Skip to content

stamparm/ipsum

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 

Repository files navigation

Logo

License

About

IPsum is a threat intelligence feed based on 30+ different publicly available lists of suspicious and/or malicious IP addresses. All lists are automatically retrieved and parsed on a daily (every 24 hours) basis and the final result is pushed to this repository. The feed contains IP addresses plus an occurrence count (how many source lists each IP appears on). Higher counts generally mean higher confidence and fewer false positives when blocking inbound traffic. Also, list is sorted by occurrence count (highest to lowest).

As an example, to get a fresh and ready-to-deploy auto-ban list of "bad IPs" that appear on at least 3 (black)lists you can run:

curl -fsSL https://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt 2>/dev/null | grep -v "^#" | grep -Ev '[[:space:]]([12])$' | cut -f 1

If you want to try it with ipset, you can do the following:

sudo -i
apt-get update && apt-get install -y iptables ipset
ipset -q flush ipsum
ipset -q create ipsum hash:ip
for ip in $(curl https://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt 2>/dev/null | grep -v "#" | grep -Ev '[[:space:]]([12])$' | cut -f 1); do ipset add ipsum $ip; done
iptables -D INPUT -m set --match-set ipsum src -j DROP 2>/dev/null
iptables -I INPUT -m set --match-set ipsum src -j DROP

In directory levels you can find preprocessed raw IP lists based on number of blacklist occurrences (e.g. levels/3.txt holds IP addresses that can be found on 3 or more blacklists).

Wall of Shame (2026-01-17)

IP DNS lookup Number of (black)lists
213.209.159.158 - 10
213.209.159.159 - 10
2.57.121.25 hosting25.tronicsat.com 9
2.57.121.112 dns112.personaliseplus.com 9
45.148.10.121 - 9
93.174.95.106 battery.census.shodan.io 9
118.26.111.61 - 9
193.32.162.157 - 9
195.40.154.8 - 9
213.55.85.202 - 9
2.57.122.210 - 8
3.143.33.63 scan.cypex.ai 8
12.156.67.18 - 8
38.55.16.34 - 8
38.248.14.48 - 8
61.245.11.87 - 8
77.83.39.128 - 8
80.94.95.115 - 8
101.36.107.228 - 8
121.52.147.5 upesh.edu.pk 8
160.174.129.232 - 8
161.18.228.75 - 8
182.93.50.90 n18293z50l90.static.ctmip.net 8
185.156.73.233 - 8
190.124.153.17 customer-ftth-sl-190-124-153-17.megacable.com.ar 8
197.5.145.102 - 8
197.221.232.44 16.44.telone.co.zw 8
217.154.69.208 - 8
220.80.223.144 - 8
1.55.33.86 - 7
3.134.148.59 scan.cypex.ai 7
3.149.59.26 scan.cypex.ai 7
5.182.83.231 undefined.hostname.localhost 7
8.243.50.114 - 7
14.63.2.243 - 7
14.63.196.175 - 7
23.91.96.123 - 7
27.112.78.223 ip27-112-78-223.cloudhost.web.id 7
34.66.72.251 251.72.66.34.bc.googleusercontent.com 7
35.237.94.18 18.94.237.35.bc.googleusercontent.com 7
36.64.68.99 - 7
36.255.3.203 - 7
37.120.213.13 - 7
38.47.92.86 - 7
41.80.35.45 - 7
41.90.100.147 - 7
43.128.149.159 - 7
43.226.60.137 - 7
45.43.37.254 - 7
45.61.184.133 smtp11.shbgura.xyz 7
45.78.219.188 - 7
45.91.64.6 - 7
45.119.212.99 - 7
45.121.147.47 - 7
45.205.27.162 - 7
46.249.99.168 - 7
47.236.76.100 - 7
50.84.211.204 syn-050-084-211-204.biz.spectrum.com 7
50.225.176.238 - 7
51.15.147.194 51-15-147-194.rev.poneytelecom.eu 7
51.75.194.10 vps-f8f463b5.vps.ovh.net 7
59.12.160.91 - 7
59.126.224.134 59-126-224-134.hinet-ip.hinet.net 7
60.199.224.2 60-199-224-2.static.tfn.net.tw 7
62.146.228.81 ip-81-228-146-62.static.contabo.net 7
64.227.174.243 - 7
66.96.239.187 host-66-96-239-187.myrepublic.co.id 7
66.132.153.117 - 7
66.132.153.118 - 7
66.132.153.119 - 7
67.205.185.159 - 7
68.183.94.236 - 7
68.233.116.124 - 7
80.82.77.33 sky.census.shodan.io 7
80.82.77.139 dojo.census.shodan.io 7
80.94.95.116 - 7
81.30.212.94 81.30.212.94.static.ufanet.ru 7
81.177.136.68 srv6-vps-st.jino.ru 7
81.192.46.45 adsl-45-46-192-81.adsl.iam.net.ma 7
82.180.145.120 vmi3019789.contaboserver.net 7
86.54.42.188 VPS-oZuXXAFO 7
86.107.77.201 - 7
87.103.126.54 54.126.103.87.rev.vodafone.pt 7
91.202.233.33 - 7
91.224.92.14 srv-91-224-92-14.serveroffer.net 7
92.27.101.99 host-92-27-101-99.static.as13285.net 7
95.167.225.76 - 7
95.214.55.246 continued.zonogicism.nl 7
96.92.63.243 96-92-63-243-static.hfc.comcastbusiness.net 7
101.36.104.242 - 7
101.36.106.113 - 7
101.36.122.139 - 7
101.47.50.183 - 7
101.47.143.185 - 7
101.47.160.250 - 7
103.48.192.48 - 7
103.51.216.210 - 7
103.66.63.1 - 7
103.89.240.251 - 7
103.100.208.88 - 7
103.113.105.228 - 7
103.149.28.105 - 7
103.171.85.118 ip103-171-85-118.cloudhost.web.id 7
103.186.1.197 ip103-186-1-197.cloudhost.web.id 7
103.187.147.214 - 7
103.200.25.218 - 7
103.210.22.17 - 7
103.232.121.71 nick8472839 7
103.237.144.204 - 7
103.249.84.18 - 7
103.250.11.92 ip103-250-11-92.cloudhost.web.id 7
104.248.245.89 - 7
107.150.112.242 - 7
107.174.208.212 easterspecialties.com 7
109.228.18.139 server109-228-18-139.live-servers.net 7
111.238.174.6 KD111238174006.ppp-bb.dion.ne.jp 7
113.193.234.210 - 7
115.91.91.182 - 7
117.6.44.221 - 7
117.72.99.219 - 7
118.69.199.170 - 7
118.145.177.248 - 7
119.96.157.188 - 7
119.96.173.169 - 7
119.246.15.94 119246015094.ctinets.com 7
121.142.146.167 - 7
122.35.192.61 - 7
123.58.212.133 - 7
125.21.59.218 - 7
130.250.191.201 ip-130-250-191-201.hosted-by-hosterdaddy.com 7
130.250.191.225 ip-130-250-191-225.hosted-by-hosterdaddy.com 7
134.65.30.157 - 7
138.124.20.112 - 7
139.59.145.164 - 7
143.110.188.80 - 7
143.198.223.41 - 7
147.185.132.152 - 7
151.80.61.151 vps-5d95afd4.vps.ovh.net 7
152.53.32.129 v2202511310510397007.powersrv.de 7
154.125.149.205 - 7
156.233.228.30 - 7
157.66.26.151 - 7
162.142.125.113 - 7
162.142.125.114 - 7
162.142.125.119 - 7
162.142.125.124 - 7
162.142.125.126 - 7
162.142.125.196 scanner-202.ch1.censys-scanner.com 7
162.142.125.198 scanner-202.ch1.censys-scanner.com 7
162.142.125.221 scanner-207.ch1.censys-scanner.com 7
162.216.150.251 251.150.216.162.bc.googleusercontent.com 7
164.177.31.66 static-csq-cds-031066.business.bouyguestelecom.com 7
165.154.105.128 - 7
165.154.214.145 - 7
165.227.119.154 - 7
167.94.138.44 scanner-06.ch1.censys-scanner.com 7
167.94.146.51 - 7
167.94.146.53 - 7
167.94.146.57 - 7
167.99.78.165 108.jobs-dev-database 7
171.220.244.134 - 7
171.244.37.103 - 7
172.104.11.46 athens.scan.bufferover.run 7
174.138.62.162 - 7
176.65.132.210 - 7
176.65.148.45 176.65.148.45.ptr.pfcloud.network 7
176.213.141.182 176x213x141x182.dynamic.rostov.ertelecom.ru 7
178.17.58.173 - 7
178.128.92.222 - 7
178.251.140.3 b32-mgmt-gw.dssv.ru 7
179.51.153.37 ip-179-51-153-37.eunapolis.netcentertelecom.net.br 7
185.110.190.90 - 7
187.16.96.250 mvx-187-16-96-250.mundivox.com 7
187.49.152.12 - 7
187.94.255.130 130.255.94.187.vitalnetprovedor.com.br 7
189.112.0.11 189-112-000-011.static.ctbctelecom.com.br 7
190.117.52.211 - 7
190.167.90.67 67.90.167.190.d.dyn.codetel.net.do 7
190.244.39.229 229-39-244-190.fibertel.com.ar 7
191.101.210.158 - 7
194.190.153.226 ib.systems 7
195.3.222.78 - 7
195.178.191.5 h-195-178-191-5.NA.cust.bahnhof.se 7
195.201.131.18 static.18.131.201.195.clients.your-server.de 7
196.188.63.238 - 7
197.5.145.8 - 7
197.211.55.20 - 7
198.98.53.110 - 7
199.45.155.76 scanner-202.hk2.censys-scanner.com 7
200.69.236.207 seldon.tecnologica.com.ar 7
200.89.178.151 151-178-89-200.fibertel.com.ar 7
200.118.99.170 dynamic-ip-cr20011899170.cable.net.co 7
200.141.47.133 200-141-47-133.user3p.veloxzone.com.br 7
202.51.214.99 - 7
202.165.16.198 - 7
206.168.34.33 unused-space.coop.net 7
206.168.34.59 unused-space.coop.net 7
206.189.82.12 - 7
206.217.131.233 206-217-131-233-host.colocrossing.com 7
210.91.73.167 - 7
212.11.64.145 VPS-aWmaqbhG 7
213.209.159.63 - 7
216.108.237.50 lasvegas-nv-datacenter.serverpoint.com 7
217.154.38.135 - 7
220.247.224.226 - 7
221.156.126.1 - 7
222.107.251.147 - 7

About

Daily feed of bad IPs (with blacklist hit scores)

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published