Custom Search

Monday, October 12, 2020

Suspected Bot List [2020-10-11]

detection period: 2020-10-11 00:00-23:59 UTC
number of suspected bots' IPs listed here: 2124

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans:

Sunday, October 11, 2020

Botnet Statistics [2020-10-10]

detection period: 2020-10-10 00:00-23:59 UTC
total number of suspected botnet IPs: 32054
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 29974
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1TencentCloud1318
2VIETTEL-VN784
3Baidu657
4VNPT-VN645
5TENCENT-CN618
6HINET-NET532
7UNICOM-SD505
8UNICOM-HA493
9ALISOFT481
10DIGITALOCEAN-192-241-128-0417

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China8315
2United States3150
3India2301
4Viet Nam2091
5Russian Federation1694
6Brazil1384
7Indonesia930
8France815
9Taiwan691
10Thailand535

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
1445352760
2143285905
3123191520
41234159275
5143374700
62256383
72350924
82047803
933344878
1066625956

Suspected Bot List [2020-10-10]

detection period: 2020-10-10 00:00-23:59 UTC
number of suspected bots' IPs listed here: 2080

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans: