660
6Russian Federation592
7Brazil545
8Indonesia461
9South Korea421
10Singapore290

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
1279434
244520017
32317741
42215483
52113512
650388845
740228128
814336981
927126315
1027105914

Suspected Bot List [2019-10-24]

detection period: 2019-10-24 00:00-23:59 UTC
number of suspected bots' IPs listed here: 604

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry
DE116.203.156.230Germany
MX189.254.33.157Mexico
PK58.65.135.98Pakistan

List from TCP port scans:

Thursday, October 24, 2019

Botnet Statistics [2019-10-23]

detection period: 2019-10-23 00:00-23:59 UTC
total number of suspected botnet IPs: 15705
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 15089
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1Baidu523
2TENCENT-CN510
3TencentCloud506
4KORNET273
5VNPT-VN268
6DO-13234
7DIGITALOCEAN-12222
8CMNET216
9HINET-NET191
10VIETTEL-VN185

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China4072
2United States1987
3France744
4Viet Nam718
5India664
6Russian Federation646
7Brazil540
8Indonesia474
9South Korea441
10Singapore289

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
1277829
244526749
3590020584
42317023
52214702
614338814
740227910
890016461
927126166
1027385978

Suspected Bot List [2019-10-23]

detection period: 2019-10-23 00:00-23:59 UTC
number of suspected bots' IPs listed here: 616

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans:

Wednesday, October 23, 2019

Botnet Statistics [2019-10-22]

detection period: 2019-10-22 00:00-23:59 UTC
total number of suspected botnet IPs: 15679
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 15025
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1Baidu525
2TENCENT-CN516
3TencentCloud515
4KORNET304
5VNPT-VN255
6DO-13233
7HINET-NET224
8CMNET218
9DIGITALOCEAN-12205
10VIETTEL-VN187

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China3974
2United States2012
3France753
4Viet Nam681
5Russian Federation631
6India621
7Brazil538
8Indonesia488
9South Korea462
10Singapore297

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
1276349
244519039
32215154
42313015
590018441
640228010
714337363
827106612
921616332
109626080

Suspected Bot List [2019-10-22]

detection period: 2019-10-22 00:00-23:59 UTC
number of suspected bots' IPs listed here: 654

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry
CA184.67.105.182Canada
ES80.28.238.53Spain
FR89.80.167.76France

List from TCP port scans:

Tuesday, October 22, 2019

Botnet Statistics [2019-10-21]

detection period: 2019-10-21 00:00-23:59 UTC
total number of suspected botnet IPs: 16477
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 15847
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1Baidu530
2TencentCloud504
3TENCENT-CN502
4VNPT-VN307
5HINET-NET299
6KORNET288
7DO-13221
8CMNET218
9DIGITALOCEAN-12216
10VIETTEL-VN202

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China4041
2United States2115
3France765
4Viet Nam732
5Russian Federation706
6India625
7Brazil579
8Indonesia527
9South Korea450
10Taiwan381

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
12317182
22216461
344511433
414338777
590018564
640228043
727046936
827106785
927126687
1070706570

Suspected Bot List [2019-10-21]

detection period: 2019-10-21 00:00-23:59 UTC
number of suspected bots' IPs listed here: 630

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry
ES83.56.9.1Spain

List from TCP port scans:

Monday, October 21, 2019

Botnet Statistics [2019-10-20]

detection period: 2019-10-20 00:00-23:59 UTC
total number of suspected botnet IPs: 15354
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 14794
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1TencentCloud517
2Baidu507
3TENCENT-CN498
4HINET-NET354
5KORNET311
6CMNET217
7DO-13211
8VNPT-VN207
9DIGITALOCEAN-12198
10VIETTEL-VN185

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China3919
2United States1959
3France787
4Russian Federation594
5Viet Nam573
6Brazil539
7Taiwan476
8South Korea465
9India459
10Indonesia415

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
144525175
22215572
32312484
4900110097
540227749
690067126
721726991
814336890
971356464
1071566433

Suspected Bot List [2019-10-20]

detection period: 2019-10-20 00:00-23:59 UTC
number of suspected bots' IPs listed here: 560

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry
FR176.168.157.23France

List from TCP port scans:

Sunday, October 20, 2019

Botnet Statistics for September 2019

detection period: 2019-09-01 00:00 - 2019-09-30 23:59 UTC
total number of suspected botnet IPs: 142242

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China19147
2United States14348
3Viet Nam11013
4Brazil9078
5Russian Federation8318
6India6720
7Indonesia6294
8Taiwan6179
9Egypt3827
10Turkey3307
11Mexico3284
12Thailand3154
13South Korea2801
14France2788
15Italy2353
16Ukraine2067
17Iran2028
18Venezuela1869
19Germany1642
20Hong Kong1586
21United Kingdom1417
22Argentina1372
23Philippines1206
24Spain1196
25Netherlands1183

The top 25 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1VNPT-VN5043
2HINET-NET5031
3VIETTEL-VN2950
4TELKOMNET2862
502.558.157/0001-622602
6AT-88-Z1917
7AFRINIC-0420051881
8VE-CSVE-LACNIC1620
9KORNET1581
10FPTDYNAMICIP-NET1386
11MX-USCV4-LACNIC1355
12CHINANET-GD1297
13DO-131211
14TEDATA-201503191112
15CMNET1110
16CHINANET-JS1102
17BSNLNET969
18TencentCloud958
19TENCENT-CN885
20MX-TPTE-LACNIC880
21TurkTelekom801
22AMAZON-2011L726
23UNICOM-SD704
24Baidu700
2540.432.544/0835-06673

The top 25 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
1445646399
223566450
322527315
43389180650
55900176870
61433172748
72222170774
8222170553
922222153939
10674150645
112022150521
128080149640
137070139908
1481139746
152200138828
161400137727
172126130068
1830000127548
192020126182
209999126118
215000124665
221569123501
23149122574
248000121055
257071120612

Botnet Statistics for August 2019

detection period: 2019-08-01 00:00 - 2019-08-31 23:59 UTC
total number of suspected botnet IPs: 128099

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China18451
2United States14334
3Viet Nam8936
4Brazil7439
5Russian Federation6849
6India6369
7Taiwan6291
8Indonesia5869
9Thailand2713
10Mexico2712
11Turkey2561
12South Korea2556
13Germany2493
14France2446
15Egypt2314
16Italy1862
17Iran1808
18Ukraine1755
19Venezuela1686
20Hong Kong1609
21United Kingdom1301
22Argentina1294
23Philippines1201
24Netherlands1084
25Canada1058

The top 25 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET5409
2VNPT-VN4113
3TELKOMNET2785
4VIETTEL-VN2389
502.558.157/0001-622271
6AT-88-Z1857
7CHINANET-JS1675
8VE-CSVE-LACNIC1476
9MX-USCV4-LACNIC1374
10KORNET1342
11AFRINIC-0420051337
12CHINANET-GD1321
13DO-131169
14FPTDYNAMICIP-NET1082
15TENCENT-CN1015
16CMNET1011
17TencentCloud939
18BSNLNET876
19AMAZON-2011L811
20Baidu731
21UNICOM-SD689
22TurkTelekom634
23GOOGLE-CLOUD623
24BEAMTELE-IN620
25ORG-AFNC1-AFRINIC-20050414593

The top 25 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
117231136867
223641637
3445597892
422470046
53389279881
6664261327
75900257553
81433256244
91569235477
10663235237
1130000211823
127046209673
13674209485
141400208287
159999205438
163390199255
179000196617
183391181423
19110180122
2081165178
218080162659
222022153365
23222151344
242222149222
252020148437

Botnet Statistics for July 2019

detection period: 2019-07-01 00:00 - 2019-07-31 23:59 UTC
total number of suspected botnet IPs: 134081

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China16260
2United States15552
3Viet Nam10379
4Brazil8199
5Russian Federation7358
6India7322
7Indonesia6796
8Taiwan5537
9Thailand3108
10Mexico2892
11France2763
12Turkey2750
13South Korea2603
14Egypt2580
15Iran2210
16Germany2046
17Venezuela1986
18Ukraine1978
19Italy1930
20Hong Kong1606
21United Kingdom1456
22Argentina1208
23Philippines1155
24Netherlands1127
25Pakistan1009

The top 25 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1VNPT-VN4950
2HINET-NET4707
3TELKOMNET3044
4VIETTEL-VN2621
502.558.157/0001-622512
6VE-CSVE-LACNIC1752
7AT-88-Z1751
8AFRINIC-0420051563
9KORNET1499
10MX-USCV4-LACNIC1359
11CHINANET-JS1235
12PSYCHZ-NETWORKS1229
13FPTDYNAMICIP-NET1219
14CHINANET-GD1169
15TENCENT-CN1022
16BSNLNET993
17DO-13910
18TencentCloud891
19AMAZON-2011L844
20CMNET804
21BEAMTELE-IN698
22TEDATA-20150319639
23Baidu634
24TurkTelekom613
25BHARTI-IN590

The top 25 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
1445636986
223613434
31723584077
45900421098
522333298
62022320286
7110280217
83389279388
9222247060
105038237385
112023234745
12627234022
135000230777
142024228682
157026225703
162021224893
177030219209
18623217734
19630217143
20102217062
21103216426
22105216245
238000215568
247032214954
25625214039

Botnet Statistics [2019-10-19]

detection period: 2019-10-19 00:00-23:59 UTC
total number of suspected botnet IPs: 16185
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 15601
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1TENCENT-CN499
2Baidu497
3TencentCloud495
4HINET-NET386
5KORNET316
6VNPT-VN275
7CMNET225
8DIGITALOCEAN-12221
9VIETTEL-VN214
10DO-13203

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China4010
2United States2055
3France759
4Russian Federation681
5Viet Nam660
6India607
7Brazil594
8Taiwan519
9South Korea479
10Indonesia438

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
144520142
22215471
3900111945
42310257
540228034
650388018
714337127
827086419
927066349
1027046153

Suspected Bot List [2019-10-19]

detection period: 2019-10-19 00:00-23:59 UTC
number of suspected bots' IPs listed here: 584

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry
ZA196.38.156.146South Africa

List from TCP port scans:

Saturday, October 19, 2019

Botnet Statistics for June 2019

detection period: 2019-06-01 00:00 - 2019-06-30 23:59 UTC
total number of suspected botnet IPs: 111644

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China12699
2United States11869
3Viet Nam8920
4Brazil7486
5Russian Federation6661
6India6390
7Taiwan5460
8Indonesia5290
9Thailand2767
10South Korea2431
11Mexico2276
12France2185
13Turkey1932
14Venezuela1808
15Iran1805
16Ukraine1679
17Italy1634
18Hong Kong1526
19Germany1289
20United Kingdom1208
21Philippines1188
22Egypt1154
23Colombia960
24Canada941
25Argentina932

The top 25 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET4785
2VNPT-VN4330
3VIETTEL-VN2348
402.558.157/0001-622330
5TELKOMNET2318
6VE-CSVE-LACNIC1592
7KORNET1492
8AT-88-Z1395
9MX-USCV4-LACNIC1045
10AFRINIC-0420051015
11CHINANET-GD953
12FPTDYNAMICIP-NET862
13BSNLNET850
14TENCENT-CN774
15CHINANET-JS759
16TencentCloud758
17AMAZON-2011L724
18PSYCHZ-NETWORKS715
19CMNET642
20DO-13613
21BEAMTELE-IN556
22NETVIGATOR533
23BHARTI-IN501
24FPT-VN487
25ORG-AFNC1-AFRINIC-20050414476

The top 25 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
13389645423
2445626839
323499714
45038363147
522361032
621324474
7222320443
88000278218
92222265164
1022222259376
115000255489
122022251814
13227245055
144009240808
154010237664
168080236076
1789235650
18223233971
1953231273
2088225607
21506220787
22507220640
2395215705
2493215560
252200215500

Botnet Statistics [2019-10-18]

detection period: 2019-10-18 00:00-23:59 UTC
total number of suspected botnet IPs: 16172
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 15532
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1TencentCloud507
2TENCENT-CN501
3Baidu495
4VNPT-VN316
5KORNET302
6HINET-NET282
7DO-13206
8CMNET203
9DIGITALOCEAN-12198
10VIETTEL-VN195

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China3998
2United States1998
3France745
4Viet Nam707
5India645
6Russian Federation635
7Brazil618
8South Korea465
9Indonesia456
10Taiwan367

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
144519937
22219748
32310580
414339747
542427954
690017879
759007167
840226801
971356361
1090036148

Suspected Bot List [2019-10-18]

detection period: 2019-10-18 00:00-23:59 UTC
number of suspected bots' IPs listed here: 640

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry
NG41.87.80.26Nigeria

List from TCP port scans:

Friday, October 18, 2019

Botnet Statistics [2019-10-17]

detection period: 2019-10-17 00:00-23:59 UTC
total number of suspected botnet IPs: 15943
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 15298
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1TencentCloud498
2Baidu497
3TENCENT-CN494
4KORNET292
5VNPT-VN242
6CMNET219
7DO-13203
8DIGITALOCEAN-12192
9TELKOMNET189
10HINET-NET189

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China4081
2United States1904
3France752
4Russian Federation679
5India665
6Brazil620
7Viet Nam604
8Indonesia496
9South Korea459
10Singapore346

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
1402276832
21112223428
344516360
42313632
52212448
6210010540
72219184
859007967
914337744
1033896707

Suspected Bot List [2019-10-17]

detection period: 2019-10-17 00:00-23:59 UTC
number of suspected bots' IPs listed here: 645

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry
NG41.203.76.251Nigeria

List from TCP port scans:

Thursday, October 17, 2019

Botnet Statistics for May 2019

detection period: 2019-05-01 00:00 - 2019-05-31 23:59 UTC
total number of suspected botnet IPs: 106835

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China11977
2United States10669
3Viet Nam9740
4Brazil7253
5Russian Federation6860
6Indonesia6186
7India6025
8Taiwan5321
9Mexico2598
10Thailand2524
11France2074
12Venezuela1930
13South Korea1929
14Turkey1842
15Ukraine1686
16Iran1416
17Germany1342
18Hong Kong1309
19Italy1263
20Philippines1094
21United Kingdom1063
22Egypt1046
23Netherlands918
24Colombia897
25Canada874

The top 25 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1VNPT-VN4782
2HINET-NET4704
3TELKOMNET2695
4VIETTEL-VN2448
502.558.157/0001-622244
6VE-CSVE-LACNIC1707
7AT-88-Z1704
8MX-USCV4-LACNIC1312
9KORNET1115
10FPTDYNAMICIP-NET988
11CHINANET-GD932
12AFRINIC-042005921
13AMAZON-2011L856
14TENCENT-CN831
15BSNLNET830
16TencentCloud729
17BEAMTELE-IN658
18CHINANET-JS613
19DO-13609
20FPT-VN535
21BHARTI-IN458
22CMNET450
23MX-GDUN-LACNIC447
24Baidu440
25CHINANET-SC427

The top 25 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
13389894985
28000774530
35000766078
43000622366
5445610852
688594753
78083585587
86001553647
910000536022
108081530127
118080529877
128087526838
138086524193
14222517864
154444505650
162222505143
173002504435
188008503360
193001502418
207071499452
21111498405
229009496791
239001494745
24666491897
252233491370

Botnet Statistics [2019-10-16]

detection period: 2019-10-16 00:00-23:59 UTC
total number of suspected botnet IPs: 16442
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 15779
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1TencentCloud512
2TENCENT-CN509
3Baidu506
4KORNET303
5VNPT-VN279
6CMNET237
7DIGITALOCEAN-12218
8DO-13209
9HINET-NET208
10CHINANET-JS186

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China4184
2United States1922
3France748
4India693
5Russian Federation680
6Viet Nam660
7Brazil619
8Indonesia511
9South Korea462
10Singapore355

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
1402254226
244540022
31112217544
42214277
52313615
6522510359
750388953
814338935
959008377
1027066701

Suspected Bot List [2019-10-16]

detection period: 2019-10-16 00:00-23:59 UTC
number of suspected bots' IPs listed here: 663

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry
CA184.67.105.182Canada

List from TCP port scans:

Wednesday, October 16, 2019

Botnet Statistics [2019-10-15]

detection period: 2019-10-15 00:00-23:59 UTC
total number of suspected botnet IPs: 16433
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 15760
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1Baidu509
2TENCENT-CN507
3TencentCloud498
4KORNET314
5VNPT-VN285
6CMNET280
7HINET-NET235
8DIGITALOCEAN-12230
9DO-13220
10OVH175

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China4238
2United States2053
3France741
4Russian Federation653
5Viet Nam640
6India624
7Brazil615
8South Korea459
9Indonesia451
10Singapore345

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
144524116
22214612
32313888
4503813813
522210786
614339888
759007799
840227507
922227345
10111226925