Custom Search

Thursday, August 3, 2017

Suspected Bot List [2017-08-02]

detection period: 2017-08-02 00:00-23:59 UTC
number of suspected bots' IPs listed here: 41

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
DE213.153.68.129Germany
ID219.83.84.146Indonesia
IN203.115.99.218India
LY197.215.136.166Libya
MO116.193.10.34Macau
MO116.193.10.35Macau
MX189.211.198.181Mexico
RU90.188.95.206Russian Federation
RU91.197.234.102Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
US206.125.41.139United States
ZA196.46.23.122South Africa

List from greylisting:

Wednesday, August 2, 2017

Botnet Statistics [2017-08-01]

detection period: 2017-08-01 00:00-23:59 UTC
total number of suspected botnet IPs: 860
number of botnet IPs notified to network operators: 833
number of spam blocked: 77796
recipient count of spam blocked: 1684180

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1WASU89
2CMNET80
3CHINANET-HB80
4UNICOM-ZJ58
5CHINANET-JS51
6UNICOM-HB50
7Baidu35
8EXMASTERS826
9CHINANET-JX20
10PSINETA16

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China550
2United States126
3Czech Republic26
4Netherlands19
5Russian Federation14
6United Kingdom14
7Singapore13
8Viet Nam12
9Ukraine8
10Germany7

Suspected Bot List [2017-08-01]

detection period: 2017-08-01 00:00-23:59 UTC
number of suspected bots' IPs listed here: 27

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
IN203.115.99.218India
LY197.215.136.166Libya
MO116.193.10.34Macau
MX189.211.198.181Mexico
RU90.188.95.206Russian Federation
RU91.197.234.102Russian Federation
RU194.79.7.70Russian Federation
SG112.140.184.136Singapore
SG112.140.184.139Singapore
SG112.140.184.147Singapore
SG112.140.187.82Singapore
TH122.155.33.12Thailand
US206.125.41.139United States
ZA196.46.23.122South Africa

List from greylisting: