Custom Search

Friday, October 9, 2020

Suspected Bot List [2020-10-08]

detection period: 2020-10-08 00:00-23:59 UTC
number of suspected bots' IPs listed here: 2204

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans:

Thursday, October 8, 2020

Botnet Statistics [2020-10-07]

detection period: 2020-10-07 00:00-23:59 UTC
total number of suspected botnet IPs: 50244
number of botnet IPs notified to network operators (best case, if all mail were sent out successfully): 47974
number of spam blocked: 0
recipient count of spam blocked: 0

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1VIETTEL-VN14830
2TencentCloud1359
3VNPT-VN1065
4HINET-NET723
5Baidu688
6TENCENT-CN646
7UNICOM-HA507
8UNICOM-SD506
9ALISOFT450
10VE-CSVE-LACNIC435

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry/Region# of suspected botnet IPs
1Viet Nam16577
2China8338
3United States3567
4India2880
5Russian Federation1951
6Brazil1755
7Indonesia1295
8Taiwan919
9France854
10Thailand837

The top 10 TCP ports, ordered by number of connection attempts received are:

RankTCP port number# of connection attempts received
14451377257
21234159302
32380875
42559404
52255197
633344526
7338925518
8143325321
9212223704
104020628

Suspected Bot List [2020-10-07]

detection period: 2020-10-07 00:00-23:59 UTC
number of suspected bots' IPs listed here: 2270

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:


country codeIP addressCountry

List from SSH probes:

country codeIP addressCountry

List from TCP port scans: