IPsum is a threat intelligence feed based on 30+ different publicly available lists of suspicious and/or malicious IP addresses. All lists are automatically retrieved and parsed on a daily (every 24 hours) basis and the final result is pushed to this repository. The feed contains IP addresses plus an occurrence count (how many source lists each IP appears on). Higher counts generally mean higher confidence and fewer false positives when blocking inbound traffic. Also, list is sorted by occurrence count (highest to lowest).
As an example, to get a fresh and ready-to-deploy auto-ban list of "bad IPs" that appear on at least 3 (black)lists you can run:
curl -fsSL https://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt 2>/dev/null | grep -v "^#" | grep -Ev '[[:space:]]([12])$' | cut -f 1
If you want to try it with ipset, you can do the following:
sudo -i
apt-get update && apt-get install -y iptables ipset
ipset -q flush ipsum
ipset -q create ipsum hash:ip
for ip in $(curl https://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt 2>/dev/null | grep -v "#" | grep -Ev '[[:space:]]([12])$' | cut -f 1); do ipset add ipsum $ip; done
iptables -D INPUT -m set --match-set ipsum src -j DROP 2>/dev/null
iptables -I INPUT -m set --match-set ipsum src -j DROP
In directory levels you can find preprocessed raw IP lists based on number of blacklist occurrences (e.g. levels/3.txt holds IP addresses that can be found on 3 or more blacklists).
| IP | DNS lookup | Number of (black)lists |
|---|---|---|
| 2.57.121.25 | hosting25.tronicsat.com | 11 |
| 2.57.121.112 | dns112.personaliseplus.com | 11 |
| 213.209.159.159 | - | 11 |
| 185.91.69.217 | - | 10 |
| 45.148.10.121 | - | 9 |
| 80.82.77.33 | sky.census.shodan.io | 9 |
| 91.224.92.50 | imize2.writeresaychooseboltsnow.com | 9 |
| 93.174.95.106 | battery.census.shodan.io | 9 |
| 213.209.159.158 | - | 9 |
| 2.57.121.86 | mta86.soniideas.com | 8 |
| 2.57.122.238 | - | 8 |
| 14.63.217.28 | - | 8 |
| 36.255.3.203 | - | 8 |
| 43.252.231.122 | - | 8 |
| 45.87.249.155 | - | 8 |
| 45.148.10.141 | - | 8 |
| 45.148.10.152 | - | 8 |
| 66.132.153.123 | 123.153.132.66.censys-scanner.com | 8 |
| 66.132.153.126 | 126.153.132.66.censys-scanner.com | 8 |
| 66.240.192.138 | census8.shodan.io | 8 |
| 71.6.158.166 | ninja.census.shodan.io | 8 |
| 80.82.77.139 | dojo.census.shodan.io | 8 |
| 80.253.31.232 | - | 8 |
| 82.24.64.32 | - | 8 |
| 87.106.91.226 | - | 8 |
| 91.224.92.22 | srv-91-224-92-22.minehost.eu | 8 |
| 92.118.39.56 | - | 8 |
| 92.118.39.72 | - | 8 |
| 92.118.39.76 | - | 8 |
| 92.118.39.92 | - | 8 |
| 95.85.234.50 | instance219590.waicore.network | 8 |
| 114.111.54.188 | - | 8 |
| 115.140.161.61 | - | 8 |
| 125.17.108.32 | server.serverinfo.in.net | 8 |
| 138.124.67.78 | - | 8 |
| 147.185.132.204 | - | 8 |
| 162.142.125.123 | 123.125.142.162.censys-scanner.com | 8 |
| 162.142.125.216 | 216.125.142.162.censys-scanner.com | 8 |
| 163.7.1.156 | - | 8 |
| 165.154.227.162 | - | 8 |
| 167.94.146.54 | 54.146.94.167.censys-scanner.com | 8 |
| 167.94.146.59 | 59.146.94.167.censys-scanner.com | 8 |
| 167.94.146.62 | 62.146.94.167.censys-scanner.com | 8 |
| 178.130.46.2 | 175197.ip-ptr.tech | 8 |
| 185.242.3.105 | - | 8 |
| 187.16.96.250 | mvx-187-16-96-250.mundivox.com | 8 |
| 187.210.77.100 | customer-187-210-77-100.uninet-ide.com.mx | 8 |
| 209.166.46.147 | 209-166-46-147.client.dsl.net | 8 |
| 1.55.33.86 | - | 7 |
| 2.57.121.50 | smtp50.kcmoa.com | 7 |
| 2.57.122.190 | - | 7 |
| 2.57.122.191 | - | 7 |
| 2.57.122.192 | - | 7 |
| 2.57.122.193 | - | 7 |
| 2.57.122.194 | - | 7 |
| 2.57.122.199 | - | 7 |
| 3.143.162.210 | scan.visionheight.com | 7 |
| 5.101.64.6 | scan.f6.security | 7 |
| 8.154.6.154 | - | 7 |
| 14.29.198.130 | - | 7 |
| 14.63.196.175 | - | 7 |
| 23.227.147.163 | - | 7 |
| 27.79.41.173 | localhost | 7 |
| 27.111.32.174 | - | 7 |
| 34.85.163.94 | 94.163.85.34.bc.googleusercontent.com | 7 |
| 35.237.94.18 | 18.94.237.35.bc.googleusercontent.com | 7 |
| 36.66.16.233 | - | 7 |
| 37.120.213.13 | - | 7 |
| 45.66.228.255 | iceberg.30x.ru | 7 |
| 45.91.64.7 | scan.f6.security | 7 |
| 45.120.216.232 | - | 7 |
| 45.148.10.147 | - | 7 |
| 45.148.10.157 | - | 7 |
| 45.148.10.192 | - | 7 |
| 45.172.152.74 | - | 7 |
| 45.175.37.18 | - | 7 |
| 45.249.245.88 | - | 7 |
| 46.26.43.117 | static-117-43-26-46.ipcom.comunitel.net | 7 |
| 47.180.114.229 | 47-180-114-229.944e76fe48b133ae6f88b784db937d44.ip.frontiernet.net | 7 |
| 49.64.169.153 | - | 7 |
| 50.84.211.204 | syn-050-084-211-204.biz.spectrum.com | 7 |
| 51.15.4.95 | samfunnssikkerhet.org | 7 |
| 51.75.194.10 | vps-f8f463b5.vps.ovh.net | 7 |
| 51.158.120.121 | 121-120-158-51.instances.scw.cloud | 7 |
| 59.12.160.91 | - | 7 |
| 60.199.224.2 | 60-199-224-2.static.tfn.net.tw | 7 |
| 60.244.155.109 | - | 7 |
| 61.245.11.87 | - | 7 |
| 62.84.179.244 | vmi3157100.contaboserver.net | 7 |
| 64.62.156.132 | - | 7 |
| 64.62.197.227 | - | 7 |
| 66.132.153.115 | 115.153.132.66.censys-scanner.com | 7 |
| 66.132.153.121 | 121.153.132.66.censys-scanner.com | 7 |
| 66.132.153.124 | 124.153.132.66.censys-scanner.com | 7 |
| 66.132.153.129 | 129.153.132.66.censys-scanner.com | 7 |
| 66.132.153.132 | 132.153.132.66.censys-scanner.com | 7 |
| 66.132.153.134 | 134.153.132.66.censys-scanner.com | 7 |
| 66.132.153.137 | 137.153.132.66.censys-scanner.com | 7 |
| 66.132.153.139 | 139.153.132.66.censys-scanner.com | 7 |
| 66.132.153.141 | 141.153.132.66.censys-scanner.com | 7 |
| 66.240.236.116 | ubtuntu20236116.aspadmin.net | 7 |
| 68.233.116.124 | - | 7 |
| 71.6.135.131 | soda.census.shodan.io | 7 |
| 71.6.165.200 | census12.shodan.io | 7 |
| 71.6.199.23 | einstein.census.shodan.io | 7 |
| 80.94.92.168 | - | 7 |
| 80.94.92.184 | - | 7 |
| 81.183.192.244 | 51B7C0F4.dsl.pool.telekom.hu | 7 |
| 82.158.224.77 | - | 7 |
| 82.165.66.87 | ip82-165-66-87.pbiaas.com | 7 |
| 86.54.31.34 | wine.census.shodan.io | 7 |
| 86.54.31.42 | green.census.shodan.io | 7 |
| 88.142.46.185 | 185.46.142.88.rev.sfr.net | 7 |
| 92.118.39.95 | - | 7 |
| 93.123.109.176 | - | 7 |
| 94.26.106.201 | - | 7 |
| 95.58.255.251 | 95.58.255.251.static.telecom.kz | 7 |
| 95.165.77.31 | 95-165-77-31.dynamic.spd-mgts.ru | 7 |
| 101.47.158.137 | - | 7 |
| 101.100.194.199 | v22081641.sin01.serveradd.com | 7 |
| 102.88.137.80 | - | 7 |
| 102.140.97.134 | - | 7 |
| 103.40.61.98 | - | 7 |
| 103.61.122.229 | - | 7 |
| 103.63.25.171 | ip103-63-25-171.cloudhost.web.id | 7 |
| 103.67.78.70 | ip103-67-78-70.cloudhost.web.id | 7 |
| 103.67.78.216 | ip103-67-78-216.cloudhost.web.id | 7 |
| 103.148.100.146 | - | 7 |
| 103.156.204.2 | - | 7 |
| 103.182.132.154 | - | 7 |
| 103.189.235.33 | ip103-189-235-33.cloudhost.web.id | 7 |
| 103.233.206.154 | - | 7 |
| 103.249.84.18 | - | 7 |
| 103.250.11.207 | ip103-250-11-207.cloudhost.web.id | 7 |
| 107.150.119.229 | - | 7 |
| 109.105.210.72 | zl-dfwc-us-gp1-wk110a.internet-census.org | 7 |
| 118.193.33.3 | - | 7 |
| 121.52.147.5 | upesh.edu.pk | 7 |
| 121.165.84.80 | - | 7 |
| 122.115.225.109 | - | 7 |
| 122.168.194.41 | abts-mp-static-041.194.168.122.airtelbroadband.in | 7 |
| 125.21.59.218 | - | 7 |
| 129.213.146.221 | - | 7 |
| 134.65.30.157 | - | 7 |
| 136.228.161.66 | - | 7 |
| 139.84.242.153 | 139.84.242.153.vultrusercontent.com | 7 |
| 144.31.11.68 | - | 7 |
| 146.190.29.141 | portscanner-ams3-01.prod.cyberresilience.io | 7 |
| 147.182.194.60 | - | 7 |
| 150.107.36.236 | - | 7 |
| 150.107.38.251 | - | 7 |
| 152.32.162.42 | - | 7 |
| 154.125.147.88 | - | 7 |
| 154.221.27.234 | - | 7 |
| 156.225.18.240 | - | 7 |
| 159.146.11.164 | - | 7 |
| 160.174.129.232 | - | 7 |
| 161.49.89.39 | 161.49.89.39.convergeict.com | 7 |
| 162.142.125.44 | 44.125.142.162.censys-scanner.com | 7 |
| 162.142.125.114 | 114.125.142.162.censys-scanner.com | 7 |
| 162.142.125.115 | 115.125.142.162.censys-scanner.com | 7 |
| 162.142.125.116 | 116.125.142.162.censys-scanner.com | 7 |
| 162.142.125.117 | 117.125.142.162.censys-scanner.com | 7 |
| 162.142.125.118 | 118.125.142.162.censys-scanner.com | 7 |
| 162.142.125.120 | 120.125.142.162.censys-scanner.com | 7 |
| 162.142.125.122 | 122.125.142.162.censys-scanner.com | 7 |
| 162.142.125.125 | 125.125.142.162.censys-scanner.com | 7 |
| 162.142.125.126 | 126.125.142.162.censys-scanner.com | 7 |
| 162.142.125.200 | 200.125.142.162.censys-scanner.com | 7 |
| 162.142.125.204 | 204.125.142.162.censys-scanner.com | 7 |
| 162.142.125.210 | 210.125.142.162.censys-scanner.com | 7 |
| 162.142.125.215 | 215.125.142.162.censys-scanner.com | 7 |
| 162.142.125.219 | 219.125.142.162.censys-scanner.com | 7 |
| 162.216.149.232 | 232.149.216.162.bc.googleusercontent.com | 7 |
| 163.7.8.88 | - | 7 |
| 165.154.6.66 | - | 7 |
| 165.154.22.195 | - | 7 |
| 165.154.105.128 | - | 7 |
| 167.94.138.52 | 52.138.94.167.censys-scanner.com | 7 |
| 167.94.138.57 | 57.138.94.167.censys-scanner.com | 7 |
| 167.94.138.183 | 183.138.94.167.censys-scanner.com | 7 |
| 167.94.138.188 | 188.138.94.167.censys-scanner.com | 7 |
| 167.94.138.205 | 205.138.94.167.censys-scanner.com | 7 |
| 167.94.146.48 | 48.146.94.167.censys-scanner.com | 7 |
| 167.94.146.49 | 49.146.94.167.censys-scanner.com | 7 |
| 167.94.146.52 | 52.146.94.167.censys-scanner.com | 7 |
| 167.94.146.53 | 53.146.94.167.censys-scanner.com | 7 |
| 167.94.146.55 | 55.146.94.167.censys-scanner.com | 7 |
| 167.94.146.57 | 57.146.94.167.censys-scanner.com | 7 |
| 167.94.146.58 | 58.146.94.167.censys-scanner.com | 7 |
| 167.94.146.60 | 60.146.94.167.censys-scanner.com | 7 |
| 167.94.146.61 | 61.146.94.167.censys-scanner.com | 7 |
| 171.104.143.176 | - | 7 |
| 171.244.37.103 | - | 7 |
| 175.196.135.148 | - | 7 |
| 175.200.104.40 | - | 7 |
| 176.32.195.85 | scan.f6.security | 7 |
| 176.120.22.17 | - | 7 |
| 178.251.140.3 | b32-mgmt-gw.dssv.ru | 7 |
| 179.32.33.161 | - | 7 |
| 182.18.161.165 | static-182-18-161-165.ctrls.in | 7 |
| 182.93.50.90 | n18293z50l90.static.ctmip.net | 7 |
| 183.82.126.193 | 183.82.126.193.actcorp.in | 7 |
| 185.129.62.62 | tor01.zencurity.com | 7 |
| 185.177.72.13 | - | 7 |
| 185.211.94.76 | 185-211-94-76.static.xelon.ch | 7 |
| 185.246.130.20 | - | 7 |
| 187.107.88.97 | bb6b5861.virtua.com.br | 7 |
| 189.190.166.109 | dsl-109-166-190-189-dynamic.prod-infinitum.com.mx | 7 |
| 189.217.130.86 | customer-189-217-130-86.cablevision.net.mx | 7 |
| 190.129.122.185 | - | 7 |
| 193.24.211.93 | - | 7 |
| 193.46.255.86 | hostingmailto239.statics.servermail.org | 7 |
| 197.5.145.8 | - | 7 |
| 197.5.145.73 | - | 7 |
| 197.5.145.102 | - | 7 |
| 197.227.8.186 | - | 7 |
| 199.45.155.102 | 102.155.45.199.censys-scanner.com | 7 |
| 201.76.120.30 | 30.120.76.201.in-addr.arpa.verointernet.com.br | 7 |
| 202.51.214.99 | - | 7 |
| 203.145.34.82 | ip203-145-34-82.cloudhost.web.id | 7 |
| 203.145.34.222 | ip203-145-34-222.cloudhost.web.id | 7 |
| 205.185.125.150 | - | 7 |
| 206.168.34.42 | 42.34.168.206.censys-scanner.com | 7 |
| 206.168.34.44 | 44.34.168.206.censys-scanner.com | 7 |
| 206.168.34.45 | 45.34.168.206.censys-scanner.com | 7 |
| 206.168.34.58 | 58.34.168.206.censys-scanner.com | 7 |
| 206.168.34.127 | 127.34.168.206.censys-scanner.com | 7 |
| 207.166.168.14 | - | 7 |
| 210.114.22.126 | - | 7 |
| 210.211.122.97 | - | 7 |
| 217.154.69.208 | - | 7 |
| 218.145.181.48 | - | 7 |
| 220.80.223.144 | - | 7 |
| 220.247.223.56 | 56.sta.idc-2.slt.lk | 7 |
| 221.156.126.1 | - | 7 |
| 221.159.150.85 | - | 7 |
| 221.161.235.168 | - | 7 |