Custom Search

Friday, December 2, 2016

Suspected Bot List [2016-12-01]

detection period: 2016-12-01 00:00-23:59 UTC
number of suspected bots' IPs listed here: 173

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AG205.217.235.162Antigua And Barbuda
AG205.217.244.26Antigua And Barbuda
AG205.217.246.9Antigua And Barbuda
AG205.217.246.20Antigua And Barbuda
AG205.217.247.137Antigua And Barbuda
AG205.217.248.240Antigua And Barbuda
AG205.217.249.103Antigua And Barbuda
AG205.217.255.157Antigua And Barbuda
AR190.191.64.42Argentina
BD58.147.173.36Bangladesh
BD202.5.37.132Bangladesh
CM41.211.106.148Cameroon
CM41.223.30.251Cameroon
CR186.32.186.58Costa Rica
CV197.255.143.108Cape Verde
CV197.255.143.121Cape Verde
CV197.255.143.122Cape Verde
CV197.255.143.123Cape Verde
ES62.14.160.198Spain
ES62.15.75.212Spain
FR82.98.48.220France
GA197.231.141.29Gabon
GA197.231.143.122Gabon
GE37.131.224.106Republic Of Georgia
GT181.209.254.17Guatemala
HT200.113.196.77Haiti
HT200.113.196.252Haiti
HT200.113.221.17Haiti
HT200.113.221.105Haiti
HT200.113.221.134Haiti
IN59.145.146.94India
IN125.17.80.106India
IN125.99.255.146India
IN182.71.16.154India
IN182.71.25.62India
IN182.71.119.162India
IN182.72.25.86India
IN182.72.26.130India
IN182.72.36.34India
IN182.72.63.238India
IN182.72.89.138India
IN182.72.98.186India
IN182.72.100.238India
IN182.72.149.230India
IN182.72.158.134India
IN182.73.105.34India
IN182.73.149.126India
IN182.73.193.250India
IN182.73.245.86India
IN182.74.31.134India
IN182.74.50.70India
IN182.74.112.246India
IN182.74.190.194India
IN182.74.217.38India
IN182.74.232.178India
IN182.74.247.122India
IN182.75.19.2India
IN182.75.77.50India
IN182.75.107.222India
IN182.75.110.198India
IN182.75.114.174India
IN182.75.119.150India
IN182.75.123.78India
IN182.75.205.202India
IN182.75.213.102India
IN203.192.221.86India
IN203.192.221.87India
IT134.255.172.28Italy
KH103.12.160.149Cambodia
KH103.12.161.70Cambodia
KH103.12.161.187Cambodia
KH103.12.163.67Cambodia
KH103.239.54.178Cambodia
KZ89.218.26.142Kazakhstan
NI190.124.32.202Nicaragua
NL213.34.69.164Netherlands
NL213.34.69.176Netherlands
PK110.36.32.105Pakistan
PK110.36.33.37Pakistan
PK110.36.35.128Pakistan
PK110.36.63.25Pakistan
PK110.38.217.63Pakistan
PK110.38.217.82Pakistan
PK110.38.217.122Pakistan
PK110.38.217.133Pakistan
PK110.38.217.161Pakistan
PK110.38.217.162Pakistan
PK110.38.219.211Pakistan
PK182.191.81.191Pakistan
PT62.28.61.78Portugal
PT62.28.64.182Portugal
PT93.108.242.15Portugal
RO89.165.156.233Romania
RU213.33.205.6Russian Federation
SC41.86.56.47Seychelles
SV179.5.32.178El Salvador
SV179.5.32.182El Salvador
SV179.5.32.186El Salvador
SV179.5.32.190El Salvador
SV179.5.32.194El Salvador
SV179.5.33.10El Salvador
SV179.5.33.137El Salvador
SV179.5.33.190El Salvador
SV179.5.33.202El Salvador
ZM155.0.27.5Zambia

List from greylisting:

Botnet Statistics [2016-12-01]

detection period: 2016-12-01 00:00-23:59 UTC
total number of suspected botnet IPs: 1137
number of botnet IPs notified to network operators: 964
number of spam blocked: 19450
recipient count of spam blocked: 23716

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1CHINANET-HN118
2VNPT-VNNIC-VN66
3BHARTI-IN52
4CMNET38
5CHINANET-GD35
6BSNLNET31
7UNICOM-JS29
8CHINANET-JS27
9CHINANET-HB22
10UNICOM-HE20

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1China456
2India137
3Viet Nam97
4Brazil33
5Antigua And Barbuda30
6Colombia26
7Russian Federation22
8Pakistan21
9Mexico16
10Italy15

Thursday, December 1, 2016

Suspected Bot List [2016-11-30]

detection period: 2016-11-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 206

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry
AR190.195.255.164Argentina
BD58.147.173.36Bangladesh
BD202.5.37.132Bangladesh
CM41.211.106.148Cameroon
CM41.223.30.251Cameroon
CR186.32.186.58Costa Rica
CV197.255.143.108Cape Verde
CV197.255.143.121Cape Verde
CV197.255.143.122Cape Verde
CV197.255.143.123Cape Verde
ES80.59.205.203Spain
ES88.28.206.137Spain
ES88.28.209.187Spain
FR80.11.102.142France
FR85.203.107.46France
FR85.203.111.200France
FR85.203.116.219France
FR85.203.120.51France
FR85.203.121.115France
FR85.203.123.53France
FR193.252.26.9France
GA197.231.141.29Gabon
GA197.231.143.122Gabon
GE37.131.224.106Republic Of Georgia
GT181.209.238.69Guatemala
HT200.113.196.77Haiti
HT200.113.196.252Haiti
HT200.113.221.17Haiti
HT200.113.221.105Haiti
HT200.113.221.134Haiti
IN59.145.146.94India
IN125.17.80.106India
IN182.71.16.154India
IN182.71.25.62India
IN182.71.119.162India
IN182.72.25.86India
IN182.72.26.130India
IN182.72.36.34India
IN182.72.63.238India
IN182.72.89.138India
IN182.72.98.186India
IN182.72.100.238India
IN182.72.149.230India
IN182.72.158.134India
IN182.73.105.34India
IN182.73.149.126India
IN182.73.193.250India
IN182.73.245.86India
IN182.74.31.134India
IN182.74.50.70India
IN182.74.112.246India
IN182.74.190.194India
IN182.74.217.38India
IN182.74.232.178India
IN182.74.247.122India
IN182.75.19.2India
IN182.75.77.50India
IN182.75.107.222India
IN182.75.110.198India
IN182.75.114.174India
IN182.75.119.150India
IN182.75.123.78India
IN182.75.205.202India
IN182.75.213.102India
IN203.192.221.86India
IN203.192.221.87India
IT134.255.172.28Italy
KH103.12.160.149Cambodia
KH103.12.161.70Cambodia
KH103.12.161.187Cambodia
KH103.12.163.67Cambodia
KH103.239.54.178Cambodia
MY203.142.35.68Malaysia
NI190.124.32.202Nicaragua
NL213.34.69.164Netherlands
NL213.34.69.176Netherlands
PK110.36.32.105Pakistan
PK110.36.33.37Pakistan
PK110.36.35.128Pakistan
PK110.36.38.210Pakistan
PK110.36.63.25Pakistan
PK110.38.217.60Pakistan
PK110.38.217.63Pakistan
PK110.38.217.82Pakistan
PK110.38.217.122Pakistan
PK110.38.217.133Pakistan
PK110.38.217.161Pakistan
PK110.38.217.162Pakistan
PK110.38.219.211Pakistan
RO89.165.156.233Romania
RU213.33.205.6Russian Federation
SC41.86.56.47Seychelles
SV179.5.32.178El Salvador
SV179.5.32.182El Salvador
SV179.5.32.186El Salvador
SV179.5.32.190El Salvador
SV179.5.32.194El Salvador
SV179.5.33.10El Salvador
SV179.5.33.137El Salvador
SV179.5.33.190El Salvador
SV179.5.33.202El Salvador
ZM155.0.27.5Zambia

List from greylisting: