Custom Search

Friday, January 3, 2025

Botnet Statistics [2025-01-02]

(To download the latest zombie ip list, please visit the Daily Zombie IP Lists for January 2025. To get an idea of what IP is scanning the Internet currently, please watch: Daily Botnet Detection Live Streaming.)
detection period: 2025-01-02 00:00-23:59 UTC
total number of suspected botnet IPs: 26928
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 25407
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by the number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1425
2GOOGLE-CLOUD1030
3BSNLNET968
4PAN-22954
5MSFT865
6UK-MICROSOFT-20000324563
7AL-3532
8KORNET-KR506
9CMNET467
10CENSY377


The top 10 countries (as defined by the 2-character country code), ordered by the number of suspected botnet IPs are:


The top 10 TCP ports, ordered by the number of connection attempts received are:

RankCountry/Region# of suspected botnet IPs
1United States8037
2China5606
3India1798
4Taiwan1626
5United Kingdom1111
6South Korea845
7Russian Federation541
8Hong Kong528
9Brazil490
10Singapore475
RankTCP port number# of connection attempts received
11122159837
28899116941
33322109629
42281394
5444478582
6600066799
7338955915
82354625
9490037411
10224834206

20250103 Botnet Detection Live Streaming 10+ zombies detected)

Thursday, January 2, 2025

Botnet Statistics [2025-01-01]

(To download the latest zombie ip list, please visit the Daily Zombie IP Lists for January 2025. To get an idea of what IP is scanning the Internet currently, please watch: Daily Botnet Detection Live Streaming.)
detection period: 2025-01-01 00:00-23:59 UTC
total number of suspected botnet IPs: 25810
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 24225
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by the number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1609
2GOOGLE-CLOUD1013
3PAN-22961
4BSNLNET930
5MSFT871
6UK-MICROSOFT-20000324564
7KORNET-KR497
8CMNET459
9AL-3454
10CHINANET-JS371


The top 10 countries (as defined by the 2-character country code), ordered by the number of suspected botnet IPs are:


The top 10 TCP ports, ordered by the number of connection attempts received are:

RankCountry/Region# of suspected botnet IPs
1United States7843
2China4622
3Taiwan1832
4India1708
5United Kingdom1142
6South Korea852
7Russian Federation604
8Hong Kong531
9Brazil478
10Singapore441
RankTCP port number# of connection attempts received
14444363777
21122206316
33322174277
48899121205
5443395772
6600078747
72272649
82357016
9338950272
102447941

20250102 Botnet Detection Live Streaming 30+ zombies detected)

Daily Zombie Lists for January 2025(2025年01月,每日殭屍電腦IP清單)

To facilitate security research, I will release the daily zombie IP lists in CSV format here for anyone interested to download. The data columns are defined as follows:
為協助資安方面的研究,我將每日釋出CSV格式的殭屍電腦IP清單,供任何有興趣的人下載。資料欄位定義如下:

Column 1: The date and time in UTC when the last connection attempt (port scans) from the zombie IP (column 2) was detected;
第1欄:該殭屍電腦最後一次被偵測到企圖連線的日期、時間,時區為UTC;
Column 2: Zombie IP;
第2欄:該殭屍電腦的IP位址;
Column 3: TCP destination port number scanned by the zombie.
第3欄:該殭屍電腦所掃描的TCP埠號。

Join the "Suspected Zombie IP List" Telegram channel to get notified when the latest data are ready for download.
想在第一時間取得資料下載網址?請加入Suspected Zombie IP List的Telegram頻道。

Here are the download links of the daily zombie IP lists for January 2025 (without excluding IP addresses of TOR exits and so-called security researchers' nodes.):
以下是2025年01月的每日殭屍電腦IP清單的下載網址(未濾除TOR exit與所謂“資安研究者”的主機IP):

01/01: download link 下載網址; MD5sum: 6d170756ea431033c5be8a00851a435b
01/02: download link 下載網址; MD5sum: abe2d123f44fb1eecbf6cd1f88347e9a

Wednesday, January 1, 2025

Botnet Statistics [2024-12-31]

(To download the latest zombie ip list, please visit the Daily Zombie IP Lists for December 2024. To get an idea of what IP is scanning the Internet currently, please watch: Daily Botnet Detection Live Streaming.)
detection period: 2024-12-31 00:00-23:59 UTC
total number of suspected botnet IPs: 26204
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 24684
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by the number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1606
2GOOGLE-CLOUD990
3PAN-22955
4MSFT872
5BSNLNET851
6UK-MICROSOFT-20000324561
7CMNET486
8AL-3480
9KORNET-KR474
10CENSY376


The top 10 countries (as defined by the 2-character country code), ordered by the number of suspected botnet IPs are:


The top 10 TCP ports, ordered by the number of connection attempts received are:

RankCountry/Region# of suspected botnet IPs
1United States8187
2China4621
3Taiwan1848
4India1669
5United Kingdom1104
6South Korea826
7Russian Federation543
8Hong Kong540
9Brazil508
10Singapore475
RankTCP port number# of connection attempts received
13322246067
21122209333
34444158246
48899122185
521105113
64433102846
7600066583
82465055
92356054
102254080

20250101 Botnet Detection Live Streaming 30+ zombies detected)