Skip to content

stamparm/ipsum

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 

Repository files navigation

Logo

License

About

IPsum is a threat intelligence feed based on 30+ different publicly available lists of suspicious and/or malicious IP addresses. All lists are automatically retrieved and parsed on a daily (every 24 hours) basis and the final result is pushed to this repository. The feed contains IP addresses plus an occurrence count (how many source lists each IP appears on). Higher counts generally mean higher confidence and fewer false positives when blocking inbound traffic. Also, list is sorted by occurrence count (highest to lowest).

As an example, to get a fresh and ready-to-deploy auto-ban list of "bad IPs" that appear on at least 3 (black)lists you can run:

curl -fsSL https://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt 2>/dev/null | grep -v "^#" | grep -Ev '[[:space:]]([12])$' | cut -f 1

If you want to try it with ipset, you can do the following:

sudo -i
apt-get update && apt-get install -y iptables ipset
ipset -q flush ipsum
ipset -q create ipsum hash:ip
for ip in $(curl https://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt 2>/dev/null | grep -v "#" | grep -Ev '[[:space:]]([12])$' | cut -f 1); do ipset add ipsum $ip; done
iptables -D INPUT -m set --match-set ipsum src -j DROP 2>/dev/null
iptables -I INPUT -m set --match-set ipsum src -j DROP

In directory levels you can find preprocessed raw IP lists based on number of blacklist occurrences (e.g. levels/3.txt holds IP addresses that can be found on 3 or more blacklists).

Wall of Shame (2026-03-14)

IP DNS lookup Number of (black)lists
2.57.121.25 hosting25.tronicsat.com 11
2.57.121.112 dns112.personaliseplus.com 11
213.209.159.159 - 11
94.26.106.201 - 10
3.143.162.210 scan.visionheight.com 9
45.148.10.121 - 9
71.6.199.23 einstein.census.shodan.io 9
94.26.106.200 - 9
101.36.104.242 - 9
107.150.119.229 - 9
130.12.182.185 - 9
2.57.122.210 - 8
2.57.122.238 - 8
3.131.220.121 scan.visionheight.com 8
45.249.245.88 - 8
66.132.153.126 126.153.132.66.censys-scanner.com 8
66.240.192.138 census8.shodan.io 8
71.6.135.131 soda.census.shodan.io 8
80.94.92.182 - 8
80.94.95.115 - 8
80.94.95.116 - 8
82.24.64.32 - 8
91.224.92.22 srv-91-224-92-22.minehost.eu 8
91.224.92.50 imize2.writeresaychooseboltsnow.com 8
92.118.39.56 - 8
93.123.109.176 - 8
101.36.118.177 - 8
103.218.243.42 - 8
114.111.54.188 - 8
115.140.161.61 - 8
121.165.204.105 - 8
130.12.181.85 - 8
130.12.181.151 - 8
130.12.181.157 - 8
157.245.13.48 - 8
167.94.146.48 48.146.94.167.censys-scanner.com 8
167.94.146.49 49.146.94.167.censys-scanner.com 8
167.94.146.56 56.146.94.167.censys-scanner.com 8
176.65.134.22 176.65.134.22 8
185.91.69.217 - 8
185.156.73.233 - 8
185.211.94.76 185-211-94-76.static.xelon.ch 8
192.109.200.220 thunderingsnail.ptr.network 8
193.24.211.93 - 8
193.32.162.145 - 8
199.45.154.146 146.154.45.199.censys-scanner.com 8
200.69.236.207 seldon.tecnologica.com.ar 8
206.168.34.33 33.34.168.206.censys-scanner.com 8
218.157.205.238 - 8
220.80.223.144 - 8
221.159.150.85 - 8
1.55.33.86 - 7
27.111.32.174 - 7
27.112.78.223 ip27-112-78-223.cloudhost.web.id 7
34.142.110.144 144.110.142.34.bc.googleusercontent.com 7
36.64.68.99 - 7
36.91.166.34 - 7
36.255.3.203 - 7
38.137.11.14 - 7
42.116.108.125 - 7
45.66.228.255 iceberg.30x.ru 7
45.120.216.232 - 7
45.148.10.151 - 7
45.148.10.152 - 7
45.148.10.192 - 7
45.153.34.213 - 7
45.164.39.253 - 7
45.172.152.74 - 7
45.175.37.18 - 7
45.232.73.84 - 7
50.104.70.175 50-104-70-175.prtg.in.frontiernet.net 7
51.195.138.37 vps-c3dafa63.vps.ovh.net 7
58.186.20.101 - 7
60.199.224.2 60-199-224-2.static.tfn.net.tw 7
60.199.224.55 60-199-224-55.static.tfn.net.tw 7
61.50.119.110 - 7
61.245.11.87 - 7
64.227.131.240 - 7
66.132.153.118 118.153.132.66.censys-scanner.com 7
66.132.153.121 121.153.132.66.censys-scanner.com 7
66.132.153.123 123.153.132.66.censys-scanner.com 7
66.132.153.131 131.153.132.66.censys-scanner.com 7
66.132.153.132 132.153.132.66.censys-scanner.com 7
66.132.153.137 137.153.132.66.censys-scanner.com 7
66.132.153.139 139.153.132.66.censys-scanner.com 7
66.132.153.141 141.153.132.66.censys-scanner.com 7
66.132.153.142 142.153.132.66.censys-scanner.com 7
68.233.116.124 - 7
80.82.70.133 rnd.group-ib.com 7
80.82.77.33 sky.census.shodan.io 7
80.82.77.139 dojo.census.shodan.io 7
80.94.92.168 - 7
80.94.92.171 - 7
80.94.92.184 - 7
80.94.92.186 - 7
80.253.31.232 - 7
81.183.192.244 51B7C0F4.dsl.pool.telekom.hu 7
81.211.72.167 - 7
82.165.66.87 ip82-165-66-87.pbiaas.com 7
85.18.236.229 85-18-236-229.ip.fastwebnet.it 7
85.217.149.6 o007.scanner.modat.io 7
85.217.149.25 o026.scanner.modat.io 7
85.217.149.58 o058.scanner.modat.io 7
85.217.149.67 o067.scanner.modat.io 7
85.217.149.70 o070.scanner.modat.io 7
86.54.31.32 hat.census.shodan.io 7
86.54.31.34 wine.census.shodan.io 7
86.54.31.38 blue2.census.shodan.io 7
92.27.101.99 host-92-27-101-99.static.as13285.net 7
92.118.39.72 - 7
92.118.39.76 - 7
92.118.39.95 - 7
95.167.225.76 - 7
101.47.158.137 - 7
102.210.148.92 - 7
103.48.192.48 - 7
103.63.25.171 ip103-63-25-171.cloudhost.web.id 7
103.67.78.216 ip103-67-78-216.cloudhost.web.id 7
103.72.147.99 - 7
103.76.120.225 - 7
103.172.236.241 - 7
103.210.22.17 - 7
103.233.206.154 - 7
103.237.144.204 - 7
103.250.10.151 ip103-250-10-151.cloudhost.web.id 7
103.250.11.96 ip103-250-11-96.cloudhost.web.id 7
111.68.98.152 111.68.98.152.pern.pk 7
112.196.70.142 - 7
113.193.234.210 - 7
121.52.147.5 upesh.edu.pk 7
121.153.60.137 - 7
121.165.84.80 - 7
122.168.194.41 abts-mp-static-041.194.168.122.airtelbroadband.in 7
125.17.108.32 server.serverinfo.in.net 7
130.12.180.95 - 7
134.65.30.157 - 7
138.124.67.78 - 7
139.59.36.12 - 7
142.93.128.21 - 7
147.50.103.212 - 7
154.83.196.237 - 7
154.221.27.234 - 7
156.238.252.133 - 7
159.89.26.2 - 7
159.146.11.164 - 7
159.223.37.230 - 7
159.223.211.238 - 7
160.174.129.232 - 7
161.49.89.39 161.49.89.39.convergeict.com 7
161.132.19.69 bora.yachay.pe 7
162.142.125.115 115.125.142.162.censys-scanner.com 7
162.142.125.125 125.125.142.162.censys-scanner.com 7
162.142.125.195 195.125.142.162.censys-scanner.com 7
162.142.125.203 203.125.142.162.censys-scanner.com 7
165.22.213.99 - 7
165.154.6.208 - 7
165.227.83.74 - 7
167.94.146.50 50.146.94.167.censys-scanner.com 7
167.94.146.52 52.146.94.167.censys-scanner.com 7
167.94.146.53 53.146.94.167.censys-scanner.com 7
167.94.146.54 54.146.94.167.censys-scanner.com 7
167.94.146.55 55.146.94.167.censys-scanner.com 7
167.94.146.57 57.146.94.167.censys-scanner.com 7
167.94.146.58 58.146.94.167.censys-scanner.com 7
167.94.146.60 60.146.94.167.censys-scanner.com 7
167.94.146.61 61.146.94.167.censys-scanner.com 7
167.94.146.62 62.146.94.167.censys-scanner.com 7
167.94.146.63 63.146.94.167.censys-scanner.com 7
170.238.160.191 - 7
171.244.37.96 - 7
175.196.135.148 - 7
176.32.195.85 scan.f6.security 7
176.65.132.23 - 7
176.65.132.143 - 7
176.120.22.13 - 7
176.120.22.17 - 7
176.120.22.47 - 7
178.251.140.3 b32-mgmt-gw.dssv.ru 7
182.93.50.90 n18293z50l90.static.ctmip.net 7
184.168.21.211 211.21.168.184.host.secureserver.net 7
185.107.80.93 - 7
185.196.10.248 - 7
185.242.3.105 - 7
185.247.184.146 145987.ip-ptr.tech 7
186.96.151.198 fixed-186-96-151-198.totalplay.net 7
187.16.96.250 mvx-187-16-96-250.mundivox.com 7
187.210.77.100 customer-187-210-77-100.uninet-ide.com.mx 7
187.212.42.32 dsl-32-42-212-187-dynamic.prod-infinitum.com.mx 7
190.129.122.185 - 7
192.109.200.219 materialoranges.ptr.network 7
192.210.254.30 192-210-254-30-host.colocrossing.com 7
194.107.115.2 - 7
196.188.93.169 - 7
197.5.145.73 - 7
197.5.145.102 - 7
197.211.55.20 - 7
198.12.67.159 - 7
198.44.177.67 - 7
199.45.154.112 112.154.45.199.censys-scanner.com 7
199.45.155.97 97.155.45.199.censys-scanner.com 7
200.196.50.91 mvx-200-196-50-91.mundivox.com 7
202.51.214.99 - 7
203.145.143.163 - 7
206.168.34.36 36.34.168.206.censys-scanner.com 7
206.168.34.38 38.34.168.206.censys-scanner.com 7
206.168.34.40 40.34.168.206.censys-scanner.com 7
206.168.34.60 60.34.168.206.censys-scanner.com 7
206.168.34.61 61.34.168.206.censys-scanner.com 7
206.168.34.63 63.34.168.206.censys-scanner.com 7
206.168.34.212 212.34.168.206.censys-scanner.com 7
211.20.14.156 211-20-14-156.hinet-ip.hinet.net 7
213.209.159.158 - 7
216.45.50.28 - 7
217.154.69.208 - 7
218.145.181.48 - 7
218.149.235.152 - 7
220.81.148.22 - 7
220.247.223.56 56.sta.idc-2.slt.lk 7
220.247.224.226 - 7
223.197.186.7 223-197-186-7.static.imsbiz.com 7

About

Daily feed of bad IPs (with blacklist hit scores)

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors