Custom Search

Sunday, March 8, 2015

Suspected Bot List [2015-03-07]

detection period: 2015-03-07 00:00-23:59 UTC
number of suspected bots' IPs listed here: 278

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
CI213.136.105.210Ivory Coast
CI213.136.105.212Ivory Coast
EC201.219.60.118Ecuador
ID103.16.115.14Indonesia
ID118.97.175.114Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.139.134Indonesia
ID202.150.157.34Indonesia
ID202.162.213.162Indonesia
ID203.201.172.162Indonesia
ID222.124.202.195Indonesia
IN117.211.27.12India
IN125.21.245.146India
IN202.63.113.12India
MN203.91.119.146Mongolia
TR88.247.164.136Turkey
TR88.250.69.146Turkey
TW180.218.34.245Taiwan
US69.197.156.226United States
US174.139.8.82United States
US208.73.202.157United States
US209.220.168.177United States

List from greylisting:

Botnet Statistics [2015-03-07]

detection period: 2015-03-07 00:00-23:59 UTC
total number of suspected botnet IPs: 2788
number of botnet IPs notified to network operators: 2510
number of spam blocked: 136327
recipient count of spam blocked: 4923232

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1109
2VNPT-VNNIC-VN190
3ZJU-CN117
4VIETEL-VNNIC-VN66
5CHINANET-GD48
6KORNET-KR40
7FPT-VN36
8AR-TEAR7-LACNIC29
9CERNET-CN27
10ETC-VNNIC-VN20

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1141
2Viet Nam366
3China310
4South Korea83
5Argentina77
6India65
7Brazil64
8Italy50
9United States44
10Colombia41

Saturday, March 7, 2015

Suspected Bot List [2015-03-06]

detection period: 2015-03-06 00:00-23:59 UTC
number of suspected bots' IPs listed here: 475

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
BD203.76.147.70Bangladesh
CI213.136.105.210Ivory Coast
CI213.136.105.212Ivory Coast
EC201.219.60.118Ecuador
ID118.97.175.114Indonesia
ID202.137.230.127Indonesia
ID202.137.230.134Indonesia
ID202.148.7.77Indonesia
ID202.150.139.134Indonesia
ID202.150.157.34Indonesia
ID203.201.172.162Indonesia
ID222.124.202.195Indonesia
IN125.21.245.146India
IN202.63.113.12India
MN203.91.119.146Mongolia
PE200.1.183.82Peru
TW180.218.34.245Taiwan
US69.197.156.226United States
US208.73.202.157United States
US209.220.168.177United States

List from greylisting: