Custom Search

Monday, November 2, 2020

Suspected Bot List [2020-11-01]

detection period: 2020-11-01 00:00-23:59 UTC
number of suspected bots' IPs listed here: 2084

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans:

Sunday, November 1, 2020

Botnet Statistics [2020-10-31]

detection period: 2020-10-31 00:00-23:59 UTC
total number of suspected botnet IPs: 33557
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 31474
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1TencentCloud1378
2VNPT-VN700
3Baidu646
4TENCENT-CN637
5VIETTEL-VN623
6DIGITALOCEAN-192-241-128-0620
7HINET-NET589
8DIGITALOCEAN-165-232-32-0563
9ALISOFT477
10UNICOM-HA429

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1China8139
2United States4382
3India2103
4Russian Federation2049
5Viet Nam2039
6Brazil1365
7Indonesia1030
8France810
9Taiwan759
10Thailand564

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
1445707227
21100140550
3200108201
470097085
5150095471
640093644
790091425
889988961
980087515
10120086444

Suspected Bot List [2020-10-31]

detection period: 2020-10-31 00:00-23:59 UTC
number of suspected bots' IPs listed here: 2083

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans: