Custom Search

Thursday, July 6, 2017

Suspected Bot List [2017-07-05]

detection period: 2017-07-05 00:00-23:59 UTC
number of suspected bots' IPs listed here: 34

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.110.72.131Arab Emirates
ID219.83.84.146Indonesia
IN203.115.99.218India
MO116.193.10.34Macau
MO116.193.10.35Macau
MX189.211.198.181Mexico
PK202.83.163.219Pakistan
PL91.185.189.179Poland
RU31.173.216.163Russian Federation
RU82.179.134.236Russian Federation
RU87.226.213.86Russian Federation
RU109.194.197.79Russian Federation
RU185.76.145.20Russian Federation
RU185.127.25.68Russian Federation
RU195.98.189.178Russian Federation
RU195.190.124.202Russian Federation
RU212.34.39.230Russian Federation
RU212.46.215.107Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
TH103.40.132.18Thailand
TH203.146.249.104Thailand
TH203.151.206.113Thailand
US71.14.28.163United States
US96.33.171.230United States
US206.125.41.139United States
VE150.187.41.90Venezuela
ZA196.46.23.122South Africa

List from greylisting:

Wednesday, July 5, 2017

Botnet Statistics [2017-07-04]

detection period: 2017-07-04 00:00-23:59 UTC
total number of suspected botnet IPs: 910
number of botnet IPs notified to network operators: 856
number of spam blocked: 104680
recipient count of spam blocked: 2087985

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1UNICOM-ZJ182
2WASU107
3CMNET103
4CHINANET-JS32
5MELBICOM-NL30
6CUBEMOTION23
7CHINANET-GD19
8VNPT-VNNIC-VN18
9SERVERYOU-NET-LAX18
10CHINANET-HA15

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China579
2United States85
3Russian Federation63
4Viet Nam33
5Brazil14
6India13
7Singapore12
8Taiwan9
9Poland8
10France7

Suspected Bot List [2017-07-04]

detection period: 2017-07-04 00:00-23:59 UTC
number of suspected bots' IPs listed here: 54

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AE83.110.72.131Arab Emirates
DZ193.194.86.122Algeria
IN203.115.99.218India
LY197.215.136.166Libya
MO116.193.10.34Macau
MO116.193.10.35Macau
MX189.211.198.181Mexico
MX201.163.21.226Mexico
NO193.150.121.66Norway
PK202.83.163.219Pakistan
PL91.185.189.179Poland
RS89.216.28.123Serbia
RU37.1.11.205Russian Federation
RU37.29.7.122Russian Federation
RU62.183.72.122Russian Federation
RU82.179.134.236Russian Federation
RU87.226.213.86Russian Federation
RU90.188.18.74Russian Federation
RU91.122.195.202Russian Federation
RU91.197.234.102Russian Federation
RU109.94.95.237Russian Federation
RU109.111.189.234Russian Federation
RU109.171.97.88Russian Federation
RU176.118.237.85Russian Federation
RU178.141.249.246Russian Federation
RU185.52.69.197Russian Federation
RU185.76.145.20Russian Federation
RU185.127.25.68Russian Federation
RU194.67.184.222Russian Federation
RU194.79.7.70Russian Federation
RU195.98.189.178Russian Federation
RU195.190.124.202Russian Federation
RU212.46.215.107Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
TH103.40.132.18Thailand
TH203.151.206.113Thailand
TW106.1.195.68Taiwan
US96.33.171.230United States
US206.125.41.139United States
ZA196.46.23.122South Africa

List from greylisting: