The Talos team published a detailed analysis of the GozNym botnet, it was possible because the experts cracked the DGA algorithm used by the malware. The number of unique IPs belonging to the botnet is 1854. The researchers from Talos have discovered flaws that allowed them to predict domain names using brute force. The experts were able to profile the Botnet, the sinkhole server they used, received 23,062 beacons within the first 24 hours. Most of the beacons were received from Germany (47%) and the United States (37%)”]
Source: http://securityaffairs.co/wordpress/51744/malware/goznym-botnet-profiling.html