Custom Search

Saturday, October 1, 2016

Botnet Statistics for September 2016

detection period: 2016-09-01 00:00 - 2016-09-30 23:59 UTC
total number of suspected botnet IPs: 24729
number of blocked spams: 568419
recipient count of blocked spams: 12868411

The top 25 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan9260
2China3681
3Viet Nam2323
4India1971
5Mexico1058
6Brazil611
7Peru593
8Iran436
9Colombia436
10Turkey332
11Thailand208
12Argentina201
13Indonesia200
14Venezuela186
15Pakistan175
16Saudi Arabia171
17Arab Emirates146
18Tunisia129
19Bolivia128
20Philippines117
21Macedonia116
22Italy107
23Serbia79
24South Africa73
25Spain73

The top 17 countries (as defined by the 2-character country code), ordered by number of blocked spams are:

RankCountry# of blocked spams
1Taiwan423203
2Poland82741
3China44535
4United States8010
5Italy4174
6Philippines3356
7United Kingdom1130
8Thailand705
9Argentina260
10Turkey230
11Canada48
12Ukraine16
13Romania5
14Arab Emirates3
15Mexico1
16Lithuania1
17Croatia1

The top 17 countries (as defined by the 2-character country code), ordered by recipient count of blocked spams are:

Suspected Bot List [2016-09-30]

detection period: 2016-09-30 00:00-23:59 UTC
number of suspected bots' IPs listed here: 0

IP addresses listed here all exhibit strange network behavior. As I could not notify the victims for various reasons (no working abuse contact, mailbox over quota, etc.), I list them here instead. I have to emphasize that those are just *suspected* to be malware-infected computers.

List from fake open relays:

country codeIP addressCountry

List from greylisting:

Botnet Statistics [2016-09-30]

detection period: 2016-09-30 00:00-23:59 UTC
total number of suspected botnet IPs: 1079
number of botnet IPs notified to network operators: 1079
number of spam blocked: 42141
recipient count of spam blocked: 1221703

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1001
2CHINANET-HN65
3CHINANET-JS9
4CHINANET-SD4

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

1Taiwan1001
2China78