Custom Search

Thursday, April 2, 2020

Suspected Bot List [2020-04-01]

detection period: 2020-04-01 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1400

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans:

Wednesday, April 1, 2020

Botnet Statistics [2020-03-31]

detection period: 2020-03-31 00:00-23:59 UTC
total number of suspected botnet IPs: 32988
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 31377
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1TencentCloud1041
2VNPT-VN998
3Baidu862
4VIETTEL-VN752
5HINET-NET651
6TENCENT-CN647
7DIGITALOCEAN-7462
8TELKOMNET438
9CHINANET-JS407
10DO-13349

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China9702
2United States3276
3Viet Nam2329
4Russian Federation1762
5Indonesia1184
6India1038
7France908
8Taiwan825
9Thailand723
10South Korea542

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
17070283280
21030187823
31024187198
42048151541
55000146396
65038102932
7402288529
8800085122
9444473953
10777770056

Suspected Bot List [2020-03-31]

detection period: 2020-03-31 00:00-23:59 UTC
number of suspected bots' IPs listed here: 1611

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans: